Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

SpaceX IPO: Everything You Need To Know

Equal AI raises $30 million to screen calls so Indians don’t have to

ServiceNow is telling customers that a bug left some of their data exposed online

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    SpaceX IPO: Everything You Need To Know

    12 June 2026

    Theker just raised $85 million to build factory robot that specializes in nothing

    12 June 2026

    DoorDash’s new AI chatbot lets you order with prompts and photos

    11 June 2026

    Opendoor’s exit from India fuels a larger conversation about AI and outsourcing

    11 June 2026

    How memory tools can make AI models worse

    10 June 2026
  • Apps

    Equal AI raises $30 million to screen calls so Indians don’t have to

    12 June 2026

    Bluesky launches group chats as company shifts focus to community features

    12 June 2026

    Pool’s new app turns your screenshots into something useful

    11 June 2026

    Pinterest bets on creators with Amazon Storefront integration

    11 June 2026

    Zest Launches Restaurant Discovery App Powered by Where People Really Eat

    10 June 2026
  • Crypto

    Startup Battlefield 200 applications close today

    27 May 2026

    5 days left: Save up to $410 on Disrupt 2026 passes

    25 May 2026

    As crypto cools, a16z crypto raises $2.2 billion in capital

    6 May 2026

    Coinbase to lay off 14% of staff as part of broader restructuring

    5 May 2026

    British cryptographer Adam Back denies NYT report that he is Bitcoin creator Satoshi Nakamoto

    9 April 2026
  • Fintech

    Ramp raises $750M at $44B valuation as investors thirst for fintechs with AI history

    5 June 2026

    Last 24 hours to save up to $410 on your Disrupt 2026 ticket

    29 May 2026

    2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

    28 May 2026

    Robinhood now allows your AI agents to trade stocks

    28 May 2026

    Disrupt 2026 Early Bird ticket savings expire in 3 days

    27 May 2026
  • Hardware

    Jeff Bezos’ Prometheus Raises $12 Billion to Build an ‘Artificial General Engineer’ for the Natural World

    12 June 2026

    WWDC 2026: What to expect, from Siri’s long-awaited revamp to Apple Intelligence and iOS 27

    9 June 2026

    What to expect from WWDC 2026: The long-awaited Siri refresh and Apple Intelligence updates

    7 June 2026

    What to expect from WWDC 2026: The long-awaited Siri refresh and Apple Intelligence updates

    5 June 2026

    Oura Ring 5 review: Thinner, lighter, better

    4 June 2026
  • Media & Entertainment

    Deezer’s new tool can recognize AI music from Spotify, Apple Music and more

    11 June 2026

    Netflix expands revamped mobile app across Asia and doubles down on games for kids

    10 June 2026

    Plex adds new social features ahead of major price hike for its lifetime pass

    6 June 2026

    Startup Battlefield 200 applications officially close in 3 days

    5 June 2026

    Founders Fund Launches Series of Games Starring Sam Altman, Palmer Luckey and Other Tech Elites

    5 June 2026
  • Security

    ServiceNow is telling customers that a bug left some of their data exposed online

    12 June 2026

    Oracle warns of security flaw that hackers abused to breach 100+ companies

    11 June 2026

    Cybersecurity researchers not happy with guardrails in Anthropic’s Fable

    11 June 2026

    North Koreans behind nearly half of US tech industry hacks, CrowdStrike says

    10 June 2026

    Massachusetts votes in favor of new privacy bill that bans sale of precise location data

    9 June 2026
  • Startups

    Military SPAC Quantum Space is trying to catch SpaceX’s IPO wave

    12 June 2026

    Microsoft is using Alt Carbon as a sign of India’s growing role in carbon removal

    11 June 2026

    Warner Music acquires artificial intelligence performance startup Sureel AI

    11 June 2026

    Datadog veterans launch AI coding startup Niteshift in a bet against Big AI lock-in

    10 June 2026

    Evotrex raises $30 million to build RV that doesn’t need a charging station

    10 June 2026
  • Transportation

    Decart’s new global model can simulate hours of photorealistic driving — with some caveats

    12 June 2026

    Waymo is launching a rewards program with 10% cash back and free cancellations

    11 June 2026

    Everyone wants a piece of Tesla’s batteries

    11 June 2026

    Because everyone is an energy company now

    10 June 2026

    Top Lucid Motors executive exits amid new CEO shakeup

    10 June 2026
  • Venture

    Why business AI will be the focus of VivaTech 2026

    10 June 2026

    How Justin Ernest invested nearly $500 million in hot startups without a traditional VC fund

    10 June 2026

    Mercor’s Brendan Foody calls out Sequoia, accusing it of “double pricing” valuation tricks.

    9 June 2026

    Founders share VC horror stories and some name names

    6 June 2026

    Defense technology, artificial intelligence and fundraising take center stage at StrictlyVC Los Angeles

    5 June 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Meet the Chinese ‘Typhoon’ Hackers Preparing for War
Security

Meet the Chinese ‘Typhoon’ Hackers Preparing for War

techtost.comBy techtost.com12 January 202508 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Meet The Chinese 'typhoon' Hackers Preparing For War
Share
Facebook Twitter LinkedIn Pinterest Email

Of the cybersecurity risks facing the United States today, few are greater than the potential sabotage capabilities posed by China-backed hackers, who senior US national security officials have described as an “era-defining threat.”

The U.S. says Chinese government-backed hackers — in some cases for years — have burrowed deep into the networks of critical U.S. infrastructure, including water, energy and transportation providers. The goal, officials say, is to lay the groundwork for potentially devastating cyberattacks in the event of a future conflict between China and the United States, such as a possible Chinese invasion of Taiwan;.

“China’s hackers are placing themselves in American infrastructure preparing to wreak havoc and cause real harm to American citizens and communities if or when China decides it’s time to strike,” then-outgoing FBI Director Christopher Wray told lawmakers.

The US government and its allies have since taken action against some of the Chinese “Typhoon” family of hacking groups and released new details about the threats posed by these groups.

In January 2024, the US disrupted ‘Volt Typhoon’, a group of Chinese government hackers tasked with setting the stage for devastating cyber attacks. Later, in September 2024, federal authorities seized control of a botnet run by another Chinese hacker group called “Flax Typhoon,” which used a Beijing-based cybersecurity firm to help hide its government hacking activities China. Then, in December, the US government sanctioned the cybersecurity company for its alleged role in “multiple computer intrusion incidents against US victims.”

Since then, another new Chinese-backed hacking group called “Salt Typhoon” has emerged on the networks of US phone and internet giants, capable of gathering information about Americans – and potential US surveillance targets – by compromising telecommunications systems used for enforcement wiretapping. of the law.

And, a Chinese threat actor called Silk Typhoon (formerly known as Hafnium), a hacker group active since at least 2021, returned in December 2024 with a new campaign targeting the US Treasury.

Here’s what we learned about Chinese hacker groups preparing for war.

Volt Typhoon

Volt Typhoon represents a new breed of Chinese-backed hacking groups. it no longer aims simply to steal sensitive US secrets, but rather to prepare to disrupt the US military’s “mobilization capability,” according to the then-FBI director.

Microsoft first spotted Volt Typhoon in May 2023, finding that hackers had targeted and compromised network equipment such as routers, firewalls and VPNs since at least mid-2021 as part of an ongoing and coordinated effort to penetrate deep into US critical infrastructure systems. The US intelligence community said that in reality, it is possible that the hackers were operating for much longer, possibly as long as five years.

Volt Typhoon compromised thousands of these Internet-connected devices in the months following Microsoft’s report, exploiting vulnerabilities in devices that were considered “end-of-life” and therefore would no longer receive security updates. The hacking group subsequently gained further access to the IT environments of several critical infrastructure sectors, including aviation, water, energy and transportation, intending to enable future disruptive cyberattacks aimed at slowing down the US government’s response to an intrusion into her main ally. Taiwan.

“This actor does not do the quiet intelligence-gathering and secret-stealing that has been the norm in the US. They probe sensitive critical infrastructure so they can disrupt major services if and when the order collapses,” said John Hultquist, chief. analyst at security firm Mandiant.

THE The US government said in January 2024 that it had successfully disrupted a botnet, used by Volt Typhoon, consisting of thousands of compromised small office and home network routers in the US, which the Chinese hacking group used to hide its malicious activity aimed at targeting US critical infrastructure . The FBI said it was able to remove the malware from compromised routers through a court-approved operation by severing the Chinese hacker group’s connection to the botnet.

By January 2025, the US had discovered more than 100 intrusions across the country and its territories linked to Typhoon Volt, Bloomberg reports. A large number of these attacks have targeted Guam, a US island territory in the Pacific and a strategic location for US military operations, the report said. Volt Typhoon reportedly targeted critical infrastructure on the island, including the main power authority, the island’s largest mobile phone provider, and several US federal networks, including sensitive defense systems, based on Guam. Bloomberg reported that Volt Typhoon used an entirely new type of malware to target networks in Guam that it had never deployed before, which researchers saw as a sign of the region’s importance to China-backed hackers.

Flax hurricane

Flax Typhoon, which was first released by Microsoft several months later August 2023 reportis another Chinese-backed hacking group that officials say has operated under the guise of a publicly traded Beijing-based cybersecurity firm to conduct hacks against critical infrastructure in recent years. Microsoft said Flax Typhoon – also active since mid-2021 – primarily targeted dozens of “government and education, critical manufacturing and information technology organizations in Taiwan”.

Then, in September 2023, the US government said it had taken control of another botnet, which consisted of hundreds of thousands of Internet-connected devices that had been hacked and used by Flax Typhoon to “conduct malicious online activity disguised as normal Internet traffic from the infected consumer devices.” Prosecutors said the botnet allowed other hackers backed by China’s government to “breach networks in the US and around the world to steal information and keep our infrastructure at risk.”

The Justice Department later confirmed Microsoft’s findings, adding that Flax Typhoon “also attacked many US and foreign companies.”

US officials said the botnet used by Flax Typhoon was managed and controlled by Beijing-based cybersecurity firm Integrity Technology Group. In January 2024, the US government sanctioned Integrity Tech for its alleged ties to Flax Typhoon.

Salt Typhoon

The latest – and potentially most ominous – group in China’s government-backed cyber army to be exposed in recent months is Salt Typhoon.

Salt Typhoon made headlines in October 2024 for a different kind of intelligence gathering operation. As first reported by the Wall Street Journalthe China-linked hacking group breached several US telecommunications and internet providers, including AT&T, Lumen (formerly CenturyLink) and Verizon. The Newspaper later reported in January 2025 that Salt Typhoon also breached US-based internet providers Charter Communications and Windstream. US cyber official Anne Neuberger said the federal government had identified an unnamed ninth phone company that had been hacked.

According to a referenceSalt Typhoon may have accessed these communications using compromised Cisco routers. Once inside the telco’s networks, the attackers were able to access customer call and text message metadata, including date and time stamps of customer communications, source and destination IP addresses, and phone numbers from more than one million users. most of which were people located in the Washington DC area. In some cases the hackers were capable of recording telephone audio from elderly Americans. Neuberger said a “large number” of those who accessed data were “government targets of interest”.

By hacking systems used by law enforcement agencies to collect court-authorized customer data, Salt Typhoon also potentially gained access to data and systems that host many of the US government’s data requests, including potential identities of Chinese US surveillance targets.

It is not yet known when the breach of the eavesdropping systems occurred, but it may date back to early 2024, according to the Journal report.

AT&T and Verizon told TechCrunch in December 2024 that their networks were secure after being targeted by the Salt Typhoon spying group. Lumen confirmed soon after that its network was free of the hackers.

Silk Typhoon

The Chinese-backed hacking group formerly known as Hafnium has quietly re-emerged as the newly named Silk Typhoon after being linked to a December 2024 hack of the US Treasury Department.

In a letter to lawmakers seen by TechCrunch, the U.S. Treasury Department said in late December 2024 that China-backed hackers used a key stolen from BeyondTrust — a company that provides identity access technology to large organizations and governments departments – to gain remote access to certain Workstations of employees of the Ministry of Finance, where they found internal documents on the department’s unclassified network.

During the hack, the state hacking group also breached the Treasury Department’s sanctions office, which imposes economic and trade sanctions against countries and individuals. It also breached the Treasury Department’s Committee on Foreign Investment in the United States (CFIUS) in December, an agency empowered to block Chinese investment in the United States.

Silk Typhoon is not a new threat group, previously making headlines in 2021 as Hafnium – as it was then known – for exploiting vulnerabilities in self-hosted Microsoft Exchange email servers that breached more than 60,000 organizations.

According to Microsoftwhich monitors the government-backed hacking group, Silk Typhoon typically focuses on identification and data theft and has been known to target healthcare organizations, law firms and non-governmental organizations in Australia, Japan, Vietnam and the United States.

First published on October 13, 2024 and updated.

China Chinese cyber security evergreen government sponsored hacking hackers Hacking Meet our government preparing Typhoon war
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe counter’s customers are now being forced to hand over their data or risk losing it, they say
Next Article Google searches to delete Facebook and Instagram rise after Meta completes background checks
bhanuprakash.cg
techtost.com
  • Website

Related Posts

ServiceNow is telling customers that a bug left some of their data exposed online

12 June 2026

Oracle warns of security flaw that hackers abused to breach 100+ companies

11 June 2026

Cybersecurity researchers not happy with guardrails in Anthropic’s Fable

11 June 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

SpaceX IPO: Everything You Need To Know

12 June 2026

Equal AI raises $30 million to screen calls so Indians don’t have to

12 June 2026

ServiceNow is telling customers that a bug left some of their data exposed online

12 June 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Ramp raises $750M at $44B valuation as investors thirst for fintechs with AI history

5 June 2026

Last 24 hours to save up to $410 on your Disrupt 2026 ticket

29 May 2026

2 days left: Lock in up to $410 in ticket savings for Disrupt 2026

28 May 2026
Startups

Military SPAC Quantum Space is trying to catch SpaceX’s IPO wave

Microsoft is using Alt Carbon as a sign of India’s growing role in carbon removal

Warner Music acquires artificial intelligence performance startup Sureel AI

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.