Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

Google’s AI testing feature for clothes now only works with a selfie

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

    14 December 2025

    Trump’s AI executive order promises ‘a rulebook’ – startups may find legal loophole instead

    13 December 2025

    Ok, so what’s up with the LinkedIn algo?

    12 December 2025

    Google Released Its Deepest Research AI Agent To Date — The Same Day OpenAI Dropped GPT-5.2

    12 December 2025

    Disney hits Google with cease and desist alleging ‘massive’ copyright infringement

    11 December 2025
  • Apps

    Google’s AI testing feature for clothes now only works with a selfie

    14 December 2025

    DoorDash driver faces felony charges after allegedly spraying customers’ food

    13 December 2025

    Google Translate now lets you listen to real-time translations on your headphones

    13 December 2025

    With iOS 26.2, Apple lets you bring back Liquid Glass again — this time on the lock screen

    12 December 2025

    World launches its ‘super app’, including payment encryption and encrypted chat features

    12 December 2025
  • Crypto

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025

    Only 5 days until Disrupt 2025 sets the startup world on fire

    22 October 2025
  • Fintech

    Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

    7 December 2025

    Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

    5 December 2025

    Nexus stays out of AI, keeping half of its new $700M fund for India startup

    4 December 2025

    Fintech firm Marquis notifies dozens of US banks and credit unions of data breach after ransomware attack

    3 December 2025

    Revolut hits $75 billion valuation in new capital raise

    24 November 2025
  • Hardware

    Pebble founder unveils $75 AI smart ring to record short notes with the push of a button

    10 December 2025

    Amazon’s Ring launches controversial AI-powered facial recognition feature on video doorbells

    10 December 2025

    Google’s first AI glasses are expected next year

    9 December 2025

    eSIM adoption is on the rise thanks to travel and device compatibility

    6 December 2025

    AWS re:Invent was an all-in pitch for AI. Customers may not be ready.

    5 December 2025
  • Media & Entertainment

    Disney signs deal with OpenAI to allow Sora to create AI videos with its characters

    11 December 2025

    YouTube TV will launch genre-based subscription plans in 2026

    11 December 2025

    Founder of AI startup Tavus says users talk to AI Santa ‘for hours’ a day

    10 December 2025

    Spotify releases music videos in the US and Canada for Premium subscribers

    9 December 2025

    Amazon Music’s 2025 Delivered is now here to compete with Spotify Wrapped

    9 December 2025
  • Security

    The flaw in the photo booth manufacturer’s website exposes customers’ photos

    13 December 2025

    Home Depot exposed access to internal systems for a year, researcher says

    13 December 2025

    Security flaws in the Freedom Chat app exposed users’ phone numbers and PINs

    11 December 2025

    Petco takes down Vetco website after exposing customers’ personal information

    10 December 2025

    Petco’s security bug affected customers’ SSNs, driver’s licenses and more

    9 December 2025
  • Startups

    Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

    13 December 2025

    Interest in Spoor’s AI bird tracking software is soaring

    13 December 2025

    Retro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll

    12 December 2025

    On Me Raises $6M to Shake Up the Gift Card Industry

    12 December 2025

    1X has struck a deal to send its ‘homemade’ humanoids to factories and warehouses

    11 December 2025
  • Transportation

    Inside Rivian’s big bet on self-driving with artificial intelligence

    13 December 2025

    Zevo wants to add robotaxis to its car-sharing fleet, starting with newcomer Tensor

    13 December 2025

    Driving aboard Rivian’s fight for autonomy

    12 December 2025

    Rivian goes big on autonomy, with custom silicon, lidar and a hint of robotaxis

    12 December 2025

    Rivian’s AI assistant is coming to its electrics in early 2026

    11 December 2025
  • Venture

    Runware raises $50 million in Series A to make it easier for developers to create images and videos

    12 December 2025

    Stanford’s star reporter understands Silicon Valley’s startup culture

    12 December 2025

    The market has “changed” and founders now have the power, VCs say

    11 December 2025

    Tiger Global plans cautious business future with new $2.2 billion fund

    8 December 2025

    Sources: AI-powered synthetic research startup Aaru raises Series A at $1B ‘headline’ valuation

    6 December 2025
  • Recommended Essentials
TechTost
You are at:Home»Security»Meet the Chinese ‘Typhoon’ Hackers Preparing for War
Security

Meet the Chinese ‘Typhoon’ Hackers Preparing for War

techtost.comBy techtost.com12 January 202508 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Meet The Chinese 'typhoon' Hackers Preparing For War
Share
Facebook Twitter LinkedIn Pinterest Email

Of the cybersecurity risks facing the United States today, few are greater than the potential sabotage capabilities posed by China-backed hackers, who senior US national security officials have described as an “era-defining threat.”

The U.S. says Chinese government-backed hackers — in some cases for years — have burrowed deep into the networks of critical U.S. infrastructure, including water, energy and transportation providers. The goal, officials say, is to lay the groundwork for potentially devastating cyberattacks in the event of a future conflict between China and the United States, such as a possible Chinese invasion of Taiwan;.

“China’s hackers are placing themselves in American infrastructure preparing to wreak havoc and cause real harm to American citizens and communities if or when China decides it’s time to strike,” then-outgoing FBI Director Christopher Wray told lawmakers.

The US government and its allies have since taken action against some of the Chinese “Typhoon” family of hacking groups and released new details about the threats posed by these groups.

In January 2024, the US disrupted ‘Volt Typhoon’, a group of Chinese government hackers tasked with setting the stage for devastating cyber attacks. Later, in September 2024, federal authorities seized control of a botnet run by another Chinese hacker group called “Flax Typhoon,” which used a Beijing-based cybersecurity firm to help hide its government hacking activities China. Then, in December, the US government sanctioned the cybersecurity company for its alleged role in “multiple computer intrusion incidents against US victims.”

Since then, another new Chinese-backed hacking group called “Salt Typhoon” has emerged on the networks of US phone and internet giants, capable of gathering information about Americans – and potential US surveillance targets – by compromising telecommunications systems used for enforcement wiretapping. of the law.

And, a Chinese threat actor called Silk Typhoon (formerly known as Hafnium), a hacker group active since at least 2021, returned in December 2024 with a new campaign targeting the US Treasury.

Here’s what we learned about Chinese hacker groups preparing for war.

Volt Typhoon

Volt Typhoon represents a new breed of Chinese-backed hacking groups. it no longer aims simply to steal sensitive US secrets, but rather to prepare to disrupt the US military’s “mobilization capability,” according to the then-FBI director.

Microsoft first spotted Volt Typhoon in May 2023, finding that hackers had targeted and compromised network equipment such as routers, firewalls and VPNs since at least mid-2021 as part of an ongoing and coordinated effort to penetrate deep into US critical infrastructure systems. The US intelligence community said that in reality, it is possible that the hackers were operating for much longer, possibly as long as five years.

Volt Typhoon compromised thousands of these Internet-connected devices in the months following Microsoft’s report, exploiting vulnerabilities in devices that were considered “end-of-life” and therefore would no longer receive security updates. The hacking group subsequently gained further access to the IT environments of several critical infrastructure sectors, including aviation, water, energy and transportation, intending to enable future disruptive cyberattacks aimed at slowing down the US government’s response to an intrusion into her main ally. Taiwan.

“This actor does not do the quiet intelligence-gathering and secret-stealing that has been the norm in the US. They probe sensitive critical infrastructure so they can disrupt major services if and when the order collapses,” said John Hultquist, chief. analyst at security firm Mandiant.

THE The US government said in January 2024 that it had successfully disrupted a botnet, used by Volt Typhoon, consisting of thousands of compromised small office and home network routers in the US, which the Chinese hacking group used to hide its malicious activity aimed at targeting US critical infrastructure . The FBI said it was able to remove the malware from compromised routers through a court-approved operation by severing the Chinese hacker group’s connection to the botnet.

By January 2025, the US had discovered more than 100 intrusions across the country and its territories linked to Typhoon Volt, Bloomberg reports. A large number of these attacks have targeted Guam, a US island territory in the Pacific and a strategic location for US military operations, the report said. Volt Typhoon reportedly targeted critical infrastructure on the island, including the main power authority, the island’s largest mobile phone provider, and several US federal networks, including sensitive defense systems, based on Guam. Bloomberg reported that Volt Typhoon used an entirely new type of malware to target networks in Guam that it had never deployed before, which researchers saw as a sign of the region’s importance to China-backed hackers.

Flax hurricane

Flax Typhoon, which was first released by Microsoft several months later August 2023 reportis another Chinese-backed hacking group that officials say has operated under the guise of a publicly traded Beijing-based cybersecurity firm to conduct hacks against critical infrastructure in recent years. Microsoft said Flax Typhoon – also active since mid-2021 – primarily targeted dozens of “government and education, critical manufacturing and information technology organizations in Taiwan”.

Then, in September 2023, the US government said it had taken control of another botnet, which consisted of hundreds of thousands of Internet-connected devices that had been hacked and used by Flax Typhoon to “conduct malicious online activity disguised as normal Internet traffic from the infected consumer devices.” Prosecutors said the botnet allowed other hackers backed by China’s government to “breach networks in the US and around the world to steal information and keep our infrastructure at risk.”

The Justice Department later confirmed Microsoft’s findings, adding that Flax Typhoon “also attacked many US and foreign companies.”

US officials said the botnet used by Flax Typhoon was managed and controlled by Beijing-based cybersecurity firm Integrity Technology Group. In January 2024, the US government sanctioned Integrity Tech for its alleged ties to Flax Typhoon.

Salt Typhoon

The latest – and potentially most ominous – group in China’s government-backed cyber army to be exposed in recent months is Salt Typhoon.

Salt Typhoon made headlines in October 2024 for a different kind of intelligence gathering operation. As first reported by the Wall Street Journalthe China-linked hacking group breached several US telecommunications and internet providers, including AT&T, Lumen (formerly CenturyLink) and Verizon. The Newspaper later reported in January 2025 that Salt Typhoon also breached US-based internet providers Charter Communications and Windstream. US cyber official Anne Neuberger said the federal government had identified an unnamed ninth phone company that had been hacked.

According to a referenceSalt Typhoon may have accessed these communications using compromised Cisco routers. Once inside the telco’s networks, the attackers were able to access customer call and text message metadata, including date and time stamps of customer communications, source and destination IP addresses, and phone numbers from more than one million users. most of which were people located in the Washington DC area. In some cases the hackers were capable of recording telephone audio from elderly Americans. Neuberger said a “large number” of those who accessed data were “government targets of interest”.

By hacking systems used by law enforcement agencies to collect court-authorized customer data, Salt Typhoon also potentially gained access to data and systems that host many of the US government’s data requests, including potential identities of Chinese US surveillance targets.

It is not yet known when the breach of the eavesdropping systems occurred, but it may date back to early 2024, according to the Journal report.

AT&T and Verizon told TechCrunch in December 2024 that their networks were secure after being targeted by the Salt Typhoon spying group. Lumen confirmed soon after that its network was free of the hackers.

Silk Typhoon

The Chinese-backed hacking group formerly known as Hafnium has quietly re-emerged as the newly named Silk Typhoon after being linked to a December 2024 hack of the US Treasury Department.

In a letter to lawmakers seen by TechCrunch, the U.S. Treasury Department said in late December 2024 that China-backed hackers used a key stolen from BeyondTrust — a company that provides identity access technology to large organizations and governments departments – to gain remote access to certain Workstations of employees of the Ministry of Finance, where they found internal documents on the department’s unclassified network.

During the hack, the state hacking group also breached the Treasury Department’s sanctions office, which imposes economic and trade sanctions against countries and individuals. It also breached the Treasury Department’s Committee on Foreign Investment in the United States (CFIUS) in December, an agency empowered to block Chinese investment in the United States.

Silk Typhoon is not a new threat group, previously making headlines in 2021 as Hafnium – as it was then known – for exploiting vulnerabilities in self-hosted Microsoft Exchange email servers that breached more than 60,000 organizations.

According to Microsoftwhich monitors the government-backed hacking group, Silk Typhoon typically focuses on identification and data theft and has been known to target healthcare organizations, law firms and non-governmental organizations in Australia, Japan, Vietnam and the United States.

First published on October 13, 2024 and updated.

China Chinese cyber security evergreen government sponsored hacking hackers Hacking Meet our government preparing Typhoon war
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThe counter’s customers are now being forced to hand over their data or risk losing it, they say
Next Article Google searches to delete Facebook and Instagram rise after Meta completes background checks
bhanuprakash.cg
techtost.com
  • Website

Related Posts

The flaw in the photo booth manufacturer’s website exposes customers’ photos

13 December 2025

Home Depot exposed access to internal systems for a year, researcher says

13 December 2025

Security flaws in the Freedom Chat app exposed users’ phone numbers and PINs

11 December 2025
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

OpenAI hits back at Google with GPT-5.2 after ‘code red’ memo.

14 December 2025

Google’s AI testing feature for clothes now only works with a selfie

14 December 2025

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

13 December 2025
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Coinbase starts onboarding users again in India, plans to do fiat on-ramp next year

7 December 2025

Walmart-backed PhonePe shuts down Pincode app in yet another step back in e-commerce

5 December 2025

Nexus stays out of AI, keeping half of its new $700M fund for India startup

4 December 2025
Startups

Eclipse Energy’s microbes can turn dormant oil wells into hydrogen factories

Interest in Spoor’s AI bird tracking software is soaring

Retro, a photo-sharing app for friends, lets you ‘time travel’ to your camera roll

© 2025 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.