Security researchers warn that Chinese state hackersare increasingly relying on a vast network of proxy servers (ORBs), created from virtual private servers and compromised electronic devices, for cyberespionage operations.
See also: Iranian hackers target Albania and Israel with wiping attacks

These proxy networks, called operational relay boxes (ORBs), are run by independent cybercriminals who provide access to multiple state-sponsored threat actors (APTs). ORBs are similar to botnets, but are a hybrid of commercially leased VPS services and compromised devices, including end-of-life routers and other IoT products.
The increasing use of ORBs by Chinese hackers comes with challenges in both detection and performance, as the attack infrastructure is no longer controlled by the threat actor, who can cycle through nodes distributed over a wide area.
Malicious proxy networks
Cybersecurity firm Mandiant is monitoring several ORBs, two of which are used by advanced Chinese hackers known for espionage and intellectual theft operations linked to the Chinese government.
One of them, called ORB3/SPACEHOP, is described as “a very active network leveraged by multiple China-nexus threat actors, including APT5 and APT15,” for vulnerability identification and exploitation. For example, SPACEHOP was used in December 2022 to exploit CVE -2022-27518, a critical vulnerability in Citrix ADC and Gateway, which the National Security Agency (NSA) linked to APT5 (also known as Manganese, Mulberry Typhoon, Bronze Fleenda, and UNC2630).
See also: Guy Verhofstadt: Former Belgian Prime Minister a victim of Chinese hackers

Mandiant researchers say the ORB SPACEHOP network used by Chinese hackers is a preemptive network that uses a relay server hosted in Hong Kong or China by a cloud. It installs an open-source command and control (C2) framework that allows for node management.
Instead, ORB2/FLORAHOX is a hybrid network consisting of an Adversary Controlled Operations Server (ACOS), compromised connected devices (routers and IoT), and VPS services that route traffic through TOR and multiple compromised routers. The researchers believe that this mesh is “espionage campaigns cyber by a diverse set of China-nexus threat actors” to obfuscate traffic from the source.
The ORB network exploited by Chinese hackers appears to contain multiple subnetworks consisting of compromised devices recruited by the FLOWERWATER router implant as well as other router-based payloads.
Although ORB2/FLORAHOX is used by multiple threat actors, Mandiant says that credible third-party sources have reported activity attributed to China-linked APT31/Zirconium adversaries focused on intellectual property theft
See also: Cyberattacks by Chinese hackers are increasing in the Philippines
The main motivations of Chinese hackers include state support and national security. Many hackers work on behalf of the Chinese government, with the goal of obtaining military and political information that could enhance China’s national security. Economic espionage is another major motivation. Chinese hackers, such as those using the ORB network, often target businesses and industries in other countries to obtain trade secrets, intellectual property, and other valuable information that can give China a competitive advantage in the global marketplace. Political influence and propaganda are also motivations for Chinese hackers. Through cyberattacks and disinformation, they seek to influence political developments in other countries, destabilize governments, and advance the Chinese agenda. Technological innovation and scientific research are also targets. Hackers are seeking to gain access to research data and cutting-edge technologies in order to accelerate China's development in the fields of science and technology.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
