EPISODE · Jan 9, 2026 · 5 MIN
Beijing's Backstage Pass: How China Hacked Congress While We Were All Looking at TikTok
from Red Alert: China's Daily Cyber Moves · host Inception Point AI
This is your Red Alert: China's Daily Cyber Moves podcast. Name’s Ting, and listeners, we are on Red Alert. In the last 72 hours, China-linked operators have been moving quietly but fast across global networks, and the blast radius points straight at U.S. interests. Government Executive reports that Chinese hackers have targeted email systems for staff on key House committees, including Foreign Affairs, Intelligence, and Armed Services, likely tied to the notorious Salt Typhoon crew that already burrowed into major U.S. telecoms like AT&T and Verizon for years. Techdirt’s deep dive on Salt Typhoon shows they once had historic access to phone and email traffic for top U.S. officials, and the new congressional email hits look like Phase Two of that same campaign. Timeline it with me. First, late last year, Salt Typhoon’s telecom hack finally comes into focus: years of undetected access, then another year of persistence even after discovery, thanks to sloppy defaults and legal teams telling engineers to stop hunting for intrusions, as reported by Techdirt. That’s your groundwork: long-term wiretap on U.S. communications. Fast forward to this week. According to Government Executive and analysis at Breached Company, Chinese state-aligned actors are now inside House staff email systems, likely pivoting from the telecom insight they already harvested. SecurityWeek notes this fits a broader pattern: Chinese cyberattacks against U.S. government emails as part of a wider espionage push, while simultaneously ramping operations against Taiwan. At the same time, Cisco Talos and Cyware’s January 9 threat briefing flag UAT-7290, a China-linked group using Linux malware and Operational Relay Box nodes to compromise telecoms in South Asia and Southeastern Europe. Those ORB nodes can serve as global proxies and launch pads, meaning U.S. networks see traffic that looks “foreign and benign,” but is really Beijing’s Ministry of State Security bouncing signals off third countries. On the U.S. side, CISA just retired ten legacy Emergency Directives, as reported by BackBox and The Hacker News, folding their protections into broader guidance. That’s not an all-clear; that’s CISA saying, “You should already be doing this by default,” even as China-linked crews are exploiting SonicWall VPN appliances and VMware ESXi zero-days, according to BleepingComputer and The Hacker News, to gain hypervisor-level control in environments that often host U.S. government and defense contractors. So what are the live defensive actions? Patch SonicWall and ESXi yesterday; lock down Microsoft 365 and enforce MFA across all admin portals; audit mail routing so internal spoofing and domain misconfig don’t give Chinese phishers a free pass, as Microsoft’s own threat intel team recently warned. For congressional, state, and contractor networks, assume email and VoIP metadata may already be compromised and move to strict least-privilege, hardware-backed authentication, and continuous anom This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
Beijing's Backstage Pass: How China Hacked Congress While We Were All Looking at TikTok
No transcript for this episode yet
Similar Episodes
No similar episodes found.