China's Cyber Crews Go Shopping: Volt Typhoon Slides Into US Power Grids While APT31 Swipes Corporate Passwords episode artwork

EPISODE · Jun 22, 2026 · 3 MIN

China's Cyber Crews Go Shopping: Volt Typhoon Slides Into US Power Grids While APT31 Swipes Corporate Passwords

from Digital Frontline: Daily China Cyber Intel · host Inception Point AI

This is your Digital Frontline: Daily China Cyber Intel podcast. Listeners, it’s Ting on Digital Frontline, and the China cyber crew has been busy. Across the last 24 hours, several US-focused threat intel feeds are flagging fresh activity linked to clusters long associated with the Ministry of State Security and the People’s Liberation Army, especially the groups commonly tracked as Volt Typhoon, APT31, and APT41. Analysts at Mandiant and CrowdStrike report renewed probing of US critical infrastructure edge devices, especially VPN appliances and older firewall models in energy, telecom, and transportation networks, with scans coming from Chinese cloud providers and bulletproof hosting in Hong Kong and Shenzhen. The big theme: quiet persistence. Volt Typhoon-style operators are still leaning on living-off-the-land techniques inside power utilities and regional ISPs, using built‑in Windows tools like PowerShell and WMI rather than malware, so they blend into normal admin noise. Microsoft’s security team and CISA warn that compromised small-town telecom and managed service providers in places like Ohio and Texas are being used as staging points into larger federal and defense contractor networks. Over in research and academia, Recorded Future and Proofpoint saw a spike in spear‑phishing targeting US universities tied to AI, quantum, and semiconductor projects. Messages pretend to be from real professors at Tsinghua University and the Chinese Academy of Sciences, inviting “collaboration” and sending booby‑trapped PDF proposals that drop custom loaders only when opened on campus networks. On the corporate side, financial services and aerospace vendors are dealing with password‑spray attacks against Outlook and Okta logins, traced to infrastructure historically used by APT31, also called Zirconium. The goal looks like long‑term access to deal data, not smash‑and‑grab ransomware. Several incident responders are calling this “pre‑positioning for leverage” in future negotiations or sanctions fights. Defensive advisories from CISA, the FBI, and NSA are doubling down on a few urgent steps. They stress immediate patching of edge gear from vendors like Cisco, Fortinet, and Palo Alto, enforcing phishing‑resistant multi‑factor authentication on all remote access, and hunting for odd command‑line usage, unusual account creation, and outbound connections to low‑reputation Chinese VPS providers. They also highlight the need to monitor logs from small subsidiaries and third‑party IT providers that often get ignored but are being heavily targeted. So here’s the Ting playbook for businesses. First, lock down identity: enforce strong MFA, kill legacy mail protocols, and review every admin account this week. Second, harden the edge: patch or replace end‑of‑life VPNs and firewalls, turn on logging, and ship those logs to a SIEM that someone actually watches. Third, assume compromise and hunt: create detections for excessive PowerShell, RDP from unusual locations, and data being exfiltrated to unfamiliar Asian IP ranges at odd hours. Finally, rehearse: run a China‑style intrusion tabletop with your execs so that if Volt Typhoon or APT41 walks in the front door, your team doesn’t panic, they execute. I’m Ting, thanks for tuning in to Digital Frontline. Make sure you subscribe so you don’t miss tomorrow’s intel. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

This is your Digital Frontline: Daily China Cyber Intel podcast. Listeners, it’s Ting on Digital Frontline, and the China cyber crew has been busy. Across the last 24 hours, several US-focused threat intel feeds are flagging fresh activity linked to clusters long associated with the Ministry of State Security and the People’s Liberation Army, especially the groups commonly tracked as Volt Typhoon, APT31, and APT41. Analysts at Mandiant and CrowdStrike report renewed probing of US critical infrastructure edge devices, especially VPN appliances and older firewall models in energy, telecom, and transportation networks, with scans coming from Chinese cloud providers and bulletproof hosting in Hong Kong and Shenzhen. The big theme: quiet persistence. Volt Typhoon-style operators are still leaning on living-off-the-land techniques inside power utilities and regional ISPs, using built‑in Windows tools like PowerShell and WMI rather than malware, so they blend into normal admin noise. Microsoft’s security team and CISA warn that compromised small-town telecom and managed service providers in places like Ohio and Texas are being used as staging points into larger federal and defense contractor networks. Over in research and academia, Recorded Future and Proofpoint saw a spike in spear‑phishing targeting US universities tied to AI, quantum, and semiconductor projects. Messages pretend to be from real professors at Tsinghua University and the Chinese Academy of Sciences, inviting “collaboration” and sending booby‑trapped PDF proposals that drop custom loaders only when opened on campus networks. On the corporate side, financial services and aerospace vendors are dealing with password‑spray attacks against Outlook and Okta logins, traced to infrastructure historically used by APT31, also called Zirconium. The goal looks like long‑term access to deal data, not smash‑and‑grab ransomware. Several incident responders are calling this “pre‑positioning for leverage” in future negotiations or sanctions fights. Defensive advisories from CISA, the FBI, and NSA are doubling down on a few urgent steps. They stress immediate patching of edge gear from vendors like Cisco, Fortinet, and Palo Alto, enforcing phishing‑resistant multi‑factor authentication on all remote access, and hunting for odd command‑line usage, unusual account creation, and outbound connections to low‑reputation Chinese VPS providers. They also highlight the need to monitor logs from small subsidiaries and third‑party IT providers that often get ignored but are being heavily targeted. So here’s the Ting playbook for businesses. First, lock down identity: enforce strong MFA, kill legacy mail protocols, and review every admin account this week. Second, harden the edge: patch or replace end‑of‑life VPNs and firewalls, turn on logging, and ship those logs to a SIEM that someone actually watches. Third, assume compromise and hunt: create detections for excessive PowerShell, RDP from unusual locations, and data being exfiltrated to unfamiliar Asian IP ranges at odd hours. Finally, rehearse: run a China‑style intrusion tabletop with your execs so that if Volt Typhoon or APT41 walks in the front door, your team doesn’t panic, they execute. I’m Ting, thanks for tuning in to Digital Frontline. Make sure you subscribe so you don’t miss tomorrow’s intel. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

NOW PLAYING

China's Cyber Crews Go Shopping: Volt Typhoon Slides Into US Power Grids While APT31 Swipes Corporate Passwords

0:00 3:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Darknet Discussions Darknet Discussions Welcome to "Darknet Discussions," the podcast that gets into the shadows of the internet to bring you the most intriguing, enlightening, and sometimes unsettling stories from the dark web. Hosted by seasoned darknet aficionados, each episode of "Darknet Discussions" explores the intricate dynamics of darknet markets, cybersecurity threats, and the digital underworld. Join us as we interview experts, discuss the latest trends in cybercrime, and shed light on the technologies that operate beneath the surface of everyday internet use. Also, we occasionally go off on a tangent about something completely unrelated. The Digital Experience Show by Enonic Enonic All you need to know about digital strategy, digital experiences, and CMS are covered in this podcast. Powered by NotebookLM. Christadelphian Encouragements CE.captivate.fm Christadelphian Encouragements provides sermons, exhortations, bible studies, memorials, and daily readings from around the world. Please visit ChristadelphianEncouragements.Com and our content creators websites for more information and Christian audio content. CISO Perspectives (public) N2K Networks This season on CISO Perspectives, host Kim Jones explores some of the challenges of leading through uncertainty. We explore the complexity of the changing nature of regulation and working with the federal government, the evolution of privacy and fraud, and how emerging technologies like AI and quantum computing are changing cyber. When you don’t know what questions to ask, you’re afraid to ask, or don’t know who to ask, CISO Perspectives provides the foundation for learning in this brave new world.

Frequently Asked Questions

How long is this episode of Digital Frontline: Daily China Cyber Intel?

This episode is 3 minutes long.

When was this Digital Frontline: Daily China Cyber Intel episode published?

This episode was published on June 22, 2026.

What is this episode about?

This is your Digital Frontline: Daily China Cyber Intel podcast. Listeners, it’s Ting on Digital Frontline, and the China cyber crew has been busy. Across the last 24 hours, several US-focused threat intel feeds are flagging fresh activity linked...

Can I download this Digital Frontline: Daily China Cyber Intel episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!