EPISODE · Oct 24, 2025 · 5 MIN
China's Cyber Sleeper Cells: NSA Blamed for Planting Landmines in Beijing's Backyard
from Cyber Sentinel: Beijing Watch · host Inception Point AI
This is your Cyber Sentinel: Beijing Watch podcast. Hey listeners, Ting here, and welcome back to Cyber Sentinel: Beijing Watch. You want to know what’s been cooking in the cyber skirmishes between China and the U.S.? Grab your caffeine, because we are diving straight into the soup—no preamble, just truth, just like the Great Firewall hates. Beijing has been extra vocal this week. Foreign Ministry Spokesperson Guo Jiakun basically stood at the podium and accused the U.S. National Security Agency—yes, that NSA—of planting cyber landmines in Chinese infrastructure, warning that Washington’s fingers are all over China’s critical networks, and not in a good way. According to Guo, citing the Chinese National Computer Network Emergency Response Team, these aren’t just snoops; they’re sleeper cells, “presetting vulnerabilities for future large-scale sabotage activities.” Strong words. The so-called “Volt Typhoon,” which the U.S. previously blamed on China? Guo says that was a red herring, a transnational ransomware group, while the real Volt Typhoon playbook is actually the NSA’s doing. At this rate, we might need a Venn diagram just for the finger-pointing. Meanwhile, the Trellix Advanced Research Center has been tracking a global spike in nation-state mischief. The industrial sector is taking the heaviest fire—890 posts, or 36.57% of sector attacks, with the U.S. topping the victim list. And it’s not just brute force. We’re seeing a blend of old-school malware and new-school AI-powered nasties, plus a rise in “malware-less” insider tricks. Remember April? Chinese aircraft carrier Shandong and its strike group throwing naval exercises near Taiwan, while Chinese APTs ramped up activity—Trellix saw a clear, data-backed surge in China-linked cyber ops right alongside those military maneuvers. That’s what I call a multi-domain strategy: flexing at sea, probing online. Let’s talk tools. China-based hackers—think Budworm, Violet Typhoon (Sheathminer), and Storm-2603—are exploiting patched flaws like CVE-2025-53770 in SharePoint servers, according to Broadcom’s Symantec Threat Hunter Team. They hit a Middle Eastern telecom, African and South American agencies, and yes, a U.S. university. Tools like Zingdoor, KrustyLoader, and ShadowPad are in play, using DLL sideloading and webshells to open backdoors, steal creds, and move laterally. These aren’t smash-and-grabs—they’re surgical, persistent, and opportunistic. But Beijing isn’t just watching the rear. There’s also the Smishing Triad, a China-linked crew running a global phishing empire. Palo Alto Networks Unit 42 reports they’ve spun up 194,000 domains since 2024, targeting everything from toll services to government portals, with infrastructure largely hosted on U.S. cloud platforms. The scale is breathtaking: 93,200 domains registered through Hong Kong’s Dominet, most active for just days before burning out. It’s a digital shell game on steroids, and the U.S. Postal Service is their favorite disguise— This content was created in partnership and with the help of Artificial Intelligence AI.
Embed this episode
NOW PLAYING
China's Cyber Sleeper Cells: NSA Blamed for Planting Landmines in Beijing's Backyard
No transcript for this episode yet
Similar Episodes
No similar episodes found.