EPISODE · Jun 8, 2026 · 3 MIN
China's Cyber Spies Are Hiding in Your Slack and Microsoft 365: The SaaS Heist You Didn't See Coming
from Cyber Sentinel: Beijing Watch · host Inception Point AI
This is your Cyber Sentinel: Beijing Watch podcast. Hey listeners, Ting here with your Cyber Sentinel: Beijing Watch, so let’s jack straight into this week’s China–US cyber chessboard. According to the cybersecurity team at Mandiant, one of the big stories is a Chinese-linked group they track as APT41 experimenting with “living off the SaaS land” attacks against US tech and healthcare companies. Instead of dropping obvious malware, they’re abusing legitimate services like Microsoft 365, GitHub, and Slack to exfiltrate data quietly, blending into normal traffic. CrowdStrike analysts say similar tactics are expanding into US biotech and semiconductor design firms, especially those doing AI accelerator research. On the critical infrastructure front, researchers at Dragos and Recorded Future report continued activity from Chinese clusters like RedEcho and Volt Typhoon quietly mapping US power grids, telecom backbones, and maritime logistics networks. Volt Typhoon is still leaning on compromised SOHO routers from brands like Cisco, Netgear, and TP-Link as covert relay nodes, which makes attribution tough and takedown slow. Targeted industries this past week: US defense contractors working on Pacific naval systems, satellite communications providers, AI chip designers, and a surprising uptick in targeted phishing against state-level government agencies in California, Virginia, and Texas, according to Proofpoint and Trellix. The lures are getting painfully specific: fake RFQ documents, spoofed invoices referencing real contract numbers, and even deepfaked voicemail callbacks to validate the scam. On attribution, Secureworks and Google’s Mandiant unit have tied several recent campaigns to Chinese state-linked groups like APT31 and APT10 using overlapping infrastructure, reused malware loaders, and compilation timestamps that conveniently line up with Beijing working hours. There is also increased use of Chinese-language open-source offensive tools like SharpHound forks and custom Cobalt Strike variants, slightly modified but still recognizable to threat hunters. Internationally, the US, UK, and Australia have pushed out joint advisories through CISA and the UK’s NCSC warning about long-term pre-positioning in critical infrastructure, essentially calling it preparation for potential crisis-time disruption. The European Union’s cyber diplomacy toolbox has also been invoked in discussions, with Brussels signaling that persistent Chinese cyber espionage against member states may trigger coordinated sanctions. Tactically, listeners, this means US organizations need to harden identity and access above all. That means phishing-resistant MFA using FIDO2 keys for admins, strict conditional access policies, continuous monitoring of OAuth app grants, and aggressive disabling of legacy protocols. Endpoint detection and response tools should be tuned to catch credential theft, unusual PowerShell use, and data moving to atypical cloud repositories. Strategically, the implication is that we’re in a long, low-visibility competition: Beijing is building detailed maps of US networks, supply chains, and choke points, aiming for leverage in any future Taiwan or South China Sea crisis. The smart move for US defenders is to treat Chinese intrusion sets like a chronic condition, not a one-off incident: assume compromise, hunt constantly, segment networks, and bake resilience and rapid recovery into every critical system. Thanks for tuning in, listeners, and don’t forget to subscribe. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta
Embed this episode
Ready to play
China's Cyber Spies Are Hiding in Your Slack and Microsoft 365: The SaaS Heist You Didn't See Coming
No transcript for this episode yet
Similar Episodes
No similar episodes found.