EPISODE · Jun 19, 2026 · 3 MIN
China's Secret Sleeper Cells in Your Power Grid: The Infrastructure Hack Nobody Saw Coming
from Dragon's Code: America Under Cyber Siege · host Inception Point AI
This is your Dragon's Code: America Under Cyber Siege podcast. Name’s Ting, your friendly neighborhood China-and-cyber nerd, and this week’s episode of Dragon’s Code: America Under Cyber Siege is…busy. Let’s jump straight to the hottest op: what analysts at Mandiant and CrowdStrike are calling a coordinated push by Chinese state-linked groups, including Volt Typhoon–style clusters, against US power and port infrastructure on both coasts. According to reports circulating among DHS and CISA briefings, the attackers focused on industrial control systems that manage power distribution, port cranes, and some regional water utilities, not to cause immediate blackout chaos, but to pre-position for future leverage. Methodology first, because I know my listeners. The crews are going “living off the land” all the way: abusing built‑in Windows tools like PowerShell and WMI, sneaking in via compromised VPN credentials, and then blending into normal network traffic. Several security teams say the intrusions rode in on old but still unpatched Fortinet and Ivanti gateways, plus stolen credentials bought from initial access brokers on Russian-language forums. Once inside, they pivoted laterally, mapped OT networks, and quietly dropped custom backdoors that talk out over HTTPS to cloud providers to look like normal business traffic. The affected systems? A West Coast power operator’s grid-monitoring network, at least two Gulf Coast ports’ logistics systems, and a Midwestern water utility’s remote pump controllers. None of these were allowed to flip physical switches, thanks to segmentation and some frantic cable‑pulling, but incident responders say the access was deep enough to be operationally serious. On attribution, the usual “China strongly denies” statement hit X within hours, but NSA and US Cyber Command officials briefed reporters that the malware toolchains, command‑and‑control infrastructure, and working hours all lined up with established PRC-linked outfits long tracked under names like Volt Typhoon and APT41. Microsoft and Google Cloud threat intel teams independently reported overlaps in infrastructure with earlier campaigns targeting Guam telecom and defense contractors, which hardened the case. Defensively, CISA pushed out emergency directives telling federal agencies and critical infrastructure operators to hunt for specific command patterns, disable outdated VPN appliances, and turn on strict multi-factor authentication everywhere. Several utilities spun up 24/7 threat-hunting cells, pulled their most sensitive OT networks fully offline from corporate IT, and deployed anomaly detection tuned to spot exactly this low‑and‑slow style of intrusion. The FBI’s Cyber Division also quietly knocked on doors of managed service providers that had been used as supply-chain stepping stones. Lessons learned? First, that “peacetime” is a myth in cyberspace; this is long‑term battlespace prep. Second, that identity is the new perimeter: stolen credentials are now more dangerous than zero‑days. Third, segmentation and rehearsed incident response saved the day; people who practiced tabletop exercises with CISA moved faster and lost less sleep. Cyber experts like Dmitri Alperovitch and former CISA director Chris Krebs are already arguing that these Chinese operations prove critical infrastructure needs security standards closer to nuclear-plant rigor than to office Wi‑Fi. I’m Ting, and if you’re still with me, you’re exactly the kind of listener I want in this cyber foxhole. Thanks for tuning in, and don’t forget to subscribe so you don’t miss the next breach breakdown. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta
Embed this episode
Ready to play
China's Secret Sleeper Cells in Your Power Grid: The Infrastructure Hack Nobody Saw Coming
No transcript for this episode yet
Similar Episodes
No similar episodes found.