EPISODE · Jun 19, 2026 · 3 MIN
Living Off the Land: How China's Hackers Are Ghosting US Power Grids While We're All Watching TikTok
from Cyber Sentinel: Beijing Watch · host Inception Point AI
This is your Cyber Sentinel: Beijing Watch podcast. Hey listeners, Ting here with your Cyber Sentinel: Beijing Watch, so let’s jack straight into this week’s Chinese cyber moves hitting US security. The headline play is a shift from smash‑and‑grab espionage to quiet persistence. Microsoft and the US Cybersecurity and Infrastructure Security Agency recently highlighted Chinese state‑backed crews like Volt Typhoon burrowing into US critical infrastructure, especially power grids and telecom routes that support Pacific military logistics. Instead of encrypting files like classic ransomware, they live off the land: abusing built‑in tools like PowerShell, WMI, and scheduled tasks so that everything looks like a stressed‑out sysadmin, not a PLA hacker. On the methodology front, threat intel teams from Mandiant and Recorded Future have been flagging more China‑linked use of stolen code‑signing certificates from legitimate US and Taiwanese vendors. That lets malware slide past endpoint defenses as if it were a firmware update from a trusted brand. Think drivers, VPN clients, even security tools themselves getting hijacked as delivery vehicles. Targeted industries this week remain the usual greatest hits: US defense contractors, satellite and telecom providers, semiconductor firms, and cloud platforms. Palo Alto Networks’ Unit 42 has been tracing campaigns where Chinese operators pivot from small regional ISPs on the US West Coast into larger backbone providers, aiming to watch military mobility, not grandma’s Netflix. Meanwhile, healthcare and biotech stay hot targets as Beijing chases drug IP and genomic data to feed its domestic AI models. Attribution is tightening. CrowdStrike and the FBI have been correlating command‑and‑control infrastructure with previously known China‑based clusters, matching unique malware strings, working hours aligned to Beijing time, and even re‑used cryptographic keys that popped up in earlier PLA and Ministry of State Security operations. Add in overlaps with infrastructure documented by the UK’s National Cyber Security Centre and Australia’s ASD, and the “maybe it’s criminal” deniability is wearing thin. International response has been noisier than usual. The recent joint advisory from the US, UK, Canada, Australia, and New Zealand explicitly called out Chinese “pre‑positioning” in critical infrastructure as preparation for potential crisis or conflict, not just spying. The European Union has echoed concerns, especially after probing Chinese‑made networking and video‑surveillance gear; some countries are accelerating rip‑and‑replace programs for Dahua and Hikvision hardware over supply‑chain risk. So what do you do if you’re defending a US network? Tactically, crank up logging on admin tools, enforce just‑in‑time privileged access, and baseline your environment so that “normal” PowerShell and remote management stands out when abused. Segment OT from IT; if your power relay talks freely to your email server, you’ve already lost. Hunt specifically for long‑dwell anomalies instead of waiting for loud alerts. Strategically, executives need to treat China‑linked cyber activity as part of Beijing’s broader coercion toolkit, the same way navies treat activity in the South China Sea. That means mapping your company’s role in national critical functions, rehearsing incident response with law enforcement, and assuming that any edge‑facing device sourced from high‑risk vendors is both a sensor and a potential beachhead. I’m Ting, and that’s your Beijing Watch for this cycle. Thanks for tuning in, and don’t forget to subscribe so you don’t miss the next deep dive. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta
Embed this episode
Ready to play
Living Off the Land: How China's Hackers Are Ghosting US Power Grids While We're All Watching TikTok
No transcript for this episode yet
Similar Episodes
No similar episodes found.