Ting Spills the Tea: China's Hackers Are Literally Practicing How to Turn Off Your Lights episode artwork

EPISODE · Jun 17, 2026 · 3 MIN

Ting Spills the Tea: China's Hackers Are Literally Practicing How to Turn Off Your Lights

from Dragon's Code: America Under Cyber Siege · host Inception Point AI

This is your Dragon's Code: America Under Cyber Siege podcast. Name’s Ting. Let’s jack straight into Dragon’s Code: America Under Cyber Siege. Over the past few days, listeners, Chinese state-backed crews have been running some of the most sophisticated probing campaigns against US infrastructure we’ve seen this quarter. According to analysts at Mandiant and CrowdStrike, clusters linked to Volt Typhoon and APT41 have shifted from quiet reconnaissance to what one DHS official called “pre‑positioning for pressure,” especially against power grids and telecom backbones on the US East and Gulf Coasts. Method-wise, this wasn’t smash-and-grab ransomware. This was living-off-the-land. Operators slipped in through exposed VPN appliances and edge devices from vendors like Fortinet and Ivanti, then used built‑in tools like PowerShell, WMI, and scheduled tasks so their activity looked like a sleepy system admin on a night shift. Microsoft’s threat intel team has been warning that these China-nexus actors increasingly hijack legitimate credentials from contractors instead of dropping noisy malware, and that pattern held all week. What got touched? According to reports shared with CISA’s Joint Cyber Defense Collaborative, they hit operational technology at regional electric utilities, management interfaces for smart grid controllers, and network management systems in Tier‑1 ISPs. No lights-out moment, but in at least one unnamed utility in the Midwest, incident responders found test commands run against substation control systems—think rehearsal, not attack. Attribution is always the spicy part. This round tied back to familiar infrastructure: command-and-control servers previously mapped to Chinese operators, overlapping malware loaders seen in earlier Volt Typhoon operations, and time-of-day patterns matching work hours in Guangdong and Hainan. NSA’s Rob Joyce-style analysts pointed to reuse of custom tunneling tools and a preference for web shells on outdated IIS servers, signatures long associated with PRC-linked espionage units. Defensively, the US didn’t just watch. CISA pushed emergency directives for federal agencies to rotate credentials, segment OT from IT where it was still embarrassingly flat, and deploy enhanced logging to catch anomalous lateral movement. Several utilities invoked their playbooks under the NERC CIP standards, isolating affected substations and running manual override drills. Cloud providers like Amazon Web Services and Microsoft Azure quietly blocked suspect IP ranges and issued new detection rules to customers. Cybersecurity experts from places like the Atlantic Council and Stanford’s Internet Observatory are calling this week a wake-up that “steady-state intrusion” is now normal, not exceptional. The big lesson: attackers are betting on weak identity management and ancient edge gear more than zero-days. Multi-factor authentication, hardware security keys for admins, and ruthless patching of internet-facing devices did the most damage to these campaigns. And from government officials at the White House Office of the National Cyber Director, the message was blunt: treat Chinese cyber operations against infrastructure as strategic shaping, not random hacking. In other words, this is about leverage in a crisis. I’m Ting, thanks for tuning in, listeners. Don’t forget to subscribe so you don’t miss the next dive into Dragon’s Code. This has been a quiet please production, for more check out quiet please dot ai. For more http://www.quietplease.ai Get the best deals https://amzn.to/3ODvOta

Episode metadata supplied by the publisher feed · Published Jun 17, 2026

Embed this episode

Ready to play

Ting Spills the Tea: China's Hackers Are Literally Practicing How to Turn Off Your Lights

0:00 3:40

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Dragon's Code: America Under Cyber Siege?

This episode is 3 minutes long.

When was this Dragon's Code: America Under Cyber Siege episode published?

This episode was published on June 17, 2026.

Can I download this Dragon's Code: America Under Cyber Siege episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!