Numerous North American critical infrastructure entities have been breached by Chinese state-sponsored threat operation UAT-8837 since last year, reports The Record, a news site by cybersecurity firm Recorded Future.Initial compromise through the exploitation of multiple vulnerabilities, including the critical Sitecore zero-day, tracked as CVE-2025-53690, allowed UAT-8837 to launch other hacking tools to facilitate further systems access, such as Earthworm, according to an analysis from Cisco Talos researchers. Earthworm, which has been leveraged by other Chinese hacking groups, facilitates the discovery of undetectable internal endpoints that are then exploited to establish a reverse tunnel to attacker-controlled servers, said researchers.Such findings come after Chinese state-backed threat group Salt Typhoon was reported to have targeted the email accounts of Congressional staffers, including those working for the House China Committee, Armed Services Committee, Foreign Affairs Committee, and Intelligence Committee, in a December cyberespionage campaign.
Critical Infrastructure Security, Threat Intelligence
North American critical infrastructure subjected to Chinese attacks

(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



