Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Chinese Infrastructure Hackers: Living Off The Land

Rubrik
09/29/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


It's 2020. We start spotting Chinese hackers tucked deep inside our infrastructure, quiet, patient, just waiting. The industry calls this living off the land. But don't let that rustic name fool you. These hacks are far from harmless. They're sleeper cells waiting for marching orders. We just didn't know what, exactly. Here's Kevin Mandia. And all of a sudden we see Chinese threat groups, since about late 2020, at least from my observables, hack in and we don't know why, because they're not the tank through the cornfield. They're hacking in and just, that's it. There's no other activity. And then you're like, why are they there? And it's maybe to have access later, maybe it's to mine user IDs and passphrases. You know, there's no better way to compromise any organization than you can just log in, period. It's the best way to breach an organization is log into it the same way the employees do. There's just no evidence. And that's what living off the land means. There's no malicious code. There's no backdoor. There's good operational security. If they created a log file that's suspicious, they would edit it. When they wanted to go surreptitious, they were good at it. And that's the thing about digital evidence. You can edit it or delete it. You can change it. You know, it's different than the physical world. You can do some wonderful things if you're on offense and you have the patience and time and skill to do it. By this point, you almost certainly understand that the CCP absolutely has the patience, time and skill. But in theory, so do we. So how did we let it get this far? How did we allow China's hackers to so intimately invade our most critical infrastructure? I'm Nicole Prolarath and this is To Catch a Thief. The answer to that question of how we let things get this out of hand is where a number of trends converge. I've walked you through China's hacking advancements and the creeping emergency of global supply chains. But what made this the perfect storm was our uniquely American blind spots. For one, despite the impression left by Snowden, the NSA and other U.S. intelligence agencies aren't actually in your private networks watching what you do. Or in this case, what Chinese hackers are doing. Not without running straight into the Fourth Amendment. The NSA is a foreign intelligence agency. It hunts for threats abroad. Its charter doesn't allow it to hunt for hackers on private American networks, not without a warrant or a special court order. And what you need to understand is that the vast majority of U.S. critical infrastructure, pipelines, the power grid, water, hospitals, more than 80 percent of it is in private sector hands, meaning the government has no visibility into it. They can't deflect attacks on those private systems or even hunt there unless they've got a court order or they're invited in. To a large degree, when it comes to these living off the land attacks, we're flying blind. Our second big vulnerability is that the United States is among the most digitally dependent nations on Earth. We've been baking technology, code into everything with security as little more than an afterthought. We let software eat the world. And we did it with this, quote unquote, move fast and break things approach, as Mark Zuckerberg coined Facebook's motto in its early days. The idea was just get the application, get the code, get the router to market, and we can worry about the bugs and security issues later. What this means in effect is that we've been plugging vulnerable software and hardware into our infrastructure with little, if any, security baked in by default. And then we leave it to these businesses and critical infrastructure operators like Nick Lawler and Littleton to figure out the security piece on the back end. The people who designed routers never thought that one day they'd be the linchpin for advanced nation state attacks. And China has been using all of this to its advantage. Because by 2020, most Americans had grown somewhat wise to China's ways. If an IT operator picked up some unnerving traffic coming from a Chinese server, they knew to look into it. But Volt Typhoon, these Chinese infrastructure hackers, they weren't breaking in from Chinese intelligence agencies can't look. Remember way back in episode three, Keep Machine and Welding, when China's hackers broke in and used the Wisconsin welding shop server to hack major American businesses? Well, China's living off the land hackers are running the same playbook. Only now they're using Americans' home routers. Here's John Holquist, Mandiant's Chief Intelligence Analyst. They're coming out of Soho routers. So your home office, your small office router, they are literally going out. A lot of them have vulnerabilities. That last bit, it's an understatement. Volt Typhoon made a habit out of targeting home routers that, as I was saying earlier, were sold without security baked in. To break into these routers, hackers only need to the default password, usually admin. And even if the user has bothered to change the password, these routers are riddled with vulnerabilities. And in too many cases, they've reached quote, unquote, end of life, which basically means that even when we detect a vulnerability, there is no patch to install, no technical support. They're just sitting ducks. And by 2020, China's Volt Typhoon hackers started capturing these home routers en masse and using them as a launchpad to infiltrate U.S. critical infrastructure. They go out, they capture these routers, and they build them into a botnet. Think of a botnet like the iconic Spider-Man villain, Doc Ock, that evil mastermind who wields robotic tentacle-like arms. Only in this case, his tentacles are hooked into hundreds, thousands of these vulnerable home routers, commanding them to infiltrate America's critical infrastructure. And these zombie routers, they're just dusty, ordinary looking devices in living rooms and small offices, quietly moving packets for Chinese state hackers halfway across the world. Cyber experts have a Marvel-esque name for these compromised routers. They call them ORBs, short for Operational Relay Boxes. So literally, you could be home right now, baking apple pie, and have zero idea that your home router is being used by China as a conduit to hack the U.S. power grid. From China's point of view, this approach is elegant. From ours, it's dangerous. For one, it's the perfect disguise. What they're doing is, instead of traversing through systems that they have to buy and set up, they're traversing through these stolen, compromised systems. And that means instead of coming from China, like, they can look like they're coming right from down the street. It's like the Wisconsin welding shop, leveled up. Same idea, just imagine that scaled up. So instead of just coming through that one, you know, handful of those compromised systems, imagine just going out and getting hundreds of them. And it's not just one botnet using these ORBs to hack us. China has employed nearly a dozen that we know about. They're managed by mid-level Chinese contractors like ISUN and Chengdu 404, who lease them out to Volt Typhoon and these other Chinese APTs. It's layers on layers, like a hall of mirrors, each one giving Beijing just enough distance to shrug and say, wasn't us. There's just a ton of operations where they're setting this stuff up and different teams are sharing it. It makes it really hard to tell what's what, right, and figure out what you're at. But it's the same exact idea. These compromised system is a great way to sort of hide your tracks. And unfortunately, this sort of router focus game is a really good way to do that. Second, routers are easily replaceable. If one gets burned, hackers can just hop to the one next door. They can pick a router that's right next to you and looks completely natural for your network. And the great thing about also is that tomorrow they can burn it and go to a new one. And so from my perspective, somebody who tries to track this stuff, it makes it really hard. Third, these routers are really hard to monitor. Rarely do they have logs or any kind of security. Volt Typhoon has used routers from US companies like Cisco, Fortinet, Netgear, and others. Many of them unpatched, still running those default passwords, or others that have reached end of life and been abandoned by their vendors. But these days, American brands are getting squeezed out by a Chinese giant. The world's largest network and communication equipment manufacturers. TP-Link maintains building production bases all over the world. TP-Link is committed to creating reliable products and technologies to link global users to a better life. While the White House dithers back and forth on TikTok, few Americans have ever even heard of TP-Link. And I get it. When you buy a home router, you don't care what brand you get. You just want it to work. TP-Link's routers are ubiquitous and easily forgotten. If you've bought a home or small office router recently, chances are your data is flowing through TP-Link. In fact, go on Amazon right now. Search the words home router. And Amazon's overall pick is a TP-Link router. It's by far the cheapest option, as in less than half the cost of its next closest competitor. TP-Link's share of the US router market has exploded from 10% in 2019 to over 60% today. That's according to the Wall Street Journal, which found that TP-Link's share of next-gen Wi-Fi systems is even higher, 80%. And as early as October 2023, China's Volt Typhoon hackers started using TP-Link routers to burrow into US infrastructure. Now, to be clear, TP-Link isn't the only brand they've used. But what makes TP-Link different is this. It's a Chinese company. It was started by two Chinese brothers and for three decades operated from Shenzhen. But last year, TP-Link split in two. One base stayed in China, while the other moved its new official headquarters to Irvine, California, to serve the US market. TP-Link wants you to believe this split means it's no longer Chinese. And as this episode was coming together, TP-Link's general counsel sent me a tersely worded message saying, quote, any claim TP-Link is a Chinese company is, quote, unlawful and legally actionable. According to this lawyer, quote, TP-Link is a US-based company that manufactures routers for the US market in Vietnam. But a week after TP-Link's lawyers put me on notice, Bloomberg published its own investigation, which found that Vietnam is effectively just a final assembly point, their words, that only half a percent of TP-Link's components come from Vietnam. The rest are still imported from China. And then there's what Rob Joyce, the NSA's former cybersecurity chief, testified to Congress and told our live panel podcast in March. He testified that TP-Link's push into the US isn't just smart business, it's strategic. Rob told us the company is selling its routers at a loss, a deliberate move to flood the US with cheap routers and build what he called a PRC platform. How have they achieved this miraculous growth? They appear to be selling at price points below profitability to drive out our Western competition. TP-Link routers were among the various brands exploited by Chinese state-sponsored hackers in the massive Volt, Flax and Salt Typhoon attacks. Imagine these routers in the homes and businesses across America as a PRC platform to launch society panicking cyber attacks. This is a threat we cannot ignore. The company is selling them at unprofitable levels and they're driving out the Western and US manufacturers. It's exponential growth. And now they have these routers in all of our homes that the software is maintained and updated out of China. Whether TP-Link is complicit in these attacks or not today, at any point the Chinese government can go under their intel laws and direct that company to support them and issue an update that either bricks a massive amount of our critical infrastructure, people's ability to get on the internet if they want to attack, or makes them even better bounces and redirectors or makes them even better. for them to do their operations through. It's a huge problem, Nicole. It reminded me of that line from Huawei's founder, a country without its own program-controlled switches is like one without an army. TP-Link disputes all of this and emphasizes that its security is on par, if not better than leading routers. That said, a recent Microsoft assessment took a careful look at one of these Chinese botnets. They call it Covert Network 1658, and it's used by multiple Chinese APTs. Microsoft determined it was comprised of 8,000 compromised devices. The vast majority of them, TP-Link. Now, that could just come back to the fact that more Americans are using TP-Link routers than ever before, or it could not. US investigators are now probing just how closely TP-Link Systems Inc., the new American incarnation of the company, is tied to China. And if they find it presents a quote, unacceptable risk, Washington could use new authorities to ban TP-Link from the US. Politicians across the aisle are now zeroing in on the issue. Here's Democratic Congressman Raja Krishnamoorthy at a hearing on cyber threats in March. For context, he's holding up a TP-Link router. You can actually buy one of these things for $20 online, but don't use this, okay? Don't put it in your critical infrastructure. I don't have one at home either. It's not a good idea. TP-Link's routers, I should note here, aren't just sold on Amazon, they're everywhere. In fact, if you go to any US military base and head to the commissary, you'll find TP-Link routers featured prominently on the shelves. But the routers are just the first step in breaking into US infrastructure. It's what these hackers do or don't do once they're in that makes these attacks really difficult to detect. Once they're in, they often don't act immediately. In some cases, they lie completely dormant on a victim's networks for 60, sometimes 90 days, which puts them well outside the period most companies even keep logs or can flag anything unusual. Here's John Holquist again. We lose half the IOCs to this battle, right? We lose all the network-related IOCs, particularly in relation to Vault Typhoon activity. They're living off the land. IOC, Indicators of Compromise. That's tech speak for the digital crumbs, artifacts, and other clues that indicate you've been breached. And Vault Typhoon has figured out how to leave as few crumbs or IOCs as possible. Here's Kevin Mandia. I think that's what's happening here, and that's why there's been additional concern. It's way harder to investigate. So when Mandia and folks go out to figure out what happened and you're up against a group like Vault Typhoon, you know they're there. You see these terrible little scraps of, yeah, they looked at this one file, but you know they looked at 10,000 files, and the evidence has only given you the one. And you're like, oh my God, I'm getting less than 1% visibility into what they're doing here. And unless you have great identity security, great identity monitoring, you're not gonna catch these folks that live off the land. And that phrase, I'm gonna explain it again, it means the attackers are accessing a organization's network the same way the organization does, period. Same user IDs, same passphrases, same programs. There's nothing special. They've learned your network so well that they look like they're part of your network. And that's really hard to investigate. It's not impossible, but it does change how we look at things. We have to do forensics a little differently. After Telvent, China's infrastructure hackers started coming for other pipeline operations across the country. But in 2020, they started hacking U.S. infrastructure with an unnerving frequency. Something had changed. Something set them off. We have waged a fierce battle against the invisible enemy, the China virus. Against the Chinese virus. It's a disease, without question, has more names than any disease in history. I can name Kung flu. You might recall from episode one, the CCP is obsessive about image control. It's why they hacked Google. It's why Xi agreed to the 2015 cyber detente. The CCP weren't willing to risk the embarrassment of the White House canceling Xi's first official trip or risk being greeted with sanctions. It's impossible to say what set them off in 2020. You'd have to be a fly on the CCP's wall. Maybe they were set off by the mocking. Maybe it was the isolation and undercurrents of suspicion that dominated COVID. If we were already looking at each other through straws, then after COVID, we were now looking through needles, as Tom Friedman, the Times columnist puts it. Whatever it was, in 2020, China's volt typhoon became the broadest, most active, most persistent cyber threat to US infrastructure that American intelligence officials have ever seen. The scale of the Chinese cyber threat is unparalleled. They've got a bigger hacking program than that of every other major nation combined. And they have stolen more of Americans' personal and corporate data than every nation, big or small, combined. To fully understand just what it was like to reckon with the scale and severity of this problem, you have to go beyond the news clips. You have to go beyond the public statements. It's time I bring in someone from inside the classified tent, someone who's been tracking the Chinese cyber threat more than anyone. Meet Andrew Scott. My name's Andrew Scott. I'm the Associate Director for China Operations here at the Cybersecurity and Infrastructure Security Agency. It's a relatively new role that was created in mid-2023 to bring together a coordinated approach to assist those efforts to defend critical infrastructure from POC cyber threats. Frankly, it's a miracle we're hearing from Andrew at all. Because over that same decade, I was stumbling around in the dark, trying to shine a spotlight on these breaches. Andrew was also tracing these assaults. Only he was doing it from classified skips, with the benefit of a giant intelligence apparatus at his back. And man, would I wouldn't have given to speak to him over that decade I was at the Times. If you happen to be watching C-SPAN during any major congressional testimony on Chinese cyber espionage, you may have glimpsed Andrew in the audience, sitting just beyond the agency heads. He tracked Chinese cyber threats at the CIA, at the National Security Council, and most recently at CISA, the Cyber Defense Agency. And here I should disclose that as this threat began metastasizing in 2021, I left the New York Times. After writing about this threat for more than a decade, I could see pretty clearly where things were headed. And it wasn't good. I reckoned I could keep writing about these cyber attacks or I could do something about it. So in 2021, I put down my pen and picked up a shovel. I joined CISA's advisory committee and I served there through its disbanding in January 2025. And that is how I came to know Andrew. Tell us how long you have been working on the threat of cyber espionage, cyber campaigns from the People's Republic of China. So it's been about almost 15 years in total. So before CISA, I spent nearly 15 years in the intelligence community working on foreign cyber threat issues to include East Asia, China, North Korea, and others. Intermixed with that, spent about four and a half years working on the National Security Council, both in the Obama and Biden administrations where I worked on everything from the APD-1 report and responses to that in the 2012-2013 timeframe to the hafnium attributions in 2021, being involved in the US-China cyber commitment negotiations and a whole range of things. So I've worked at pretty much every aspect of this issue from intel to national policy to homeland security now. I should note here that Andrew left CISA after I interviewed him for this episode. What he describes here is what he witnessed while he was there. Through multiple incident response efforts that we've had, we've verified that the PRCs compromised various pieces of critical infrastructure. And what we're seeing is that these actors are persistent and patient against their targets, that they are compromising the same entity multiple times over a number of years. We are seeing them gain access into environment, steal credentials, lay dormant on the network because all they're looking to do is maintain that access, come back a period of time later, test their credentials, see if they work. If they don't, steal credentials again, maintain access in the environment. It is an act of maintaining access, testing that access and validating that access, which is exactly what you would do if you were looking to just maintain access and preposition on a network. Preposition on a network. That means get in and stay in. Jim Lewis puts it more succinctly. My usual line is you don't hack infrastructure for fun, right, it's reconnaissance, it's target reconnaissance for the event of a conflict between the United States and China. A sinking realization started to creep in. China was and is making strategic inroads into America's most critical infrastructure. They're not just sightseeing, they're strategically positioning themselves. And big picture, what Andrew and his colleagues were seeing with each new living off the land attack, with the access Chinese hackers were gaining to US power and water supplies, our ports, our supply chains, our gas pipelines, our railways, aviation, all of it makes for a big red button. One CCP leadership can push in the event of a conflict. And so I'm curious what it was like inside government when you all made this realization that, oh, this is not just IP theft anymore. What did it take for the intelligence community to make that determination that, wait a minute, this looks like it could be the beginnings of something far more aggressive? Was it the victims? So I'd answer that in a couple of different ways. The first is to say it was an eye-opening experience when we sort of came collectively to that realization of a shift in the kinds of targets that we were seeing. And over the course of a number of years, sort of my colleagues elsewhere in government and the IC, here at CISO, in DOD, our international partners, all sort of really focused on this question of, as we looked at a bunch of different factors, right? Outside of the cyber domain, Xi Jinping coming in and stating that reunification is a goal with Taiwan. William Lai from Taiwan's ruling party wins the presidential election and vows to defend the island from China's intimidation. But China said reunification with Taiwan is still inevitable. A sort of shift and reorganization of the People's Liberation Army in 2015 around blunting and deterring U.S. intervention in a conflict in the Indo-Pacific. A Chinese defense official has said that the United States is trying to build an Asia-Pacific version of NATO to maintain its hegemony in the region. The remarks were made at the Shangri-La Dialogue in Singapore. Lieutenant General Jiang Xiaofen warned that if regional countries were to sign up for the U.S. Indo-Pacific strategy, they would be lured into taking bullets for the United States. And then you bring together this piece of what do we see being targeted? And one of the realizations was exactly what you highlighted, which some of the things that we saw being targeted were entities that even if you stretch the boundaries of your imagination to say, could they be an espionage target? They very clearly weren't. And one thing that I really wanted to emphasize here, I've even gotten questions recently of what's fundamentally different now. And the answer really is, we've now confirmed they're there. The PRC is inside the house. The PRC was inside the house. Not just a fear, a fact. U.S. officials watched as Chinese hackers crept through dozens, then hundreds of critical systems across the country. Smaller utilities in Littleton, Massachusetts, major infrastructure hubs, power, water, transportation. This wasn't spycraft as usual. This was sabotage in slow motion. This was sabotage in slow motion, a silent crawl through the machinery that keeps America running. They weren't gathering secrets, they were laying tripwires. And that was enough to drag U.S. officials out of the shadows and into the open. There has been far too little public focus on the fact that PRC hackers are targeting our critical infrastructure, our water treatment plants, our electrical grid, our oil and natural gas pipelines, our transportation systems. And the risk that poses to every American requires our attention now. China's hackers are positioning on American infrastructure in preparation to wreak havoc and cause real world harm to American citizens and communities if and when China decides the time has come to strike. They're not focused just on political and military targets. We can see from where they position themselves across civilian infrastructure that low blows aren't just a possibility in the event of a conflict. Low blows against civilians are part of China's plan. That was former FBI Director Chris Wray. In January of 2024, he, along with Jenny Sturley and General Paul Nakasone, the now former director of NSA and U.S. Cyber Command, testified before the House Select Committee on China. We and our partners identified hundreds of routers that had been taken over by the PRC state-sponsored hacking group known as Vault Typhoon. The Vault Typhoon malware enabled China to hide, among other things, preoperational reconnaissance and network exploitation against critical infrastructure like our communications, energy, transportation and water sectors, steps China was taking, in other words, to find and prepare to destroy or degrade the civilian critical infrastructure that keeps us safe and prosperous. And let's be clear, cyber threats to our critical infrastructure represent real world threats to our physical safety. PRC cyber actors are pre-positioning in our U.S. critical infrastructure, and it is not acceptable. Defending against this activity is our top priority. This is a world where a major crisis halfway across the planet could well endanger the lives of Americans here at home. Three top officials speaking plainly before Congress. That should give you a sense of the severity of the situation. That's about as stark a warning as you ever get from the intelligence community in public. What has us particularly concerned at CISA and across government is the breadth of the pre-positioning that we see. We see it in the transportation sector. We see it in the water sector. We see it in the communication sector. We see it in the energy sector. The worst day is an everything, everywhere, all at once scenario that all of a sudden we see disruption in multiple sectors simultaneously with services to the American public going out. Most Americans can't even fathom the everything, everywhere, all at once cyber attack. We've only caught one off glimpses, like flashes in the dark. But the full scope, the full capability, we haven't seen it, not yet. Nobody really knows if the gloves came off in cyberspace between China and the U.S. what would really happen. Like, is it pandemonium? I've had the privilege of lecturing on modern warfare, and even I'm not so sure of the collateral damage, but I do know that a lot of things would get less predictable and it would be eerie. Like, if the gloves came off in cyberspace, the impact of it, you know, some companies can make phone calls, some can't. Some companies, the gate rises when you go to park and sometimes you can't. Services might shut down. We don't really know the impact just yet and how widespread it would be because we don't understand all the complex dependencies. So it's really hard to even know what the fear. What I'm hopeful about is the gloves just don't come off. I don't think they do until they come off kinetically. I really don't think people are just going to unleash everything they've got in cyber. I don't think we've seen China's total A game. All we know for certain is they've prepared the battlefield, but have we? That's next on To Catch a Thief. Follow To Catch a Thief to make sure you don't miss the next episode. And if you like what you hear, rate and review the show. To Catch a Thief is produced by Rubrik in partnership with Pod People, with special thanks to Julia Lee. It was written and produced by me, Nicole Perleroth and Rebecca Chasson. Additional thanks to Hannah Pedersen, Sam Devour and Amy Machado. Editing and sound design by Morgan Foose and Carter Wogan.

TL;DR

  • Chinese state hackers (Volt Typhoon) have infiltrated U.S. critical infrastructure—power grids, water systems, pipelines, transportation—not to steal data but to pre-position for potential sabotage in the event of conflict over Taiwan.
  • They use a "living off the land" technique, employing legitimate credentials and native tools to avoid detection, often remaining dormant for 60-90 days to evade standard security logging and monitoring.
  • The attacks are routed through compromised American home routers (ORBs) from brands like TP-Link, Cisco, and Netgear, making the traffic appear domestic rather than originating from China and providing plausible deniability.
  • TP-Link, a Chinese company now controlling 60% of the U.S. router market, is under investigation for potential national security risks, with officials alleging the company sells routers at a loss to create a "PRC platform" for cyber operations.
  • U.S. intelligence officials publicly testified in 2024 that China has successfully pre-positioned across multiple infrastructure sectors simultaneously, creating an "everything, everywhere, all at once" attack capability that could disrupt civilian services during a crisis.

Volt Typhoon's Stealth Infrastructure Campaign

This episode examines how Chinese state-sponsored hackers, operating under the codename Volt Typhoon, have systematically infiltrated U.S. critical infrastructure since 2020. Unlike traditional cyber espionage focused on intellectual property theft, these operations target electric grids, water systems, pipelines, railways, and transportation networks with a disturbing pattern: they break in, establish persistent access, and wait. The hackers employ a technique called "living off the land," using legitimate credentials and native system tools to avoid detection. They leave minimal forensic evidence, often remaining dormant for 60-90 days to evade standard logging periods. This isn't reconnaissance for espionage—it's pre-positioning for potential sabotage in the event of geopolitical conflict, particularly around Taiwan.

The Home Router Vulnerability Exploit

Volt Typhoon's operational security relies heavily on compromising American home and small office routers to create botnets of "Operational Relay Boxes" (ORBs). These routers—many from brands like Cisco, Fortinet, Netgear, and increasingly TP-Link—are riddled with vulnerabilities, often running default passwords or having reached end-of-life with no security patches available. Chinese hackers capture hundreds or thousands of these devices, using them as proxies to mask their true origin. Instead of traffic appearing to come from China, it looks like it's coming from down the street. TP-Link, a Chinese company that recently split its operations with a U.S. headquarters in California, now controls over 60% of the U.S. router market. NSA officials testified that the company appears to be selling routers at a loss to drive out Western competitors, creating what they call a "PRC platform" for potential cyber attacks. Microsoft identified one Chinese botnet comprised of 8,000 compromised devices, the vast majority being TP-Link routers.

Government Response and Strategic Implications

By 2024, the threat had become severe enough that FBI Director Chris Wray, NSA Director Paul Nakasone, and CISA officials testified publicly before Congress—a rare move signaling the gravity of the situation. They confirmed Chinese hackers had successfully pre-positioned across multiple critical infrastructure sectors simultaneously, creating an "everything, everywhere, all at once" scenario capability. The challenge for defenders is compounded by constitutional constraints: the NSA cannot hunt for threats on private U.S. networks without warrants, and over 80% of critical infrastructure is privately owned. Andrew Scott, former CISA Associate Director for China Operations, described the realization as "eye-opening"—the shift from espionage to pre-positioning for sabotage became undeniable when targets included entities with no conceivable intelligence value. The strategic calculus is clear: China is building the capability to disrupt American civilian life as leverage in a potential conflict over Taiwan, and the infrastructure to execute such attacks is already in place.

Chapters

0:00 - Introduction: Sleeper Cells in Infrastructure
3:00 - American Blind Spots and Vulnerabilities
5:21 - The Home Router Botnet Strategy
10:39 - TP-Link's Market Dominance
17:02 - Living Off the Land Techniques
19:43 - The 2020 Escalation
24:18 - Inside the Intelligence Assessment
30:02 - Congressional Testimony and Public Warning
33:00 - The Unknown Scope of Cyber Warfare

Key Quotes

0:32 "And all of a sudden we see Chinese threat groups, since about late 2020, at least from my observables, hack in and we don't know why, because they're not the tank through the cornfield. They're hacking in and just, that's it. There's no other activity."
1:12 "There's just no evidence. And that's what living off the land means. There's no malicious code. There's no backdoor. There's good operational security. If they created a log file that's suspicious, they would edit it."
14:52 "The company is selling them at unprofitable levels and they're driving out the Western and US manufacturers. It's exponential growth. And now they have these routers in all of our homes that the software is maintained and updated out of China."
18:23 "I'm getting less than 1% visibility into what they're doing here. And unless you have great identity security, great identity monitoring, you're not gonna catch these folks that live off the land."
21:23 "My usual line is you don't hack infrastructure for fun, right, it's reconnaissance, it's target reconnaissance for the event of a conflict between the United States and China."
30:35 "Low blows aren't just a possibility in the event of a conflict. Low blows against civilians are part of China's plan."

FAQ

What does "living off the land" mean in the context of these cyber attacks?

"Living off the land" refers to a hacking technique where attackers access a target's network using legitimate credentials and native system tools, making their activity indistinguishable from normal employee behavior. They don't drop malware or create obvious backdoors—they simply log in the same way employees do, leaving minimal forensic evidence. This makes detection extremely difficult because there are no malicious code signatures or suspicious network patterns to flag.

How are Chinese hackers using American home routers in these attacks?

Chinese hackers compromise vulnerable home and small office routers (often running default passwords or unpatched firmware) and organize them into botnets called Operational Relay Boxes (ORBs). They route their attacks through these compromised American routers, making the malicious traffic appear to originate from domestic sources rather than China. This provides both operational disguise and plausible deniability. If one router is detected and blocked, they simply switch to another nearby device.

Why is the U.S. government so concerned about TP-Link routers specifically?

TP-Link is a Chinese company that now controls over 60% of the U.S. router market, with 80% of next-generation Wi-Fi systems. U.S. officials testified that TP-Link appears to be selling routers at a loss to drive out Western competitors. The concern is that under Chinese intelligence laws, the government could compel TP-Link to issue malicious updates that either brick American infrastructure or enhance the routers' use as attack proxies. Microsoft identified one Chinese botnet where the vast majority of 8,000 compromised devices were TP-Link routers, though this could reflect market share or indicate deeper vulnerabilities.


Categories:
  • » Webinar Library » Rubrik
  • » Cybersecurity » Network Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Critical Infrastructure
  • Nation-State Threats
  • Network Security
  • Threat Intelligence
  • OT
  • IoT Security
  • Executive Briefing
  • Critical Infrastructure Security
  • Chinese State-Sponsored Hacking
  • Volt Typhoon APT
  • Living Off the Land Techniques
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Chinese Infrastructure Hackers: Living Off The Land

              Industry Events (Sponsor Hosted)

              • Oct
                01

                Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?

                10/01/202601:00 PM ET
                • Oct
                  13

                  Interactive Q&A Session on DatasecAI 2026 Insights and Innovations

                  10/13/202602:00 PM ET
                  • Oct
                    15

                    Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation

                    10/15/202611:00 AM ET
                    More events

                    Upcoming Webinar Calendar

                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: A Comprehensive Approach to Visibility and Control
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-a-comprehensive-approach-to-visibility-and-control/
                    • 10/01/2026
                      01:00 PM
                      10/01/2026
                      Meta Muse 101: Embracing the Arrival of the Agentic Internet. What's Next?
                      https://www.truthinit.com/index.php/channel/2144/meta-muse-101-embracing-the-arrival-of-the-agentic-internet-whats-next/
                    • 10/13/2026
                      02:00 PM
                      10/13/2026
                      Interactive Q&A Session on DatasecAI 2026 Insights and Innovations
                      https://www.truthinit.com/index.php/channel/2141/interactive-q-a-session-on-datasecai-2026-insights-and-innovations/
                    • 10/15/2026
                      11:00 AM
                      10/15/2026
                      Risk in Real Time Demo Series: Virtual Patching: Protection at the Speed of Exploitation
                      https://www.truthinit.com/index.php/channel/1372/risk-in-real-time-demo-series-the-autonomous-era-orchestrating-a-resilient-enterprise/
                    • 10/20/2026
                      11:00 AM
                      10/20/2026
                      Harnessing Data Governance for AI with Cyera and Snowflake
                      https://www.truthinit.com/index.php/channel/2137/harnessing-data-governance-for-ai-with-cyera-and-snowflake/
                    • 10/27/2026
                      01:00 PM
                      10/27/2026
                      The HUMAN Experience: Real-Time Insights into Page Intelligence
                      https://www.truthinit.com/index.php/channel/2139/the-human-experience-real-time-insights-into-page-intelligence/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version