* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Sunday, December 21, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    Country music star, wife are getting divorced: ‘We are no longer suited to be married’ – PennLive.com

    Country Music Star and Spouse Reveal They Are No Longer Suited for Marriage

    Nate Bargatze is leaving his podcast — and Utah recently saw why – Deseret News

    Nate Bargatze Is Leaving His Podcast – What Utah Fans Recently Went Through

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    Walk on White features Conchettes and Santa – keysnews.com

    Uncover the Enchantment of Conchettes and Santa in Walk on White

    Blizzard Entertainment President on BlizzCon 2026, 35th Anniversary Plans – Variety

    Blizzard Entertainment President Reveals Thrilling BlizzCon 2026 and 35th Anniversary Celebrations

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

    Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

    The 8 worst technology flops of 2025 – MIT Technology Review

    The 8 worst technology flops of 2025 – MIT Technology Review

    Bangor School District receives new CNC router technology from First National Bank – news8000.com

    Bangor School District Unveils Cutting-Edge CNC Router Technology Thanks to Local Support

    6G discussions: How things have changed – 5gtechnologyworld.com

    The Evolution of 6G: How the Conversation Has Transformed

    Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

    Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

    China exploits US-funded research on nuclear technology, a congressional report says – ABC News

    Congressional Report Uncovers China’s Exploitation of US-Funded Nuclear Technology Research

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

    Country music star, wife are getting divorced: ‘We are no longer suited to be married’ – PennLive.com

    Country Music Star and Spouse Reveal They Are No Longer Suited for Marriage

    Nate Bargatze is leaving his podcast — and Utah recently saw why – Deseret News

    Nate Bargatze Is Leaving His Podcast – What Utah Fans Recently Went Through

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    State Farm Arena Ranks In The Top 5 Live Entertainment Venues In The U.S. & Top 7 In The World, According To Billboard – Secret Atlanta

    Walk on White features Conchettes and Santa – keysnews.com

    Uncover the Enchantment of Conchettes and Santa in Walk on White

    Blizzard Entertainment President on BlizzCon 2026, 35th Anniversary Plans – Variety

    Blizzard Entertainment President Reveals Thrilling BlizzCon 2026 and 35th Anniversary Celebrations

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

    Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

    The 8 worst technology flops of 2025 – MIT Technology Review

    The 8 worst technology flops of 2025 – MIT Technology Review

    Bangor School District receives new CNC router technology from First National Bank – news8000.com

    Bangor School District Unveils Cutting-Edge CNC Router Technology Thanks to Local Support

    6G discussions: How things have changed – 5gtechnologyworld.com

    The Evolution of 6G: How the Conversation Has Transformed

    Retail supply chains brace for a redefined 2026 as tariffs, technology gaps, and nearshoring upend old models – Raleigh News & Observer

    Retail Supply Chains Revolutionize in 2026: How Tariffs, Technology Gaps, and Nearshoring Are Shaping the Future

    China exploits US-funded research on nuclear technology, a congressional report says – ABC News

    Congressional Report Uncovers China’s Exploitation of US-Funded Nuclear Technology Research

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

ORBs: Hacking groups’ new favourite way of keeping their attacks hidden

May 22, 2024
in Technology
ORBs: Hacking groups’ new favourite way of keeping their attacks hidden
Share on FacebookShare on Twitter

Beware the ORB: why attacks on your network could come from a home router down the street


Steve  Ranger

By

Steve Ranger

Published: 22 May 2024 15:00

Cyber-espionage groups are making it harder to spot where their attacks are coming from by upping their usage of proxy networks – known as operational relay box networks or ORBs – that can throw defenders off the scent.

Cyber security company Mandiant has warned that it has seen a growing trend for China-backed espionage operations, in particular, to use ORBs to cover their tracks.

These ORB networks are somewhat like botnets and can be made up of virtual private servers (VPS), as well as compromised internet of things (IoT) devices and insecure routers. This combination makes it harder for defenders to track attacks because these groups can disguise traffic between their command-and-control infrastructure and their final targets.

ORB networks are one of the major innovations in Chinese cyber espionage that are challenging defenders, said Michael Raggi, Mandiant principal analyst at Google Cloud.

“They’re like a maze that is continually reconfiguring with the entrance and the exit disappearing from the maze every 60 to 90 days,” he said. “To target someone, these actors may be coming from a home router right down the street. It’s not unusual for an entirely unwitting person’s home router to be involved in an act of espionage.” 

These networks are often built by renting VPS and using malware designed to target routers to grow the number of devices capable of relaying traffic. Because the makeup of these networks changes rapidly, using an ORB network makes it harder to spot attacks and pin them on a particular group in terms of attribution.

That makes classic indicators of compromise (IOC) – the tech details and clues commonly shared about attacks – less useful because these groups will regularly cycle through network infrastructure.

The scale of these networks, Mandiant said, means attackers can piggyback on devices that have a handy geographic proximity to targeted enterprises. That allows their malicious traffic to blend in when being reviewed by analysts.

“One such example would be traffic from a residential ISP that is in the same geographic location as the target that is regularly used by employees and would be less likely to get picked up for manual review,” said Mandiant’s report.

As a result, the security company said, enterprise security teams should shift their thinking. That means that rather than treating ORB networks as just part of the infrastructure used by attackers, they should track ORBs “like evolving entities akin to APT [advanced persistent threat] groups”.

ORB networks are not a new invention and have regularly been used as part of espionage campaigns to obscure who the attacker is and where they are. But Mandiant said the use of these networks by China-backed espionage actors has become more common over recent years.

These ORBs are infrastructure networks run by contractors or others within China. They are not controlled by a single APT espionage or hacking group, but are shared between them, which Mandiant said means multiple APT actors will use the ORB networks to carry out their own distinct espionage and reconnaissance.

This infrastructure often shifts – the lifespan of an IPv4 address associated with an ORB node can be as short as 31 days. Mandiant said a competitive differentiator among ORB network contractors in China appears to be their ability to cycle significant percentages of their compromised or leased infrastructure on a monthly basis.

That means just blocking the infrastructure linked to an ORB network at a particular time is not going to be as effective as was previously the case. “As a result, IOC extinction is accelerating and the shelf life of network indicators is decreasing,” Mandiant said.

“Infrastructure or the compromised router device communicating with a victim environment may now be identifiable to a particular ORB network, while the actor using that ORB network to carry out the attack may be unclear and require investigation of the complex tools and tactics observed as part of an intrusion,” the report said.

John Hultquist, Mandiant chief analyst, Google Cloud, added: “Chinese cyber espionage was once noisy and easily trackable. This is a new type of adversary.”

The nodes in an ORB network are usually distributed globally. Mandiant gives the example of one it tracks as ORB3 or Spacehop, which it described as a very active network used by multiple China-backed groups.

It uses a relay server hosted in either Hong Kong or China by cloud providers, while the relay nodes are often cloned Linux-based images, which are used to proxy malicious network traffic through the network to an exit node that communicates with targeted victim environments.

Mandiant said it was notable that this network has a “robust volume” of nodes in Europe, the Middle East, and the US – all of which are regions targeted by China-backed APT15 and ATP5.

In contrast, another network that Mandiant tracks (known as ORB2 or Florahox) also features compromised network routers and IOT devices. The network appears to contain several subnetworks composed of compromised devices recruited by the router implant known as Flowerwater.

Mandiant said that all of this creates a problem for defenders, because rather than simply blocking infrastructure associated with attackers they now have to consider what infrastructure is part of the ORB network right now, for how long, and who is using the ORB network.

Mandiant added that the best way to deal with the challenge posed by ORB networks is to stop tracking espionage command and control infrastructure as an inert indicator of compromise and start tracking it as an entity in itself.

“Instead, infrastructure is a living artifact of an ORB network that is a distinct and evolving entity where the characteristics of IP infrastructure itself, including ports, services, and registration/hosting data, can be tracked as evolving behaviour by the adversary administrator responsible for that ORB network,” Mandiant said.

It warned that the rise of the ORB industry in China points to long-term investments in equipping China-backed cyber operations with more sophisticated tactics and tools.

“Whether defenders will rise to this challenge depends on enterprises applying the same deep tactical focus to tracking ORB networks as has been done for APTs over the past 15 years,” Mandiant said.

Read more on Hackers and cybercrime prevention


Fancy Bear sniffs out Ubiquiti router users

AlexScroxton

By: Alex Scroxton


Critical infrastructure hacks raise alarms on Chinese threats

AlexanderCulafi

By: Alexander Culafi


US government disrupts Chinese botnet containing hundreds of end-of-life Cisco and Netgear routers

CarolineDonnelly

By: Caroline Donnelly


Chinese threat group exploited VMware vulnerability in 2021

ArielleWaldman

By: Arielle Waldman

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366585945/ORBs-Hacking-groups-new-favourite-way-of-keeping-their-attacks-hidden

Tags: Group’sHackingtechnology
Previous Post

AI Seoul Summit: 27 nations and EU to set red lines on AI risk

Next Post

Dutch employers should discuss using algorithms in managing staff

Vietnam: Creating a green lifestyle with remote growing, vegetable boxes – Hortidaily

Vietnam Embraces Green Living with Remote Gardening and Fresh Vegetable Boxes

December 21, 2025
Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

December 21, 2025
Georgia vs. Ole Miss set for Sugar Bowl: Preview and odds for CFP quarterfinal – CBS Sports

Georgia vs. Ole Miss Sugar Bowl Showdown: Exciting Preview and CFP Quarterfinal Odds

December 21, 2025
Consciousness breaks from the physical world by keeping the past alive – IAI TV

Consciousness breaks from the physical world by keeping the past alive – IAI TV

December 21, 2025
Charting the Global Economy: ECB, UK, BOJ Diverge on Rate Moves – Bloomberg.com

Global Economy in Flux: How the ECB, UK, and BOJ Are Diverging on Interest Rates

December 21, 2025
WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

WildBrain Sells Stake in Peanuts Holdings to Sony Pictures Entertainment – Licensing International

December 21, 2025
HHS Announces Request for Information to Harness Artificial Intelligence to Deflate Health Care Costs and Make America Healthy Again – U.S. Department of Health and Human Services (HHS) (.gov)

HHS Announces Request for Information to Harness Artificial Intelligence to Deflate Health Care Costs and Make America Healthy Again – U.S. Department of Health and Human Services (HHS) (.gov)

December 21, 2025
Welcome to the age of zero-sum politics – Financial Times

Welcome to the Era of Zero-Sum Politics: What It Means for Our Future

December 21, 2025
CSR must include environment & ecology, rules Supreme Court; calls green spending a constitutional duty, not charity – TheCSRUniverse

Supreme Court Rules Environmental Protection Is a Constitutional Duty, Not Mere Charity

December 20, 2025
‘This year nearly broke me as a scientist’ – US researchers reflect on how 2025’s science cuts have changed their lives – The Conversation

This Year Nearly Broke Me as a Scientist: How 2025’s Science Cuts Transformed Researchers’ Lives

December 20, 2025

Categories

Archives

December 2025
M T W T F S S
1234567
891011121314
15161718192021
22232425262728
293031  
« Nov    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (979)
  • Economy (998)
  • Entertainment (21,875)
  • General (18,862)
  • Health (10,038)
  • Lifestyle (1,011)
  • News (22,149)
  • People (1,004)
  • Politics (1,012)
  • Science (16,213)
  • Sports (21,499)
  • Technology (15,981)
  • World (987)

Recent News

Vietnam: Creating a green lifestyle with remote growing, vegetable boxes – Hortidaily

Vietnam Embraces Green Living with Remote Gardening and Fresh Vegetable Boxes

December 21, 2025
Technology is powerful but unforgiving when misused – Supreme Court judge warns – GhanaWeb

Supreme Court Judge Issues Stark Warning: Technology’s Power Can Be Dangerous When Misused

December 21, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version