×
GreekEnglish

×
  • Politics
  • Diaspora
  • World
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Cooking
Wednesday
25
Mar 2026
weather symbol
Athens 10°C
  • Home
  • Politics
  • Economy
  • World
  • Diaspora
  • Lifestyle
  • Travel
  • Culture
  • Sports
  • Mediterranean Cooking
  • Weather
Contact follow Protothema:
Powered by Cloudevo
> World

Microsoft says China installed malware in US systems in Guam

Custom tools help them set up a command and control channel through a proxy that keeps their info secret

Newsroom May 25 03:29

China may have conducted digital espionage against the US’ Pacific interests. Microsoft and the National Security Agency (NSA) have revealed that an alleged state-sponsored Chinese hacking group, Volt Typhoon, installed surveillance malware in “critical” systems on the island of Guam and elsewhere in the US.

The group has been operating since mid-2021 and reportedly compromised government organizations as well as communications, manufacturing, education and other sectors.

Volt Typhoon prioritizes stealth, according to the investigators. It uses “living off the land” techniques that rely on resources already present in the operating system, as well as direct “hands-on-keyboard” action.

They use the command line to scrape credentials and other data, archive the info and use it to stay in targeted systems.

See Also:

“I didn’t think I’d ever work again”: Jeff Bridges gives fans update on cancer battle

They also try to mask their activity by sending data traffic through small and home office network hardware they control, such as routers.

>Related articles

Channel 12: The 14 points of Trump’s proposal to end the war – Terms on uranium enrichment and the Strait of Hormuz

Papastavrou meets with ExxonMobil: Drilling in the Ionian Sea on track for 2027

US commission calls for Turkey to be placed on “special watch list” for religious freedoms

Custom tools help them set up a command and control channel through a proxy that keeps their info secret.

The malware hasn’t been used for attacks, but the web shell-based approach could be used to damage infrastructure. Microsoft and the NSA are publishing info that could help potential victims detect and remove Volt Typhoon’s work, but they warn that fending off intrusions could be “challenging” as it requires either closing or changing affected accounts.

Read more: Engadget

Ask me anything

Explore related questions

#china#Cyber attacks#espionage#Guam#malware#spying#usa
> More World

Follow en.protothema.gr on Google News and be the first to know all the news

See all the latest News from Greece and the World, the moment they happen, at en.protothema.gr

> Latest Stories

Channel 12: The 14 points of Trump’s proposal to end the war – Terms on uranium enrichment and the Strait of Hormuz

March 24, 2026

The “miraculous” CAR-T cells: The Greek scientist and the new treatment for autoimmune diseases

March 24, 2026

Papastavrou meets with ExxonMobil: Drilling in the Ionian Sea on track for 2027

March 24, 2026

The Times: The British Royal Navy will lead an international force to open the Strait of Hormuz

March 24, 2026

FT: Volkswagen transforms its factory, instead of cars it will produce Iron Dome components

March 24, 2026

Cyprus: Low-altitude flights by Turkish F-16s, Greek fighter jets on constant readiness with training flights

March 24, 2026

Mitsotakis speaks with the Emir of Qatar on developments in the Middle East

March 24, 2026

Alexis Charitsis resigns as leader of New Left: “Political disagreement cannot keep us trapped in stagnation”

March 24, 2026
All News

> technology

What conversations between AI agents and users reveal

AI agents surface the real questions, needs, and points of hesitation of users visiting a corporate website.

February 26, 2026

How AI agents retrieve data from CRM systems, databases and support platforms

February 13, 2026

How AI Chatbots are reshaping marketing and advertising

February 8, 2026

How AI agents turn contact forms into natural language conversations

February 7, 2026

How a chatbot can support business operations

February 1, 2026
Homepage
PERSONAL DATA PROTECTION POLICY COOKIES POLICY TERM OF USE
Powered by Cloudevo
Copyright © 2026 Πρώτο Θέμα