Description

Security researchers warn that China-linked state-backed hackers are increasingly using vast proxy server networks called operational relay boxes (ORBs) for cyberespionage. These ORB networks, created from virtual private servers (VPS) and compromised devices, are managed by independent cybercriminals and accessible to multiple state-sponsored actors. ORBs, resembling botnets, combine leased VPS services with compromised devices like end-of-life routers and IoT products. This makes detection and attribution challenging, as threat actors can cycle through geographically dispersed nodes. Cybersecurity firm Mandiant has identified multiple ORBs used by China-nexus threat actors for espionage and intellectual property theft. One such network, ORB3/SPACEHOP, is utilized by APT5 and APT15 for reconnaissance and exploiting vulnerabilities, such as CVE-2022-27518 in Citrix ADC and Gateway. SPACEHOP uses a relay server in Hong Kong or China, employing an open-source command and control (C2) framework to manage downstream nodes. Another network, ORB2/FLORAHOX, combines an Adversary Controlled Operations Server (ACOS), compromised routers and IoT devices, and VPS services. It runs traffic through TOR and multiple hacked routers, used by China-linked groups like APT31/Zirconium. ORB2 includes payloads like FLOWERWATER and PETALTOWER to navigate the network. ORB networks consist of key components: ACOS for node administration, relay nodes for traffic authentication, traversal nodes to obfuscate traffic origins, and exit/staging nodes for launching attacks. These networks offer stealth, resilience, and independence from national internet infrastructure, complicating detection and attribution for defenders. Mandiant notes that ORB nodes' IP addresses often change monthly, hindering tracking efforts. Attackers use Autonomous System Number (ASN) providers globally, enabling them to target enterprises from nearby devices, reducing suspicion. As ORBs proliferate, defending against these sophisticated networks becomes increasingly difficult.