[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f0eePZBoSjRLJ16kXxf_q4RmHOG_JCc5Yq2Oyo8Ldmhs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":19,"created_at":20,"published_at":21,"article":22,"tags":26,"podcasts":39},"391678e3-5e56-4eca-830e-1d4277fedd93","chinese-apt-maintains-18-month-persistence-through-advanced-access-control-bypass","a2f92596-302b-404f-8ceb-ede5f2bc167a","Chinese APT Maintains 18-Month Persistence Through Advanced Access Control Bypass","UNC5221 successfully maintained undetected access to Microsoft 365 environments for 18 months by deploying multiple sophisticated backdoors and bypassing Conditional Access policies through credential theft. The threat actor's ability to reinfect networks after remediation and compromise both victims and their MSPs demonstrates critical failures in access control enforcement and monitoring capabilities. This attack highlights how advanced persistent threats can exploit weak identity management and insufficient logging to establish long-term persistence across cloud environments.","**Immediate actions:**\n- Implement Zero Trust architecture with strict Conditional Access policies for all M365 access\n- Deploy enhanced logging for all authentication events and privileged account activities\n- Conduct emergency review of all service accounts and privileged access permissions\n\n**Long-term improvements:**\n- Establish continuous monitoring for anomalous authentication patterns and credential usage\n- Implement privileged access management (PAM) solutions with just-in-time access controls\n- Develop incident response procedures specifically for cloud environment compromises\n\n**Detection measures:**\n- Deploy advanced threat detection tools capable of identifying WebSocket-based C2 communications\n- Monitor for unusual cross-tenant activities between organizations and their MSPs\n- Implement behavioral analytics to detect credential theft and policy bypass attempts",[12,13,14,15,16,17,18],"CIS Control 6","CIS Control 8","NIST AC-2","NIST AC-3","NIST AU-2","NIST SI-4","MITRE ATT&CK T1078","published","2026-06-05T20:20:41.766027+00:00","2026-06-05T20:20:41.695+00:00",{"id":7,"url":23,"slug":24,"title":25},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks\u002F","chinese-apt-deploys-new-malware-to-keep-access-to-hacked-networks-180b69","Chinese APT deploys new malware to keep access to hacked networks",[27,33],{"id":28,"name":29,"slug":30,"description":31,"color":32},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":34,"name":35,"slug":36,"description":37,"color":38},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",[40],{"id":41,"date":42,"edition":43,"title":44,"audio_url":45},"218597b2-07a4-4fae-9316-40a9b6f8eec3","2026-06-06","morning","ThreatNoir Weekend Brief — June 6","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-06\u002Fthreatnoir-morning-brief-2026-06-06.mp3"]