The breach isn’t the problem. The spread is. →Free Assessment

In an unprecedented joint cybersecurity advisory, 17 security agencies from 11 countries — including the United States, United Kingdom, Germany, Japan, Australia, and Canada — have confirmed that Chinese state-sponsored actors are actively compromising edge and backbone routers to maintain long-term access to sensitive networks across the globe. 

The CISA AA25-239A advisory warns that attackers are exploiting known, unpatched vulnerabilities in widely deployed devices to persist below the radar — modifying router configurations, capturing traffic, and harvesting credentials without triggering traditional defenses. 

And while the advisory does not explicitly confirm cloud compromise, the tactics it describes — credential harvesting, lateral movement from edge infrastructure, and the use of trusted services to mask exfiltration — are exactly how Chinese APTs have pivoted into cloud and SaaS environments in prior campaigns. 

Hijacking Routers — and the Trust They Carry 

Attackers are actively exploiting vulnerabilities in platforms like: 

 Once inside, attackers modify Access Control Lists (ACLs), enable Generic Routing Encapsulation (GRE) or IPsec tunnels, and configure covert SSH or web services on high ports. They also use packet capture (PCAP) tools to sniff network traffic and exploit Simple Network Management Protocol (SNMP) and Terminal Access Controller Access-Control System Plus (TACACS+) to escalate access and discover additional infrastructure. 

How This Enables Cloud Infiltration 

The advisory documents credential harvesting and lateral movement from infrastructure — both well-known tactics that enable attackers to move from routers into cloud environments. 

While the report doesn’t explicitly say “Chinese APTs compromised AWS or Azure,” it describes the exact conditions for such a pivot: 

  • Long-term access to infrastructure trust paths 

  • Harvested credentials and authentication flows 

  • Tunnels and ACLs allowing stealthy movement into connected systems 

These tactics align with previously documented campaigns where Chinese APTs gained infrastructure access and then infiltrated cloud control planes and SaaS applications. 

Real-World Example: APT40’s Router-to-Cloud Infiltration 

In 2021–2022, APT40, a Chinese state-sponsored threat group, exploited vulnerable routers and VPNs, harvested credentials, and gained access to Microsoft 365 and other SaaS platforms using valid logins. 

They disguised traffic through trusted infrastructure and tunnels — mirroring the tactics seen in AA25-239A. 

This proves that infrastructure compromise is not the end — it’s the beginning of cloud infiltration. 

Why Traditional Tools Don’t Catch This 

Security controls built for endpoints and posture fall short when the attack is living inside the infrastructure. 

  • Endpoint Detection and Response (EDR) isn’t present on routers 

  • Next-Generation Firewalls (NGFWs) don’t detect internal ACL manipulation or GRE/IPsec abuse 

  • Security Information and Event Management (SIEM) tools can’t correlate router behavior with credential harvesting 

  • Zero Trust architectures often lack enforcement between infrastructure and cloud workloads 

By the time cloud compromise occurs, the attacker is using valid credentials and established tunnels from trusted devices. 

How Aviatrix CNSF Closes the Gap 

The Aviatrix Cloud Network Security Fabric (CNSF) delivers real-time enforcement and visibility where traditional tools fail — at the runtime infrastructure layer. 

With CNSF, organizations gain: 

  • Inline visibility into edge, inter-region, and inter-cloud traffic 

  • Detection of ACL anomalies, tunneling behavior, and covert service exposure 

  • Microsegmentation that blocks identity-based pivots into cloud VPCs or SaaS 

  • Threat chain mapping through CoPilot, our observability and analytics platform 

  • Flow + DNS + telemetry correlation to detect credential-based escalation 

No agents to manage. No deep packet dependency. Just zero Ttust enforcement built into the fabric of your cloud and network infrastructure.  

What It Means for Compliance 

This attack campaign exposes critical visibility and control gaps across regulatory frameworks: 

Framework 

Impact 

CISA ZTMM 2.0 

Fails segmentation, enforcement, and visibility at infrastructure 

EO 14028 

Violates APT detection mandates for federal contractors 

HIPAA 2025 

Exposes PHI in motion at under-secured network edges 

PCI DSS 4.0 

Enables unmonitored paths for cardholder data 

NIS2 / DORA 

Lacks runtime observability for regulated critical infrastructure 

 What You Can Do Now  

You don’t need new hardware — you need visibility and enforcement in the network fabric. 

👉 Talk to a security specialist   


📚 Sources (with full URLs) 

Share This Article
Connect With Us

Ready to see Aviatrix in action?

Get a personalized live demo walkthrough or explore our latest deep-dive cloud threat research intelligence.

Gartner Report

Gartner Strategic Roadmap for Zero Trust Security Programs 2025 Report

Download and gain actionable insights to advance your cloud security strategy.

Download Now!
Recent Articles
Futuriom Report: Implementing Crypto Agility for Post-Quantum Cryptography

Futuriom Report: Implementing Crypto Agility for Post-Quantum Cryptography

Sep 24, 20264 min read
The Other Shift Nobody’s Watching Harvest Now, Decrypt Later

The Other Shift Nobody’s Watching: Harvest Now, Decrypt Later

Sep 22, 202610 min read
Post-Quantum Cryptography is Here: We Need to Adapt

Post-Quantum Cryptography Is Here: We Need to Adapt

Sep 17, 202612 min read
Aviatrix In Progress Episode 6 - John Qian on Building Security Programs Under Fire

Building Security Programs Under Fire | In Progress, Episode 6

Sep 16, 20265 min read

Keep Reading

Related Articles

Featured Categories

95a2292256ee0f5750aa745fc7d21d39c8ae2870

ACE Program

Explore Category
Rectangle 3966

Customers

Explore Category
5a9318112c7cc265fab072924a2acaa2122a1c9f

Cloud Network Security

Explore Category
Aws-card

AWS

Explore Category
partner_card

Partners

Explore Category
cloud networking heroes

Cloud Networking Heroes

Explore Category
azure_card

Azure

Explore Category
events_card

Events

Explore Category

Secure The Connections Between Your Clouds and Cloud Workloads

Leverage a security fabric to meet compliance and reduce cost, risk, and complexity.

Cta pattren Image