Volt Typhoon Cybersecurity Incident

Year

2023

Month

Reference number

20230102

Impact area

Shore

Incident location

USA

Incident country

USA

Victim country

USA

Victim identity

Critical infrastructure organizations

Victim Type

Critical infrastructure organizations

Method

Hacking

Attacker country

China

Summary:

Since mid-2021, Volt Typhoon, a state-sponsored cyber actor from China, has been targeting critical infrastructure organizations in the United States, including sectors such as communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education. The campaign focuses on post-compromise credential access and network system discovery, using stealthy techniques like living-off-the-land and hands-on-keyboard activity to evade detection. Volt Typhoon routes traffic through compromised small office and home office network equipment to blend into normal network activity. Despite efforts to disrupt their activities, Volt Typhoon remains an ongoing threat, with the U.S. government issuing multiple advisories detailing their tactics and providing mitigation steps.

Reference URL

https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
https://www.cisa.gov/news-events/alerts/2024/02/07/cisa-and-partners-release-advisory-prc-sponsored-volt-typhoon-activity-and-supplemental-living-land

https://unit42.paloaltonetworks.com/volt-typhoon-threat-brief/