Year2023 |
Month |
Reference number20230102 |
Impact areaShore |
Incident locationUSA |
Incident countryUSA |
Victim countryUSA |
Victim identityCritical infrastructure organizations |
Victim TypeCritical infrastructure organizations |
MethodHacking |
Attacker countryChina |
Since mid-2021, Volt Typhoon, a state-sponsored cyber actor from China, has been targeting critical infrastructure organizations in the United States, including sectors such as communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education. The campaign focuses on post-compromise credential access and network system discovery, using stealthy techniques like living-off-the-land and hands-on-keyboard activity to evade detection. Volt Typhoon routes traffic through compromised small office and home office network equipment to blend into normal network activity. Despite efforts to disrupt their activities, Volt Typhoon remains an ongoing threat, with the U.S. government issuing multiple advisories detailing their tactics and providing mitigation steps.