Volt Typhoon: PRC State-Sponsored Pre-Positioning Inside US Critical Infrastructure
By Sethu Satheesh · 7 Feb 2024 · 16 min read
Threat Actor: Volt Typhoon (Vanguard Panda, BRONZE SILHOUETTE, DEV-0391, UNC3236, Voltzite, Insidious Taurus) · Target: US critical infrastructure: Communications, Energy, Transportation, Water and Wastewater sectors
Source: www.cisa.gov
Executive Summary
On February 7, 2024, CISA, NSA, and the FBI — joined by DOE, EPA, TSA, and the cyber agencies of Australia, Canada, the United Kingdom, and New Zealand — published joint advisory AA24-038A confirming that the People's Republic of China (PRC) state-sponsored group Volt Typhoon had successfully compromised the IT environments of multiple US critical infrastructure organizations. The confirmed victim sectors were Communications, Energy, Transportation Systems, and Water and Wastewater Systems, spanning the continental United States and territories including Guam.
The advisory's central assessment is what elevates this beyond a conventional espionage case: the agencies assessed with high confidence that Volt Typhoon was pre-positioning on IT networks to enable lateral movement to Operational Technology (OT) assets and disrupt physical functions in the event of a geopolitical crisis or military conflict. In one confirmed compromise, actors moved laterally from IT to a control system and were positioned to reach a second control system. In a Water and Wastewater Sector intrusion, the group reached a VMware vCenter server adjacent to OT assets and enumerated stored PuTTY sessions that included profiles for water treatment plants, water wells, and an electrical substation.
Volt Typhoon's operational hallmark is extreme stealth through living-off-the-land (LOTL) techniques: almost no malware, no conventional command-and-control implants on endpoints, and — critically — credential theft through offline NTDS.dit extraction repeated at intervals over years. The US agencies observed actors maintaining footholds in some victim environments for at least five years, re-extracting the Active Directory database from the same victim three times in four years in one case, and twice in nine months in another. Detection is unusually hard because nearly every observed action — vssadmin, ntdsutil, wmic, RDP with valid admin credentials — is also legitimate administrative activity.
The campaign's infrastructure relied on compromised end-of-life SOHO routers (Cisco, NETGEAR, and others) infected with KV Botnet malware, which the US Department of Justice disrupted in early 2024 through a court-authorized operation that removed the implants. The combination of OT pre-positioning, five-year dwell time, LOTL tradecraft, and botnet-proxied C2 makes Volt Typhoon one of the most consequential state-sponsored campaigns publicly documented against US civilian infrastructure.
Verification of Claims
-
Claim: Volt Typhoon compromised IT networks of multiple US critical infrastructure organizations in Communications, Energy, Transportation, and Water/Wastewater sectors. → Verified → Joint advisory AA24-038A, issued by CISA, NSA, FBI, DOE, EPA, TSA, and Five Eyes partners, based on confirmed incident response engagements.
-
Claim: Volt Typhoon maintained access inside some victim networks for at least five years. → Verified → AA24-038A: "the U.S. authoring agencies have recently observed indications of Volt Typhoon actors maintaining access and footholds within some victim IT environments for at least five years."
-
Claim: The actors extracted NTDS.dit from domain controllers, in one case from three DCs over four years. → Verified → AA24-038A documents the VSS/vssadmin + ntdsutil extraction technique and states: "in one compromise, Volt Typhoon likely extracted NTDS.dit from three domain controllers in a four-year period."
-
Claim: Volt Typhoon reached OT-adjacent systems, including a vCenter server with PuTTY profiles for water treatment plants and an electrical substation. → Verified → AA24-038A documents the Water and Wastewater Sector compromise with this exact lateral movement path (Figure 2 in the advisory).
-
Claim: In one confirmed compromise, actors moved laterally to a control system and were positioned to reach a second control system. → Verified → AA24-038A: "In one confirmed compromise, Volt Typhoon actors moved laterally to a control system and were positioned to move to a second control system."
-
Claim: Initial access in one confirmed case was achieved by exploiting CVE-2022-42475 on an unpatched FortiGate 300D firewall, with buffer overflow evidence in SSL-VPN crash logs. → Verified → AA24-038A documents this specific initial access vector, including the crash log evidence.
-
Claim: Volt Typhoon used KV Botnet malware implanted on end-of-life Cisco and NETGEAR SOHO routers for C2 proxying, which the US government disrupted. → Verified → AA24-038A and referenced DOJ press release ("U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure").
-
Claim: The actors used FRP (Fast Reverse Proxy) clients with filenames
BrightmetricAgent.exeandSMSvcService.exe, UPX-packed, on victim infrastructure for covert C2 channels. → Verified → AA24-038A documents these exact filenames, the UPX packing, the ShoreTel ECC server placement, and the KCP-over-UDP protocol details; corroborated by CISA Malware Analysis Report MAR-10448362-1.v1. -
Claim: Volt Typhoon's activity is definitively attributable to the PRC government itself rather than PRC-based criminal actors. → Partially verified → Attribution to a PRC state-sponsored actor is asserted with high confidence by five governments and supported by target selection, but the advisory does not publish the classified evidence linking specific operators to PRC state direction. Independent verification of the state nexus is not possible from public sources.
-
Claim: Volt Typhoon has actually executed disruptive or destructive actions against OT systems. → Unverified / Not supported by available evidence → The advisory consistently frames the activity as pre-positioning ("intends to," "pre-positioning to enable"). No confirmed destructive OT event attributed to Volt Typhoon has been publicly documented.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| Mid-2021 | Volt Typhoon | Group becomes active; campaign begins targeting Guam and US critical infrastructure | Microsoft Threat Intelligence |
| 2019–2024 (est.) | Volt Typhoon | Maintains persistent access in some victim networks for at least five years, per agency assessment | AA24-038A |
| Pre-2023 | Volt Typhoon | Exploits CVE-2022-42475 on unpatched FortiGate 300D; gains initial access; buffer overflow observed in SSL-VPN crash logs | AA24-038A |
| Continuous | Volt Typhoon | Reconnaissance via FOFA, Shodan, Censys; targets personal emails of network and IT staff | AA24-038A |
| (9-month span) | Volt Typhoon | Water/Wastewater compromise: VPN in with stolen admin creds → RDP → file server → DC → Oracle Management Server → vCenter server adjacent to OT | AA24-038A |
| (4-year span) | Volt Typhoon | Extracts NTDS.dit from three domain controllers of one victim | AA24-038A |
| (9-month span) | Volt Typhoon | Extracts NTDS.dit twice from another victim | AA24-038A |
| May 24, 2023 | Microsoft Threat Intelligence | Public disclosure of Volt Typhoon LOTL campaign against US critical infrastructure in Guam and elsewhere | Microsoft Security Blog |
| May 2023 | NSA et al. | Joint advisory AA23-144A: "People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection" | NSA/CISA |
| 2023–2024 | Volt Typhoon | KV Botnet implants deployed on EOL Cisco/NETGEAR SOHO routers as C2 proxy layer | DOJ press release |
| Early 2024 | US DOJ / FBI | Court-authorized operation disrupts KV Botnet, removing implants from hijacked routers | DOJ press release |
| Feb 7, 2024 | CISA, NSA, FBI + partners | Joint advisory AA24-038A published: "pre-positioning" assessment made public | CISA AA24-038A |
| Feb–May 2024 | CISA | MAR-10448362-1.v1 (Volt Typhoon malware analysis) and STIX IoC package released | CISA AR24-038A |
Attack Anatomy
Reconnaissance
Volt Typhoon conducts extensive pre-compromise reconnaissance: gathering victim organization information, network details, and staff identities; searching victim-owned websites; and using FOFA, Shodan, and Censys to identify exposed infrastructure. Post-compromise, they targeted the personal email addresses of key network and IT staff, and stole Chrome browsing history plus the Local State (AES key) and Login Data files from administrators' workstations — enabling decryption of stored browser passwords and insight into internal infrastructure through browsing patterns.
Initial Access
The primary vector is exploitation of vulnerabilities in public-facing network appliances — Fortinet, Ivanti Connect Secure (formerly Pulse Secure), NETGEAR, Citrix, and Cisco devices — using publicly available exploits or self-developed zero-days. The advisory's documented example: exploitation of CVE-2022-42475 against an unpatched FortiGate 300D, with the buffer overflow attack identifiable in the SSL-VPN crash logs. In that intrusion, Volt Typhoon additionally recovered a domain admin credential that had been improperly stored on the compromised appliance itself. Post-access, they connect back into the environment via the victim's own VPN, blending with legitimate remote administration traffic.
Privilege Escalation & Credential Access
The credential-theft chain is the campaign's technical core:
- Lateral movement to DC via interactive RDP using compromised domain administrator credentials.
- Shadow copy creation using Windows-native
vssadmin— creating a point-in-time snapshot that bypasses file locking on the liveNTDS.dit. - Extraction via WMIC/ntdsutil — copying
NTDS.ditand theSYSTEMregistry hive (which holds the keys needed to decrypt NTDS contents) out of the shadow copy into staging directories such asC:\Users\Public\proandC:\Windows\Temp\tmp\Active Directory. - Archiving with a renamed RAR binary observed as
ronf.exe. - Offline cracking of the extracted hashes, yielding plaintext credentials for long-term reuse.
Additional credential techniques observed: dumping LSASS memory using a legitimate-but-misplaced copy of comsvcs.dll with its MiniDump export (a detection-evading LOLBin variant), Magnet RAM Capture (MRC v1.20) for in-memory credential and in-transit data analysis on domain controllers, Mimikatz, and Impacket.
Persistence
Persistence is almost entirely credential-based. Volt Typhoon's durable access comes from valid accounts rather than implants — which is precisely why they exfiltrate NTDS.dit repeatedly over multi-year spans: to keep their valid account set current as passwords change. They demonstrated awareness of behavioral detection by restricting some operations to normal working hours to avoid anomalous-login alerts.
Defense Evasion
LOTL dominance: cmd, PowerShell, certutil, dnscmd, ldifde, makecab, net user/group/use, netsh, nltest, netstat, ntdsutil, ping, quser, reg, systeminfo, tasklist, wevtutil, whoami, wmic, xcopy. Beyond LOTL: FRP client binaries and the ScanLine port scanner were UPX-packed; filenames masqueraded as legitimate services (SMSvcService.exe, BrightmetricAgent.exe); and actors selectively cleared Windows Event Logs (Event ID 1102 in the Security log — "audit log cleared" — is a key hunting indicator) and removed staged artifacts such as user.dat and systeminfo.dat after collection.
Discovery & Collection
PowerShell was used to extract security event logs (specifically successful logon Event ID 4624) into files like C:\users\public\documents\user.dat for authentication-pattern analysis. A file rult3uil.log found in C:\Windows\System32\ of a DC contained timestamps of window focus, keypresses, and command executions — user-behavior surveillance on the domain controller itself. Collection focused on OT-relevant material: in one compromise, actors zipped diagrams and documentation for SCADA systems, relays, and switchgear on a file server. In another, they knowingly browsed directories containing construction drawings and facility data.
Lateral Movement Toward OT
RDP with stolen administrator credentials is the primary movement method; PSExec with auto-accepted EULA (-accepteula) was also used for remote execution. The advisory's pivotal finding: in a Water and Wastewater Sector intrusion, actors traversed file server → domain controller → Oracle Management Server → VMware vCenter server adjacent to OT assets, where they enumerated stored PuTTY sessions covering water treatment plants, water wells, an electrical substation, OT systems, and network security devices — giving them the potential to access those systems without further exploitation. Separately, anomalous login attempts to an Azure tenant using credentials consistent with NTDS.dit theft suggested possible cloud pivoting, though attribution for that activity was inconclusive.
Exfiltration
Exfiltration was kept minimal and targeted — consistent with pre-positioning rather than bulk espionage. The documented channel is SMB exfiltration of zipped archives. The advisory notes that industry reporting confirms long periods of near-silence punctuated by credential re-harvesting.
Command and Control
Two layers: (1) compromised EOL SOHO routers (Cisco, NETGEAR, plus ASUS, D-Link, Zyxel models with internet-exposed HTTP/SSH management) implanted with KV Botnet forming multi-hop proxies; (2) FRP clients planted on victim infrastructure establishing reverse proxies back to actor C2 over TCP/UDP/HTTP/HTTPS, using the KCP protocol for error-checked anonymous UDP delivery. In one case, a Paessler PRTG monitoring server was converted into an internal proxy via a netsh PortProxy registry modification — redirecting specific port traffic into Volt Typhoon's proxy infrastructure and abusing a trusted monitoring host.
Loading diagram...
Threat Actor Profile
- Name / Alias: Volt Typhoon (Microsoft); also tracked as Vanguard Panda, BRONZE SILHOUETTE, DEV-0391, UNC3236, Voltzite, Insidious Taurus.
- Attribution Confidence: High (multi-agency, multi-government). Assessed PRC state sponsorship with high confidence by US and Five Eyes partners.
- Motivation: Strategic pre-positioning for potential disruptive/destructive effects against US critical infrastructure during a geopolitical crisis or conflict — assessed explicitly as not consistent with traditional espionage tradecraft.
- Sophistication Level: Advanced. No reliance on custom endpoint malware; deep Windows internals knowledge (NTDS/VSS/LSASS/ESENT behavior); disciplined OpSec with selective log clearing; multi-year re-validation of access; OT-aware target selection.
- Known Previous Operations: Active since at least mid-2021; Guam telecommunications targeting (2023 Microsoft disclosure); sustained multi-year presence in energy, water, transport, and communications networks.
- Nation-State Nexus: Yes — assessed by the US government and Five Eyes partners as PRC state-sponsored. Direct classified evidence is not public.
- MITRE ATT&CK Techniques:
- T1591 / T1590 / T1589 / T1593 / T1594 / T1592 — Reconnaissance (org, network, identity, host info; FOFA/Shodan/Censys)
- T1583.003 / T1584.005 — Acquire/Compromise Infrastructure: Botnet (KV Botnet SOHO routers)
- T1190 — Exploit Public-Facing Application (Fortinet/Ivanti/NETGEAR/Citrix/Cisco edge devices; CVE-2022-42475)
- T1133 — External Remote Services (VPN-based re-entry)
- T1059.001 / T1059.004 / T1059 / T1218 — Command execution via PowerShell, Unix shell, LOLBins
- T1105 — Ingress Tool Transfer (comsvcs.dll, MRC, FRP)
- T1078 / T1078.004 — Valid Accounts (incl. cloud accounts)
- T1027.002 — Software Packing (UPX on FRP clients, ScanLine)
- T1070.001 / T1070.009 / T1070.004 — Clear event logs, clear persistence, file deletion
- T1036.005 — Masquerading (BrightmetricAgent.exe, SMSvcService.exe)
- T1068 — Exploitation for Privilege Escalation
- T1552 / T1552.004 — Unsecured Credentials (on edge appliances; Private Keys — Chrome Local State AES key)
- T1003.003 — OS Credential Dumping: NTDS (vssadmin + ntdsutil + SYSTEM hive)
- T1003.001 — LSASS Memory (comsvcs.dll MiniDump)
- T1555.003 — Credentials from Web Browsers
- T1110.002 — Password Cracking (offline)
- T1006 — Direct Volume Access (shadow copies)
- T1047 — Windows Management Instrumentation
- T1021.001 / T1021.007 — RDP / Cloud Services (possible Azure pivot)
- T1550 — Use Alternate Authentication Material (potential PtH/PtT after full AD compromise)
- T1563 — Remote Service Session Hijacking (PuTTY session enumeration)
- T1082 / T1046 / T1069 / T1033 / T1057 / T1087.001 / T1007 / T1016.001 / T1010 / T1012 / T1083 / T1654 — Discovery (system, network, groups, users, processes, services, windows, registry, files, log enumeration)
- T1560.001 — Archive Collected Data (ronf.exe / renamed rar)
- T1048 — Exfiltration Over Alternative Protocol (SMB)
- T1090 / T1090.001 / T1090.003 — Proxy (FRP clients; netsh PortProxy on PRTG; multi-hop SOHO proxies)
- T1112 — Modify Registry (PortProxy key)
- T1573 — Encrypted Channel (KCP-over-UDP FRP)
- Operational Security (OpSec): Exceptional for a state actor: five-year undetected dwell, working-hours-only activity to evade behavioral analytics, no bulk exfiltration, log clearing, UPX packing, filename masquerading. Key weaknesses: repeated NTDS.dit extraction leaves detectable ESENT events (216, 325, 326, 327, 637); RDP sessions generate Terminal Services logs (21–25); log-clearing itself fires Security Event 1102.
Technical Indicators
domains: []
ip_addresses: []
file_hashes: []
urls: []
files_and_artifacts:
- "BrightmetricAgent.exe — UPX-packed FRP client (C2 reverse proxy)"
- "SMSvcService.exe — UPX-packed FRP client planted on ShoreTel ECC server"
- "ronf.exe — renamed RAR archiver used to compress NTDS.dit + SYSTEM hive"
- "comsvcs.dll — legitimate DLL downloaded to non-standard folder for LSASS MiniDump abuse"
- "rult3uil.log — user-activity surveillance log in C:\\Windows\\System32\\ on DC"
- "user.dat — staged 4624 logon-event extract in C:\\Users\\Public\\Documents"
- "systeminfo.dat — staged then deleted from C:\\Users\\Public\\Documents"
- "History.zip — staged Chrome browser-history archive in user Downloads"
- "C:\\Users\\Public\\pro, C:\\Windows\\Temp\\tmp\\Active Directory, C:\\Windows\\Temp\\tmp\\registry — NTDS staging paths"
network_and_c2:
- "KV Botnet implants on end-of-life Cisco and NETGEAR SOHO routers (DOJ-disrupted)"
- "FRP clients using KCP protocol over UDP; TCP/UDP/HTTP/HTTPS reverse proxies"
- "netsh PortProxy registry modification on PRTG server converting it to internal proxy"
- "Multi-hop proxies across compromised VPS and SOHO infrastructure"
vulnerabilities:
- "CVE-2022-42475 — FortiGate SSL-VPN buffer overflow (confirmed initial access in one compromise)"
detection_artifacts:
- "Windows ESENT Application log Event IDs 216, 325, 326, 327, 637 — NTDS.dit copy/staging"
- "Security log Event ID 1102 — audit log cleared"
- "Terminal Services LSM Operational log Event IDs 21-25 — RDP session telemetry"
- "PowerShell command: Get-EventLog security -instanceid 4624 -after <date> | fl * | Out-File 'C:\\users\\public\\documents\\user.dat'"
- "ntdsutil invocation via WMIC against volume shadow copies"
- "taskkill /f /im rdpservice.exe"
- "PSExec with -accepteula flag under admin accounts"Note: CISA published a downloadable STIX 2.0 IoC package (MAR-10448362.c1.v2.CLEAR_stix2.json) alongside Malware Analysis Report MAR-10448362-1.v1; the above captures the artifacts documented in the advisory text itself.
Legal and Regulatory Response
Law Enforcement Actions
The FBI led the court-authorized disruption of the KV Botnet in early 2024, removing Volt Typhoon's implants from hijacked US-based SOHO routers that formed its proxy layer. The Department of Justice publicly announced the operation in "U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure." FBI field offices engaged directly with compromised critical infrastructure operators through incident response activities that produced the advisory's confirmed-compromise evidence.
Government Directives
Joint advisory AA24-038A (Feb 7, 2024) was issued by CISA, NSA, FBI, DOE, EPA, and TSA with co-seal from Australia's ASD/ACSC, Canada's CCCS, UK NCSC, and New Zealand NCSC-NZ — an unusually broad set for a US domestic infrastructure warning. Directive-level mitigations include: priority patching of Fortinet, Ivanti, NETGEAR, Citrix, and Cisco internet-facing appliances; phishing-resistant MFA; centralized logging; and end-of-life planning for unsupported technology. The advisory was paired with the joint guide "Identifying and Mitigating Living Off the Land Techniques," the Secure by Design alert for SOHO device manufacturers, and CISA's Cross-Sector Cybersecurity Performance Goals.
Platform Response
Microsoft published the original disclosure (May 2023) with Defender detections and Microsoft 365 Defender/Sentinel hunting queries, including ntdsutil-based domain controller media-creation detection and internal-proxy detection. Sandia National Labs released the gait Zeek extension, recommended in the advisory, for enriching connection logs with TCP/TLS/SSH timing metadata to surface proxy infrastructure. Network appliance vendors' patch posture (Fortinet, Ivanti, NETGEAR, Citrix, Cisco) became a core mitigation focus, alongside vendor-agnostic calls to eliminate credential storage on edge devices.
Criminal Proceedings
No indictments of individual Volt Typhoon operators have been publicized in the advisory or its cited DOJ release. The US government response has centered on technical disruption (KV Botnet takedown), collective public attribution, and defensive guidance rather than criminal charging documents as of the advisory's publication.
Impact Assessment
- Confirmed sectors compromised: Communications, Energy, Transportation Systems, Water and Wastewater Systems — continental US, non-continental US, and Guam.
- Victim profile: Includes smaller organizations with limited cybersecurity capability that provide critical services to larger organizations or key geographic regions.
- Dwell time: At least five years in some environments — among the longest publicly confirmed dwell times for a state actor in US civilian infrastructure.
- Credential compromise scope: Full Active Directory compromise in confirmed cases via repeated NTDS.dit extractions (3 DCs/4 years; 2 extractions/9 months).
- OT exposure: Confirmed lateral movement to OT-adjacent systems (vCenter with PuTTY profiles for water plants and substations); confirmed positioning on one control system with a path to a second. No destructive OT action confirmed.
- Data exfiltrated: SCADA diagrams, relay/switchgear documentation, facility/construction drawings, domain credentials, browser data of network administrators.
- Strategic impact: First joint, multi-nation public assessment that a PRC actor is pre-positioning for disruption rather than espionage — a doctrinal shift that reshaped congressional testimony, CISA funding priorities, and the FCC's rip-and-replace/edge-hardening debates through 2024.
Lessons and Defensive Recommendations
For Security Teams / SOC Analysts:
- Hunt on ESENT Application log events 216, 325, 326, 327, and 637 — NTDS.dit database relocation and staging are the highest-fidelity Volt Typhoon indicators because their persistence model requires repeated credential re-harvesting.
- Treat every Security log Event 1102 (log cleared) as an investigation trigger, and baseline then alert on RDP Terminal Services events 21–25 from unexpected sources or off-hours sessions.
- Alert on
ntdsutil,vssadmin(especiallyvssadmin create shadow), andcomsvcs.dll-based dumping from any non-ITSM-correlated context; watch forGet-EventLog ... 4624 ... Out-Fileextraction patterns. - Deploy the Sandia
gaitZeek extension or equivalent TLS/TCP timing telemetry to detect proxy chains; baseline normal VPN login times, frequency, duration, and geography to catch "impossible travel" by valid accounts. - Audit
C:\Windows\Temp,C:\Users\Public, and non-standard paths for copies ofSystem32binaries, archives, or staged database files.
For Developers and Architects:
- Eliminate the need for credentials on edge appliances entirely — a domain admin credential stored on a FortiGate was Volt Typhoon's documented on-ramp in one confirmed case.
- Architect segmentation so that IT-to-OT adjacency (e.g., vCenter bridging both worlds) is monitored, brokered, and does not accumulate reusable session material like stored PuTTY profiles for plant equipment.
- Prefer managed identity / short-lived credentials over static domain accounts for any service touching critical paths; assume credentials, not implants, are the persistence mechanism.
For Platform / Cloud Providers:
- Harden telephone-edge and management interfaces of SOHO/enterprise appliances against default exposure; accelerate end-of-life firmware replacement guidance, since EOL Cisco/NETGEAR routers were the chosen C2 substrate.
- Improve detections for legitimate tools performing anomalous actions at scale: auto-accepted EULA PSExec pushes, WMI-invoked ntdsutil, and shadow-copy creation outside backup windows.
- Watch for AD-to-cloud account reuse: leaked NTDS hashes facilitate lateral movement into Azure tenants where MFA and conditional access are misconfigured or legacy accounts are exempt.
For Leadership / CISO:
- Adopt the agencies' stated assumption: a Volt Typhoon indication means assume full domain compromise — sever internet connectivity, reset all privileged and local accounts, reset
krbtgttwice with replication in between, audit every edge-device configuration, and only then reconnect. - Fund logging retention sufficient for multi-year dwell: ephemeral endpoint telemetry alone cannot reconstruct a five-year intrusion; preserve ESENT and authentication logs centrally.
- Include "pre-positioning" — quiet, credential-based, OT-adjacent access — explicitly in threat models and tabletop exercises; do not measure risk only by observed data theft.
- Institute asset lifecycles that force replacement of end-of-support network appliances; EOL devices are where this adversary builds its infrastructure.
Sources
- CISA, NSA, FBI, DOE, EPA, TSA, ASD/ACSC, CCCS, NCSC-UK, NCSC-NZ. "PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A)". 7 Feb 2024.
- Microsoft Threat Intelligence. "Volt Typhoon targets US critical infrastructure with living-off-the-land techniques". 24 May 2023.
- CISA, NSA, FBI et al. "People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (AA23-144A)". May 2023.
- US Department of Justice. "U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure". 2024.
- CISA. "MAR-10448362-1.v1 Volt Typhoon — Malware Analysis Report". 2024.
- CISA. "MAR-10448362.c1.v2.CLEAR_stix2.json — Indicators of Compromise". 2024.
- CISA et al. "Identifying and Mitigating Living Off the Land Techniques". 2024.
- CISA. "Secure by Design Alert: Security Design Improvements for SOHO Device Manufacturers".
- Sandia National Laboratories. "gait: Zeek Extension to Collect Metadata for Profiling of Endpoints and Proxies". GitHub.
- NSA et al. "Identifying and Mitigating Living Off the Land (LOTL) — CSA_Living_off_the_Land.PDF". 24 May 2023.
- NIST NVD. "CVE-2022-42475 — FortiOS / FortiProxy SSL-VPN Heap-Based Buffer Overflow".
- MITRE ATT&CK. Techniques referenced per AA24-038A Appendix C mapping (v14)
Related Research
In July 2026, a small-scale gas-fired electricity generation facility in the United Kingdom suffered a four-day operational shutdown following a sophisticated cyberattack. The targeted plant,...
A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.
The cyber espionage landscape has evolved toward an industrialized 'quartermaster' model of network obfuscation and reconnaissance. On August 26, 2026, the United States Department of Justice (DOJ)...