Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

U.S. agencies assess that Volt Typhoon, a PRC state-sponsored cyber actor, has sought to maintain access to networks in U.S. critical-infrastructure organizations in case it could disrupt or destroy services during a future crisis or conflict. The cited government statements describe a potential contingency purpose—not evidence that Volt Typhoon has already caused those destructive effects.

What is Volt Typhoon?

Volt Typhoon is the name U.S. agencies use for a cyber campaign they attribute to a PRC state-sponsored actor. On February 7, 2024, CISA, NSA, the FBI and partner agencies described compromises in critical-infrastructure organizations and assessed that the actor was pre-positioning for possible disruptive or destructive activity in a future crisis.

That assessment is significant because it frames the activity as preparation for a possible future contingency, rather than simply espionage or an attack whose destructive effects have already been demonstrated in these sources. FBI Director Christopher Wray said on January 31, 2024, that “China’s hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict.” This is the government’s characterization of the assessed intent and potential harm.

Which infrastructure sectors were identified?

A U.S. government fact sheet marked “As of March 2024” says organizations compromised by the activity were especially in these sectors:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Communications
  • Energy
  • Transportation systems
  • Water and wastewater

The fact sheet also notes that Canada, Australia and New Zealand assess that similar activity could affect their infrastructure. That is a risk assessment about potential exposure; it is distinct from the U.S. observations about compromised organizations.

How does “living off the land” work?

In its May 24, 2023 joint advisory, U.S. and partner agencies described Volt Typhoon’s use of “living off the land”: relying on built-in system functions and tools instead of depending on malware to maintain access and conduct activity. The agencies said this approach can help the actor evade detection.

For defenders, the practical challenge is that legitimate administrative functions can also be misused. A tool or command may not look suspicious by itself, so monitoring needs to account for context: which account used it, on which system, at what time, and whether the activity fits the system’s normal role. Application, access and security logs—stored centrally—can help teams connect those events and investigate anomalies.

What happened with the KV Botnet?

In December 2023, a court-authorized U.S. operation disrupted a botnet of hundreds of U.S.-based small-office/home-office (SOHO) routers. The Department of Justice said Volt Typhoon used routers infected with KV Botnet malware to conceal the PRC origin of further hacking activity. The operation removed malware and blocked communications to botnet-control devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The DOJ described the mitigation as temporary and warned that remediated routers remained vulnerable to future exploitation. The vast majority of the routers in the botnet were Cisco and Netgear devices that had reached end of life and no longer received manufacturer security patches or other software updates. The FBI urged owners to remove and replace end-of-life SOHO routers. This warning concerns unsupported devices; it does not mean that all routers from either manufacturer are unsafe.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can organizations detect and defend against this activity?

Agency guidance emphasizes layered preparation rather than reliance on a single alert or product. The measures below reflect the CISA/FBI leadership fact sheet’s recommendations and the DOJ account of unsupported router risks.

Improve visibility and detection

  • Collect application, access and security logs, and store them centrally so teams can correlate activity across systems.
  • Apply detection and hardening practices, with attention to built-in administrative tools and commands used outside their expected context.
  • Train staff continuously to recognize and report anomalous activity.

Prepare for disruption, including in operational technology

  • Create a comprehensive information-security incident plan and exercise it before an incident.
  • Test operational-technology (OT) systems and the procedures for operating them in manual mode; identify how essential services can continue safely if connected systems are unavailable.
  • For an incident, follow the response plan, report anomalous activity, and consider having a third-party incident-response retainer in place.

Address supplier and equipment risk

  • Conduct supply-chain risk management and due diligence when selecting software, devices, cloud providers and managed-service providers.
  • Check whether internet-facing equipment remains within the manufacturer’s support lifecycle and receives security updates. Replace devices that have reached end of life rather than treating a one-time cleanup as a lasting fix.

Match support to internal capacity

Organizations without an internal cybersecurity team can consider managed security services to help with monitoring and response. The relevant choice depends on whether a provider can deliver useful application, access and security-log visibility; identify anomalous use of built-in tools; support the organization’s IT and OT environment; and work within its incident plan. These are decision criteria drawn from agency guidance, not a comparison or endorsement of particular vendors.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.