Site icon TheCyberThrone

Volt Typhoon – Chinese Threat Actor Targetting US Infra

Advertisements

Researchers at Microsoft detailed a sophisticated cyberattack aimed at critical U.S. infrastructure, orchestrated by an alleged China-based state-sponsored actor.

The threat actor goes by the name, Volt Typhoon, has been active since mid-2021 and is suspected of preparing to disrupt U.S.-Asia communication networks in potential future crises. The sectors affected by the campaign include communications, manufacturing, utilities, transportation, construction, maritime, government, information technology and education.

Its campaign emphasizes stealth, using advanced techniques such as living-off-the-land binaries of LOLBins and hands-on-keyboard activity. The TTP include gathering credentials, staging data for exfiltration, and maintaining persistence in compromised systems using valid credentials.

Advertisements

The group obfuscates itself by attempting to blend with typical network activity by routing traffic through compromised small office and home office network equipment and establishing C2 channels over proxies using custom open-source tools.

The U.S. intelligence agencies first became aware of the Volt Typhoon campaign in February, at around the same time an alleged Chinese spy balloon crossed North America. The infiltration is focused on communications infrastructure in Guam and other parts of the U.S., alarming intelligence officials because Guam is vital to any response to a future invasion of Taiwan.

The researchers note that detecting and mitigating infiltration by Volt Typhoon can be difficult due to the use of valid accounts and LOLBins. To address compromised accounts, Microsoft has provided detailed information on Volt Typhoon’s activities, mitigation strategies, best practices, and details on how Microsoft 365 Defender detects such activity.

Microsoft has notified targeted or compromised customers directly and provided the necessary information to secure their systems.

Advertisements

Defending against this campaign

Indicators of Compromise

Exit mobile version