top of page

Volt Typhoon: Quietly Positioning Inside Critical Infrastructure

7 days ago
4 min read

Most of the attacks that make headlines do something visible: a shutdown, an outage, a ransom note. Volt Typhoon is different and, in some ways, more unsettling. It is an intrusion campaign whose apparent purpose is not to act now but to be in position to act later. It hides by blending into normal activity, and it can sit undetected for years. For operators of critical infrastructure, it is a reminder that the absence of damage is not the same as the absence of an intruder.

What happened

In May 2023, Microsoft publicly described a threat actor it named Volt Typhoon, assessing it to be a state-sponsored group based in China and active since at least mid-2021. Microsoft reported that the group was targeting critical infrastructure organizations, including in Guam, and assessed with moderate confidence that it was developing capabilities that could disrupt communications between the United States and the Asia region during a future crisis.

In February 2024, a joint advisory, carrying the identifier AA24-038A, was issued by CISA, the NSA, the FBI and international partners, including Canada's Cyber Centre. It attributed the activity to People's Republic of China state-sponsored actors and described pre-positioning inside US critical infrastructure across the communications, energy, water and wastewater, and transportation sectors, as well as in Guam. The agencies assessed that the actors were positioning themselves to be able to disrupt operations in the event of a major crisis or conflict, and reported that in some cases they had maintained access for at least five years.

Shortly before that advisory, in late January 2024, the US government announced a court-authorized operation that disrupted a botnet of compromised small-office and home-office routers, many of them end-of-life Cisco and NetGear devices, that Volt Typhoon had used to hide its activity.

How it worked, at a high level

Four-step flow: compromised edge devices, living-off-the-land in IT networks, long-term hidden access, positioned to disrupt operations
Volt Typhoon hides by using legitimate tools and compromised edge devices, and has kept access for years.

Volt Typhoon's approach is defined by stealth rather than force:

  • Living off the land. Instead of deploying custom malware that security tools might catch, the actors rely heavily on legitimate tools and features already present on compromised systems. Their activity looks like normal administration, which is what makes it so hard to spot.

  • Edge devices as a foothold and a hiding place. They are reported to gain access through internet-facing appliances such as VPN gateways and firewalls, and to route their traffic through compromised home and small-office routers to blend in with ordinary internet traffic.

  • Patience over impact. The point is not to cause an effect today. It is to establish and quietly keep access, learn the environment, and be ready. Dwell times measured in years reflect that goal.

  • Moving toward operations. The concern is that footholds in IT networks are a stepping stone toward operational technology, so that services could be disrupted at a chosen moment.

Impact

Because the aim is pre-positioning rather than disruption, Volt Typhoon has not been linked to outages. The impact is strategic: an adversary believed to be quietly embedded in the networks behind essential services, with the assessed intent to be able to disrupt them later. For defenders, the hard part is that there may be no obvious symptom to react to.

What it taught the industry

  • No damage does not mean no intruder. An environment can be compromised for years without anything visibly going wrong. Security cannot rely only on noticing effects.

  • Living-off-the-land activity evades traditional tools. When attackers use built-in tools, antivirus and signature-based detection often see nothing. Spotting them requires understanding what normal looks like and noticing deviations.

  • Edge devices are the front line. Internet-facing appliances and consumer-grade routers are both entry points and hiding places, and end-of-life hardware is especially risky.

  • Detection and logging matter as much as prevention. If you are not capturing the right logs and keeping them, you may have no way to find a quiet intruder or reconstruct what happened.

Practical defensive lessons

  • Harden and track edge devices. Inventory every internet-facing appliance and router. Patch them promptly, replace end-of-life hardware, require multi-factor authentication, and remove management interfaces from the public internet.

  • Log centrally and keep it. Collect authentication, access and command logs, store them centrally, and retain them long enough to investigate activity that may have begun years earlier.

  • Establish a baseline. Know what normal looks like in your environment, including which accounts act, when and from where, so that quiet, legitimate-looking misuse stands out.

  • Learn to detect living-off-the-land behaviour. Focus on unusual use of built-in administrative tools, odd account behaviour and unexpected lateral movement, rather than relying only on malware signatures.

  • Segment IT from OT. Strong separation between business and control networks makes it far harder for a foothold on the IT side to reach operations, which is the outcome this kind of actor is working toward.

Key takeaways

  • Volt Typhoon, disclosed by Microsoft in May 2023 and detailed in the February 2024 advisory AA24-038A, is attributed to People's Republic of China state-sponsored actors.

  • Its goal is pre-positioning inside communications, energy, water and transportation infrastructure in the US and Guam, with assessed intent to disrupt in a future crisis.

  • It uses living-off-the-land techniques and compromised edge devices to stay hidden, with dwell times of years.

  • The absence of visible damage can mask a long-running intrusion.

  • Edge-device hygiene, logging, baselining, detecting living-off-the-land activity and IT/OT segmentation are the key defences.

How QBits Networks can help

Defending against a quiet, long-dwell intruder depends on visibility and separation, not on waiting for something to break. Our OT visibility snapshots use passive capture to establish what is really happening on your network and help build a baseline, and our network segmentation reviews assess whether a foothold on your IT side could reach your control systems. Tell us what you need through our contact page and we'll scope it with you.

bottom of page