CASE DOSSIER investigation

Volt Typhoon Critical Infrastructure Pre-Positioning Campaign

Docket: CISA-FBI-NSA-JSA-2024-02 Court: Joint Cybersecurity Advisory: CISA, NSA, FBI, CCCS, ACSC, NCSC-NZ, NCSC-UK Opened: 2024-02-07 Sector: Water, Energy, Transportation, Communications

Key Facts

Status
INVESTIGATION
Legal disposition
Loss Amount
$250.0 million
Nationwide perimeter replacement, OT architecture segregation, and multi-agency federal incident triage.
Techniques
2
Verified mappings
Defendants
0
Named in charges
  • Legal Status: INVESTIGATION in Joint Cybersecurity Advisory: CISA, NSA, FBI, CCCS, ACSC, NCSC-NZ, NCSC-UK.
  • Primary Target Sector: Water, Energy, Transportation, Communications.
  • Documented Financial Loss: $250.0 million.
  • 2 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

State-sponsored cyber campaign by the People's Republic of China (Volt Typhoon / Bronze Silhouette / Vanguard Panda) infiltrating operational and IT environments of U.S. water treatment, electric grid, pipeline, and transportation authorities in Guam and the continental U.S., leveraging living-off-the-land techniques to establish disruptive pre-positioned footholds for geopolitical crisis contingencies.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2022-42475) combined with targeted spearphishing and stolen remote access credentials.

Operational & Financial Fallout

Nationwide perimeter replacement, OT architecture segregation, and multi-agency federal incident triage. Impacted Water, Energy, Transportation, Communications infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: INVESTIGATION
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2022-42475) combined with targeted spearphishing and stolen remote access credentials.

Adversary Kill Chain Flow

2 Documented Phases
1
Phase 1: Infiltration Perimeter Ingress
MITRE ATT&CK T1190 →

Operatives secured access to victim infrastructure within the Water, Energy, Transportation, Communications sector.

Artifacts & Tooling: Network perimeter logs
2
Phase 2: Execution Payload Deployment
MITRE ATT&CK T1486 →

State-sponsored cyber campaign by the People's Republic of China (Volt Typhoon / Bronze Silhouette / Vanguard Panda) infiltrating operational and IT environments of U.S. water treatment, electric grid, pipeline, and transportation authorities in Guam and the continental U.S., leveraging living-off-the-land techniques to establish disruptive pre-positioned footholds for geopolitical crisis contingencies.

Artifacts & Tooling: Malicious payload
Real-World Blast Radius & Operational Fallout

Nationwide perimeter replacement, OT architecture segregation, and multi-agency federal incident triage. Impacted Water, Energy, Transportation, Communications infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2023-05-24 incident

Microsoft and Five Eyes intelligence agencies disclose Volt Typhoon targeting Guam critical infrastructure.

2024-01-31 court_order

DOJ and FBI execute federal court order neutralizing the KV-botnet router infrastructure.

2024-01-31 congressional_hearing

FBI Director Christopher Wray testifies before House Select Committee on CCP cyber threat to critical infrastructure.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1059
"Actors strictly avoided installing malware, exclusively utilizing native administrative utilities (wmic, ntdsutil, netsh) to blend into legitimate system administration." CISA Advisory: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to US Critical Infrastructure reviewed
T1090.003
"Operated the KV-botnet comprising compromised end-of-life Cisco, Netgear, and DrayTek SOHO routers to proxy C2 traffic through domestic residential IP blocks." DOJ Court-Authorized Botnet Disruption Order (S.D. Tex.) reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Volt Typhoon Critical Infrastructure Pre-Positioning Campaign, No. CISA-FBI-NSA-JSA-2024-02 (Joint Cybersecurity Advisory: CISA, NSA, FBI, CCCS, ACSC, NCSC-NZ, NCSC-UK 2024), https://cybercaselibrary.com/cases/volt-typhoon-infrastructure-prepositioning/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/volt-typhoon-infrastructure-prepositioning" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>