{
  "id": "case-volt-typhoon-infrastructure",
  "slug": "volt-typhoon-infrastructure-prepositioning",
  "title": "Volt Typhoon Critical Infrastructure Pre-Positioning Campaign",
  "summary": "State-sponsored cyber campaign by the People's Republic of China (Volt Typhoon / Bronze Silhouette / Vanguard Panda) infiltrating operational and IT environments of U.S. water treatment, electric grid, pipeline, and transportation authorities in Guam and the continental U.S., leveraging living-off-the-land techniques to establish disruptive pre-positioned footholds for geopolitical crisis contingencies.",
  "case_number": "CISA-FBI-NSA-JSA-2024-02",
  "court": "Joint Cybersecurity Advisory: CISA, NSA, FBI, CCCS, ACSC, NCSC-NZ, NCSC-UK",
  "district": "U.S. Critical Infrastructure",
  "country": "United States",
  "opened_at": "2024-02-07",
  "status": "investigation",
  "victim_sector": "Water, Energy, Transportation, Communications",
  "victim_country": "United States",
  "loss_amount_usd": 250000000,
  "loss_amount_note": "Nationwide perimeter replacement, OT architecture segregation, and multi-agency federal incident triage.",
  "first_seen_at": "2021-06-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "volt-typhoon",
  "defendant_slugs": [],
  "cves": [
    "CVE-2023-46805",
    "CVE-2024-21887",
    "CVE-2022-42475"
  ],
  "techniques": [
    {
      "technique_id": "T1059",
      "evidence_excerpt": "Actors strictly avoided installing malware, exclusively utilizing native administrative utilities (wmic, ntdsutil, netsh) to blend into legitimate system administration.",
      "evidence_locator": "CISA Advisory: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to US Critical Infrastructure",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Joint Cybersecurity Advisory on Volt Typhoon",
      "source_url": "https://www.cisa.gov"
    },
    {
      "technique_id": "T1090.003",
      "evidence_excerpt": "Operated the KV-botnet comprising compromised end-of-life Cisco, Netgear, and DrayTek SOHO routers to proxy C2 traffic through domestic residential IP blocks.",
      "evidence_locator": "DOJ Court-Authorized Botnet Disruption Order (S.D. Tex.)",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Disruption of KV-Botnet Used by Volt Typhoon",
      "source_url": "https://www.justice.gov"
    }
  ],
  "events": [
    {
      "event_type": "incident",
      "event_date": "2023-05-24",
      "description": "Microsoft and Five Eyes intelligence agencies disclose Volt Typhoon targeting Guam critical infrastructure."
    },
    {
      "event_type": "court_order",
      "event_date": "2024-01-31",
      "description": "DOJ and FBI execute federal court order neutralizing the KV-botnet router infrastructure."
    },
    {
      "event_type": "congressional_hearing",
      "event_date": "2024-01-31",
      "description": "FBI Director Christopher Wray testifies before House Select Committee on CCP cyber threat to critical infrastructure."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Adversary initial penetration relied on exploitation of known vulnerabilities (CVE-2023-46805, CVE-2024-21887, CVE-2022-42475) combined with targeted spearphishing and stolen remote access credentials.",
    "blast_radius": "Nationwide perimeter replacement, OT architecture segregation, and multi-agency federal incident triage. Impacted Water, Energy, Transportation, Communications infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Infiltration",
        "title": "Perimeter Ingress",
        "description": "Operatives secured access to victim infrastructure within the Water, Energy, Transportation, Communications sector.",
        "technical_artifacts": [
          "Network perimeter logs"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Phase 2: Execution",
        "title": "Payload Deployment",
        "description": "State-sponsored cyber campaign by the People's Republic of China (Volt Typhoon / Bronze Silhouette / Vanguard Panda) infiltrating operational and IT environments of U.S. water treatment, electric grid, pipeline, and transportation authorities in Guam and the continental U.S., leveraging living-off-the-land techniques to establish disruptive pre-positioned footholds for geopolitical crisis contingencies.",
        "technical_artifacts": [
          "Malicious payload"
        ],
        "mitre_technique_id": "T1486"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}