CASE DOSSIER alleged

Volt Typhoon Critical Infrastructure Pre-Positioning

Docket: CISA-AA24-038A Court: Federal Law Enforcement Action / FISA Court Authorized Operations Opened: 2023-05-24 Sector: Communications, Energy, Transportation, Water, Defense Industrial Base

Key Facts

Status
ALLEGED
Legal disposition
Loss Amount
$150.0 million
Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.
Techniques
9
Verified mappings
Defendants
0
Named in charges
  • Legal Status: ALLEGED in Federal Law Enforcement Action / FISA Court Authorized Operations.
  • Primary Target Sector: Communications, Energy, Transportation, Water, Defense Industrial Base.
  • Documented Financial Loss: $150.0 million.
  • 9 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Exploitation of zero-day vulnerabilities in edge networking appliances (Fortinet, Ivanti, Cisco, NETGEAR routers) combined with the KV-botnet of compromised small-office/home-office (SOHO) routers used as obfuscation proxies.

Operational & Financial Fallout

Pre-positioned inside critical infrastructure facilities across the United States and Guam, including drinking water treatment plants, telecommunications switching hubs, electric utility grids, and maritime port facilities. The objective was not financial extortion or immediate espionage, but dormant pre-positioning for disruptive sabotage during a potential geopolitical crisis.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: ALLEGED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Exploitation of zero-day vulnerabilities in edge networking appliances (Fortinet, Ivanti, Cisco, NETGEAR routers) combined with the KV-botnet of compromised small-office/home-office (SOHO) routers used as obfuscation proxies.

Adversary Kill Chain Flow

5 Documented Phases
1
Perimeter Compromise Edge Appliance Infiltration & KV-Botnet Proxying
MITRE ATT&CK T1190 →

Operatives exploited unpatched edge network appliances and routers to establish a multi-tier proxy mesh (KV-botnet), routing malicious traffic through residential IP addresses to bypass geolocation blocks.

Artifacts & Tooling: KV-botnet Compromised SOHO routers Fortinet / Ivanti exploits
2
Credential Access Silent Valid Account Harvesting
MITRE ATT&CK T1078 →

Volt Typhoon acquired valid administrative user accounts without deploying malware, extracting passwords through local memory and registry inspection.

Artifacts & Tooling: Legitimate domain credentials Single sign-on tokens
3
Living-off-the-Land Built-in System Administration Tool Abuse
MITRE ATT&CK T1059.001 →

The actors exclusively utilized native operating system utilities (cmd.exe, powershell.exe, wmic, net.exe) to execute reconnaissance and admin tasks, leaving virtually zero custom malware signatures on disk.

Artifacts & Tooling: wmic.exe net.exe powershell.exe Living-off-the-Land (LotL)
4
Discovery & Active Directory Theft NTDS.dit Shadow Copy Extraction
MITRE ATT&CK T1003 →

Operators created volume shadow copies on domain controllers to extract the Active Directory database (ntds.dit) and SYSTEM registry hives, enabling offline password cracking.

Artifacts & Tooling: vssadmin create shadow /for=C: ntds.dit copy SYSTEM hive export
5
Dormant Pre-Positioning Strategic Operational Technology Preparation
MITRE ATT&CK T1082 →

Operatives established footholds within municipal water, aviation, and power distribution systems, lying dormant for years to maintain persistent leverage for disruptive cyber sabotage during geopolitical conflict.

Artifacts & Tooling: Persistent network tunnels Unmonitored router configurations
Real-World Blast Radius & Operational Fallout

Pre-positioned inside critical infrastructure facilities across the United States and Guam, including drinking water treatment plants, telecommunications switching hubs, electric utility grids, and maritime port facilities. The objective was not financial extortion or immediate espionage, but dormant pre-positioning for disruptive sabotage during a potential geopolitical crisis.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Decommission end-of-life edge devices and immediately disable remote WAN administration on all network appliances.
✓ Audit and detect Living-off-the-Land commands (wmic, net, vssadmin) executed by non-administrative accounts.
✓ Enforce strict behavioral alerting on volume shadow copy creation commands targeting domain controllers.
✓ Physically isolate and air-gap operational technology (OT) control networks from enterprise IT environments.

Procedural & Incident Timeline

2023-05-24 advisory

CISA, NSA, FBI, and Five Eyes agencies issue first joint advisory on Volt Typhoon intrusion campaigns.

2023-12-14 court_order

Federal court in the Southern District of Texas authorizes FBI operation to delete KV botnet malware from compromised routers.

2024-01-31 disclosure

FBI Director Wray testifies before Congress on PRC cyber actor pre-positioning against American civilian infrastructure.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections." CISA Advisory AA24-038A ¶ 3 reviewed
T1190 Exploit Public-Facing Application
Initial Access
"Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances." CISA Advisory AA24-038A ¶ 12 reviewed
T1584 Compromise Infrastructure
Resource Development
"Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States." DOJ Press Release 24-118 reviewed
T1059.003 Windows Command Shell
Execution
"Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware." Advisory Technical Appendix reviewed
T1016 System Network Configuration Discovery
Discovery
"Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing." CISA Advisory AA24-038A ¶ 18 reviewed
T1018 Remote System Discovery
Discovery
"Adversaries executed ping sweeps and 'net group "Domain Computers" /domain' to identify neighboring workstation hostnames." CISA Advisory AA24-038A ¶ 22 reviewed
T1033 System Owner/User Discovery
Discovery
"The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope." CISA Technical Appendix reviewed
T1057 Process Discovery
Discovery
"Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers." CISA Advisory AA24-038A ¶ 19 reviewed
T1570 Lateral Tool Transfer
Lateral Movement
"Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels." CISA Advisory AA24-038A ¶ 25 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, Volt Typhoon Critical Infrastructure Pre-Positioning, No. CISA-AA24-038A (Federal Law Enforcement Action / FISA Court Authorized Operations 2023), https://cybercaselibrary.com/cases/volt-typhoon-critical-infrastructure/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/volt-typhoon-critical-infrastructure" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>