{
  "id": "case-volt-typhoon",
  "slug": "volt-typhoon-critical-infrastructure",
  "title": "Volt Typhoon Critical Infrastructure Pre-Positioning",
  "summary": "State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.",
  "case_number": "CISA-AA24-038A",
  "court": "Federal Law Enforcement Action / FISA Court Authorized Operations",
  "district": "S.D. Tex. & Multiple",
  "country": "United States",
  "opened_at": "2023-05-24",
  "status": "alleged",
  "victim_sector": "Communications, Energy, Transportation, Water, Defense Industrial Base",
  "victim_country": "United States, Guam",
  "loss_amount_usd": 150000000,
  "loss_amount_note": "Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.",
  "first_seen_at": "2021-06-01T00:00:00Z",
  "last_updated_at": "2026-09-15T14:00:00Z",
  "actor_slug": "volt-typhoon",
  "defendant_slugs": [],
  "cves": [
    "CVE-2023-27997",
    "CVE-2023-46805"
  ],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 3",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1584",
      "evidence_excerpt": "Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States.",
      "evidence_locator": "DOJ Press Release 24-118",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Takedown of KV Botnet",
      "source_url": "https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical",
      "technique_name": "Compromise Infrastructure",
      "tactic": "Resource Development"
    },
    {
      "technique_id": "T1059.003",
      "evidence_excerpt": "Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware.",
      "evidence_locator": "Advisory Technical Appendix",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Joint Guidance",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Windows Command Shell",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1016",
      "evidence_excerpt": "Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 18",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "System Network Configuration Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1018",
      "evidence_excerpt": "Adversaries executed ping sweeps and 'net group \"Domain Computers\" /domain' to identify neighboring workstation hostnames.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 22",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Remote System Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1033",
      "evidence_excerpt": "The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope.",
      "evidence_locator": "CISA Technical Appendix",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "System Owner/User Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1057",
      "evidence_excerpt": "Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 19",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Process Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1570",
      "evidence_excerpt": "Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 25",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Lateral Tool Transfer",
      "tactic": "Lateral Movement"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2023-05-24",
      "description": "CISA, NSA, FBI, and Five Eyes agencies issue first joint advisory on Volt Typhoon intrusion campaigns."
    },
    {
      "event_type": "court_order",
      "event_date": "2023-12-14",
      "description": "Federal court in the Southern District of Texas authorizes FBI operation to delete KV botnet malware from compromised routers."
    },
    {
      "event_type": "disclosure",
      "event_date": "2024-01-31",
      "description": "FBI Director Wray testifies before Congress on PRC cyber actor pre-positioning against American civilian infrastructure."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Exploitation of zero-day vulnerabilities in edge networking appliances (Fortinet, Ivanti, Cisco, NETGEAR routers) combined with the KV-botnet of compromised small-office/home-office (SOHO) routers used as obfuscation proxies.",
    "blast_radius": "Pre-positioned inside critical infrastructure facilities across the United States and Guam, including drinking water treatment plants, telecommunications switching hubs, electric utility grids, and maritime port facilities. The objective was not financial extortion or immediate espionage, but dormant pre-positioning for disruptive sabotage during a potential geopolitical crisis.",
    "kill_chain": [
      {
        "phase": "Perimeter Compromise",
        "title": "Edge Appliance Infiltration & KV-Botnet Proxying",
        "description": "Operatives exploited unpatched edge network appliances and routers to establish a multi-tier proxy mesh (KV-botnet), routing malicious traffic through residential IP addresses to bypass geolocation blocks.",
        "technical_artifacts": [
          "KV-botnet",
          "Compromised SOHO routers",
          "Fortinet / Ivanti exploits"
        ],
        "mitre_technique_id": "T1190"
      },
      {
        "phase": "Credential Access",
        "title": "Silent Valid Account Harvesting",
        "description": "Volt Typhoon acquired valid administrative user accounts without deploying malware, extracting passwords through local memory and registry inspection.",
        "technical_artifacts": [
          "Legitimate domain credentials",
          "Single sign-on tokens"
        ],
        "mitre_technique_id": "T1078"
      },
      {
        "phase": "Living-off-the-Land",
        "title": "Built-in System Administration Tool Abuse",
        "description": "The actors exclusively utilized native operating system utilities (cmd.exe, powershell.exe, wmic, net.exe) to execute reconnaissance and admin tasks, leaving virtually zero custom malware signatures on disk.",
        "technical_artifacts": [
          "wmic.exe",
          "net.exe",
          "powershell.exe",
          "Living-off-the-Land (LotL)"
        ],
        "mitre_technique_id": "T1059.001"
      },
      {
        "phase": "Discovery & Active Directory Theft",
        "title": "NTDS.dit Shadow Copy Extraction",
        "description": "Operators created volume shadow copies on domain controllers to extract the Active Directory database (ntds.dit) and SYSTEM registry hives, enabling offline password cracking.",
        "technical_artifacts": [
          "vssadmin create shadow /for=C:",
          "ntds.dit copy",
          "SYSTEM hive export"
        ],
        "mitre_technique_id": "T1003"
      },
      {
        "phase": "Dormant Pre-Positioning",
        "title": "Strategic Operational Technology Preparation",
        "description": "Operatives established footholds within municipal water, aviation, and power distribution systems, lying dormant for years to maintain persistent leverage for disruptive cyber sabotage during geopolitical conflict.",
        "technical_artifacts": [
          "Persistent network tunnels",
          "Unmonitored router configurations"
        ],
        "mitre_technique_id": "T1082"
      }
    ],
    "defensive_takeaways": [
      "Decommission end-of-life edge devices and immediately disable remote WAN administration on all network appliances.",
      "Audit and detect Living-off-the-Land commands (wmic, net, vssadmin) executed by non-administrative accounts.",
      "Enforce strict behavioral alerting on volume shadow copy creation commands targeting domain controllers.",
      "Physically isolate and air-gap operational technology (OT) control networks from enterprise IT environments."
    ]
  }
}