Cyber Threat Report: 'People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection'

Report Author CISA
Publication Date 2023-05-24
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets Volt Typhoon
Identified CVEs CVE-2021-40539 , CVE-2021-27860

This advisory from the US National Security Agency, CISA and various other agencies outlines tactics, techniques and procedures used by Volt Typhoon in attacking US critical infrastructure sectors. In particular, the report calls out the actor's use of living-off-the-land techniques to avoid detection.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1090.002 External Proxy Command and Control
T1090 Proxy Command and Control
T1016 System Network Configuration Discovery Discovery
T1069.002 Domain Groups Discovery
T1069.001 Local Groups Discovery
T1033 System Owner/User Discovery Discovery
T1082 System Information Discovery Discovery
T1555 Credentials from Password Stores Credential Access
T1003 OS Credential Dumping Credential Access
T1110.003 Password Spraying Credential Access
T1110 Brute Force Credential Access
T1003.003 NTDS Credential Access
T1070.001 Clear Windows Event Logs Defense Evasion
T1070 Indicator Removal Defense Evasion
T1505.003 Web Shell Persistence
T1059.003 Windows Command Shell Execution
T1059.001 PowerShell Execution
T1047 Windows Management Instrumentation Execution
T1190 Exploit Public-Facing Application Initial Access