Cyber Threat Report: 'PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure'

Report Author CISA
Publication Date 2024-02-07
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets Volt Typhoon
Identified CVEs CVE-2022-42475
Victim Sectors Telecommunications, Transportation, Utilities, Water, Energy

Following an initial advisory issued in May 2023, this advisory from CISA, NSA and partners outlines information on the broader campaign of cyber attacks carried out by Volt Typhoon against critical infrastructure organizations in the US and it's territories, including Guam. The report describes the tactics, techniques and procedures (TTPs) used by Volt Typhoon, including the use of extensive pre-compromise reconnaissance, initial access through exploitation of vulnerabilities in public-facing network appliances and living-off-the-land techniques.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques