Microsoft and cyber security agencies from the US, UK, Canada, Australia, and New Zealand warned that a Chinese state-sponsored group, Volt Typhoon, was targeting critical infrastructure organisations. China denied the allegations.
What happened
- Microsoft said targets included communications, utilities, transport, and other sectors, including in Guam, home to major US military bases.
- The group relied on ‘living off the land’ techniques, using built-in tools rather than malware to avoid detection.
- It routed traffic through compromised small office and home office routers to blend in with normal activity.
- Microsoft assessed that the group could be developing capabilities to disrupt communications between the US and Asia during a future crisis.
Why it mattered
The warning marked a shift in concern from espionage to pre-positioning for possible disruption, and Volt Typhoon became a central theme in Western cyber policy. In February 2024 US agencies said Volt Typhoon had maintained access to some victim networks for at least five years.
Lessons for organisations
Organisations should replace end-of-life network devices, log and monitor use of administrative tools, and look for unusual account activity rather than relying only on malware detection. Joint guidance from the NCSC, CISA, and partners on living-off-the-land techniques gives practical detection advice.
Source: CNBC
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.