Security Alert: What to Know About Threat Actor Volt Typhoon
On May 24, 2023, Microsoft and Cybersecurity and Infrastructure Security Agency (CISA) warned in a coordinated effort that the Chinese state-sponsored advanced persistent threat (APT) known as Volt Typhoon was targeting United States critical infrastructure.
CISA issued a Cybersecurity Advisory (CSA) from U.S., Canadian, United Kingdom, Australian, and New Zealand intelligence agencies that advised one of Volt Typhoon's primary tactics, techniques, and procedures (TTPs) is living off the land (LOTL), which hinders detection. In a separate post, Microsoft announced it had uncovered "malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the U.S." carried out by Volt Typhoon. Microsoft noted that Volt Typhoon has been active since 2021, primarily targeting critical infrastructure in the U.S. and Guam.
Once Volt Typhoon gains access to a network, the threat actor uses LOTL techniques to harvest credentials and maintain persistent access. As a result, endpoint detection and response (EDR) tools are less effective in mitigating this attack because the threat actor is not installing malicious software or code, but instead maintaining access using valid applications found on installations of Microsoft Windows.