Volt Typhoon hackers were in Massachusetts utility’s systems for 10 months
ID: 6a0f0664-dad2-5c7d-8678-161cc3618eec
STIX ID: report--6a0f0664-dad2-5c7d-8678-161cc3618eec
Feed Name: The Record from Recorded Future News
Dragos, working with the Littleton (MA) utility, found that China-linked APT 'Volt Typhoon' maintained persistent access to the utility’s IT environment from February 2023 through late 2023, performing lateral movement and exfiltrating OT-related information (network diagrams, operating procedures, spatial layout data). U.S. agencies characterize this as part of a wider campaign to pre-position access in critical infrastructure for potential disruptive or destructive attacks; Dragos and partners recommend patching internet-facing VPN/firewall appliances, monitoring for unusual lateral movement, and validating suspicious user activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
