China's Volt Typhoon spies broke into emergency network of 'large' US city
ID: 5d0c920e-5c60-5a7a-8a18-3181e716ba9b
STIX ID: report--5d0c920e-5c60-5a7a-8a18-3181e716ba9b
Feed Name: The Register (Security)
Dragos reports that Volt Typhoon (aka Voltize), a China-linked espionage group, has been conducting sustained intrusions and reconnaissance since early 2023 against U.S. and international critical infrastructure — targeting electric transmission/distribution, telecommunications, and emergency management services. The group has exploited routers and VPN gateways (including Ivanti zero-days), compromised appliances and monitoring tools (Fortinet, PRTG, ManageEngine, Cisco ASA), used stolen credentials and legitimate admin tools to move laterally, maintained long dwell times (300+ days in one case), and exfiltrated GIS data that could enable disruptive future attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
