Volt Typhoon: LOLBins get serious by Joshua St. Hilaire
ID: 6430e074-e46b-5554-9461-e949b6aaf776
STIX ID: report--6430e074-e46b-5554-9461-e949b6aaf776
Feed Name: Vectra AI Blog
This report summarizes Microsoft and JCA findings on Volt Typhoon, a Chinese state-sponsored espionage campaign targeting US critical infrastructure that maintains long-term, stealthy access by abusing compromised SOHO devices as proxies and using stolen credentials and built-in Windows tools (e.g., netsh portproxy, WMIC, ping) rather than deploying obvious malware; it highlights detection challenges and recommends behavioral hunting for unusual logins, rare inbound ports, WMI activity, and other deviations from normal patterns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
