logo

PRC State-Sponsored Threat Actors (Volt Typhoon) Target Critical Infrastructure Entities

ID: 3913bd29-6cb6-5ba8-8f24-177bfcae9529

STIX ID: report--3913bd29-6cb6-5ba8-8f24-177bfcae9529

Feed Name: Arctic Wolf

Threat Score
85/100

Date Published: 2024-02-09

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

This advisory summarizes CISA and Arctic Wolf analysis of Volt Typhoon, a PRC‑linked APT actively intruding into U.S. critical infrastructure IT environments (communications, energy, transportation, water), using vulnerability exploits, credential theft, lateral movement and Active Directory compromise to pursue footholds and access OT assets; the bulletin documents observed TTPs, high‑risk targeted product classes (Fortinet, Ivanti, NETGEAR, Citrix, Cisco), and prescribes patching, phishing‑resistant MFA, and security awareness as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.