logo

Volt Typhoon Strikes Massachusetts Power Utility

ID: 30b272fc-dabd-500c-b887-4ab54eda4130

STIX ID: report--30b272fc-dabd-500c-b887-4ab54eda4130

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-03-12

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Chinese APT Volt Typhoon (Voltzite) conducted a prolonged 2023 intrusion into the Little Electric Light and Water Departments (Massachusetts), maintaining persistence for well over 300 days to exfiltrate operational technology (OT) procedures and spatial layout data; FBI, CISA, and Dragos identified and removed the actor and recommended mitigations. The group leveraged SOHO router botnets and likely exploited Internet-facing VPN/firewall flaws for initial access, then used SMB traversal and RDP lateral movement to navigate the environment. Dragos advises improved asset visibility, patch management, network segmentation, and incident response planning, and warns Voltzite will continue targeting critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.