logo

China's Cyberattackers Maneuver to Disrupt US Critical Infrastructure

ID: f3fbe2c6-b081-5def-bfc3-0d8fdcd1800b

STIX ID: report--f3fbe2c6-b081-5def-bfc3-0d8fdcd1800b

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-02-07

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

CISA warns that the China-backed Volt Typhoon APT has maintained multi-year access to IT environments of US and allied critical infrastructure and is pivoting into OT/ICS networks; the group uses valid accounts and living-off-the-land techniques for stealthy, long-term persistence, posing a credible risk of disruptive physical effects on energy, water, communications, and transportation systems, while recent actions disrupted a SOHO router botnet the group used.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.