operational Critical Infrastructurecritical

Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure

Wed, Feb 7, 2024, 02:00 PM UTC·Feb 7, 2024· Critical Infra: Water (CI-WATER)

Summary

Bottom line: authoring agencies assessed that Chinese state actors are pre-positioned on communications, energy, transportation and water networks to enable disruption, not espionage. Hunt for living-off-the-land activity on edge appliances rather than waiting on malware signatures.

Key claims· extracted from reporting

  • Bottom line: authoring agencies assessed that Chinese state actors are pre-positioned on communications, energy, transportation and water networks to enable disruption, not espionage.Low · 10%
    named entity×2
  • Hunt for living-off-the-land activity on edge appliances rather than waiting on malware signatures.Low · 10%
    named entity

Heuristic extraction, verify against the original report before citing.

Tags· click to alert

Key takeaways

The three things worth remembering from this item.

  1. 1Bottom line: Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure[1]
  2. 2Volt Typhoon activity is the driver here, and the objective is what should shape your response, not the tool names.[1][2][3]
  3. 3Defensively, the highest-leverage move is coverage for T1190 · Exploit Public-Facing Application, because it is a behavior class rather than an indicator.[1][2]

Concepts in this story

Each concept opens in layers: plain English, technical, then expert.

Volt Typhoon

China · Very high tempo

Volt Typhoon is a China linked hacking group. In plain terms, they break into us critical infrastructure, guam telecom, water utilities and stay there. Their goal is to pre-position for disruption of us critical infrastructure in a taiwan contingency.

Why it matters
Beijing-nexus operations are the pacing threat in US cyber policy: the concern is pre-positioning inside critical infrastructure for use during a crisis, not day-to-day theft.[1][2][3]
Common misconception
That every Chinese intrusion is intellectual property theft. Pre-positioning groups deliberately steal nothing, which is exactly why they go unnoticed.
MITRE ATT&CK G1017 Cyber Kill ChainNIST CSF 2.0, Identify, Detect, Respond
Sources for this concept
  1. [1]Volt Typhoon group profile· MITRE ATT&CK G1017
  2. [2]CISA: Volt Typhoon pre-positioned in US critical infrastructure for 5+ years· Public incident reporting· 2024-02-07 00:00Z
  3. [3]Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure· CISA / NSA / FBI advisory AA24-038A· 2024-02-07 14:00Z

T1190 · Exploit Public-Facing Application

Initial Access · used by 13 tracked groups

Exploit Public-Facing Application is how an attacker initial access works in practice. Edge devices and VPN appliances (Ivanti, Fortinet, Citrix, Cisco) exploited within hours of CVE disclosure.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1190 Tactic: Initial Access
Sources for this concept
  1. [1]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190
  2. [2]Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure· CISA / NSA / FBI advisory AA24-038A· 2024-02-07 14:00Z

T1505.003 · Server Software Component: Web Shell

Persistence · used by 5 tracked groups

Server Software Component: Web Shell is how an attacker persistence works in practice. Web shells planted on perimeter devices and Exchange servers for durable re-entry.

Why it matters
This is a persistence behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1505.003 Tactic: Persistence
Sources for this concept
  1. [1]T1505.003 · Server Software Component: Web Shell· MITRE ATT&CK T1505.003
  2. [2]Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure· CISA / NSA / FBI advisory AA24-038A· 2024-02-07 14:00Z

T1078 · Valid Accounts

Initial Access · used by 18 tracked groups

Valid Accounts is how an attacker initial access works in practice. Stolen or sprayed credentials used in place of malware, defeating signature-based detection.

Why it matters
This is a initial access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1078 Tactic: Initial Access
Sources for this concept
  1. [1]T1078 · Valid Accounts· MITRE ATT&CK T1078
  2. [2]Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure· CISA / NSA / FBI advisory AA24-038A· 2024-02-07 14:00Z

T1003.001 · OS Credential Dumping: LSASS Memory

Credential Access · used by 3 tracked groups

OS Credential Dumping: LSASS Memory is how an attacker credential access works in practice. LSASS and NTDS.dit theft to escalate from a single host to domain-wide access.

Why it matters
This is a credential access behavior, so blocking it early removes an entire branch of the intrusion rather than one tool.[1][2]
Common misconception
That a technique ID is a detection. ATT&CK describes behavior; coverage still has to be built and tested per environment.
MITRE ATT&CK T1003.001 Tactic: Credential Access
Sources for this concept
  1. [1]T1003.001 · OS Credential Dumping: LSASS Memory· MITRE ATT&CK T1003.001
  2. [2]Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure· CISA / NSA / FBI advisory AA24-038A· 2024-02-07 14:00Z
Sources for these takeaways
  1. [1]Advisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure· CISA / NSA / FBI advisory AA24-038A· 2024-02-07 14:00Z
  2. [2]Volt Typhoon group profile· MITRE ATT&CK G1017
  3. [3]CISA: Volt Typhoon pre-positioned in US critical infrastructure for 5+ years· Public incident reporting· 2024-02-07 00:00Z
  4. [4]T1190 · Exploit Public-Facing Application· MITRE ATT&CK T1190

Knowledge check

Five questions. Answers explain the reasoning, not just the result.

Question 1 of 5

Which nexus is Volt Typhoon attributed to in public reporting?

Question 2 of 5

Which sector is a primary target for Volt Typhoon?

Question 3 of 5

Which ATT&CK tactic does T1190 (Exploit Public-Facing Application) belong to?

Question 4 of 5

Which ATT&CK tactic does T1505.003 (Server Software Component: Web Shell) belong to?

Question 5 of 5

Which ATT&CK tactic does T1078 (Valid Accounts) belong to?

Answer all 5 to check.
Estimated mastery
First time on this material.
New · 0/100