CASE DOSSIER
alleged
Volt Typhoon Critical Infrastructure Pre-Positioning
Docket: CISA-AA24-038A Court: Federal Law Enforcement Action / FISA Court Authorized Operations Opened: 2023-05-24 Sector: Communications, Energy, Transportation, Water, Defense Industrial Base
Key Facts
Status
ALLEGED
Legal disposition
Loss Amount
$150.0 million
Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.
Techniques
9
Verified mappings
Defendants
0
Named in charges
- Legal Status: ALLEGED in Federal Law Enforcement Action / FISA Court Authorized Operations.
- Primary Target Sector: Communications, Energy, Transportation, Water, Defense Industrial Base.
- Documented Financial Loss: $150.0 million.
- 9 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:
Case Summary
State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.
Procedural & Incident Timeline
2023-05-24 advisory
CISA, NSA, FBI, and Five Eyes agencies issue first joint advisory on Volt Typhoon intrusion campaigns.
2023-12-14 court_order
Federal court in the Southern District of Texas authorizes FBI operation to delete KV botnet malware from compromised routers.
2024-01-31 disclosure
FBI Director Wray testifies before Congress on PRC cyber actor pre-positioning against American civilian infrastructure.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections." | CISA Advisory AA24-038A ¶ 3 | reviewed |
| T1190 | Exploit Public-Facing Application Initial Access | "Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances." | CISA Advisory AA24-038A ¶ 12 | reviewed |
| T1584 | Compromise Infrastructure Resource Development | "Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States." | DOJ Press Release 24-118 | reviewed |
| T1059.003 | Windows Command Shell Execution | "Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware." | Advisory Technical Appendix | reviewed |
| T1016 | System Network Configuration Discovery Discovery | "Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing." | CISA Advisory AA24-038A ¶ 18 | reviewed |
| T1018 | Remote System Discovery Discovery | "Adversaries executed ping sweeps and 'net group "Domain Computers" /domain' to identify neighboring workstation hostnames." | CISA Advisory AA24-038A ¶ 22 | reviewed |
| T1033 | System Owner/User Discovery Discovery | "The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope." | CISA Technical Appendix | reviewed |
| T1057 | Process Discovery Discovery | "Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers." | CISA Advisory AA24-038A ¶ 19 | reviewed |
| T1570 | Lateral Tool Transfer Lateral Movement | "Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels." | CISA Advisory AA24-038A ¶ 25 | reviewed |
Cite & Embed This Case Record
Public Domain / CC0 Bluebook Legal Citation:
Cyberattack Case Library, Volt Typhoon Critical Infrastructure Pre-Positioning, No. CISA-AA24-038A (Federal Law Enforcement Action / FISA Court Authorized Operations 2023), https://cyberattackcaselibrary.pages.dev/cases/volt-typhoon-critical-infrastructure/
Embeddable Incident Card (HTML):
<iframe src="https://cyberattackcaselibrary.pages.dev/embed/case/volt-typhoon-critical-infrastructure" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>