{
  "id": "case-volt-typhoon",
  "slug": "volt-typhoon-critical-infrastructure",
  "title": "Volt Typhoon Critical Infrastructure Pre-Positioning",
  "summary": "State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.",
  "case_number": "CISA-AA24-038A",
  "court": "Federal Law Enforcement Action / FISA Court Authorized Operations",
  "district": "S.D. Tex. & Multiple",
  "country": "United States",
  "opened_at": "2023-05-24",
  "status": "alleged",
  "victim_sector": "Communications, Energy, Transportation, Water, Defense Industrial Base",
  "victim_country": "United States, Guam",
  "loss_amount_usd": 150000000,
  "loss_amount_note": "Multi-million dollar disruption and extensive remediation costs across federal agencies, defense bases, and utilities.",
  "first_seen_at": "2021-06-01T00:00:00Z",
  "last_updated_at": "2026-09-15T14:00:00Z",
  "actor_slug": "volt-typhoon",
  "defendant_slugs": [],
  "cves": [
    "CVE-2023-27997",
    "CVE-2023-46805"
  ],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 3",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    },
    {
      "technique_id": "T1190",
      "evidence_excerpt": "Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 12",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Exploit Public-Facing Application",
      "tactic": "Initial Access"
    },
    {
      "technique_id": "T1584",
      "evidence_excerpt": "Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States.",
      "evidence_locator": "DOJ Press Release 24-118",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "DOJ Takedown of KV Botnet",
      "source_url": "https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical",
      "technique_name": "Compromise Infrastructure",
      "tactic": "Resource Development"
    },
    {
      "technique_id": "T1059.003",
      "evidence_excerpt": "Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware.",
      "evidence_locator": "Advisory Technical Appendix",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Joint Guidance",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Windows Command Shell",
      "tactic": "Execution"
    },
    {
      "technique_id": "T1016",
      "evidence_excerpt": "Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 18",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "System Network Configuration Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1018",
      "evidence_excerpt": "Adversaries executed ping sweeps and 'net group \"Domain Computers\" /domain' to identify neighboring workstation hostnames.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 22",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Remote System Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1033",
      "evidence_excerpt": "The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope.",
      "evidence_locator": "CISA Technical Appendix",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "System Owner/User Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1057",
      "evidence_excerpt": "Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 19",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Process Discovery",
      "tactic": "Discovery"
    },
    {
      "technique_id": "T1570",
      "evidence_excerpt": "Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels.",
      "evidence_locator": "CISA Advisory AA24-038A \u00b6 25",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "CISA Advisory AA24-038A",
      "source_url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a",
      "technique_name": "Lateral Tool Transfer",
      "tactic": "Lateral Movement"
    }
  ],
  "events": [
    {
      "event_type": "advisory",
      "event_date": "2023-05-24",
      "description": "CISA, NSA, FBI, and Five Eyes agencies issue first joint advisory on Volt Typhoon intrusion campaigns."
    },
    {
      "event_type": "court_order",
      "event_date": "2023-12-14",
      "description": "Federal court in the Southern District of Texas authorizes FBI operation to delete KV botnet malware from compromised routers."
    },
    {
      "event_type": "disclosure",
      "event_date": "2024-01-31",
      "description": "FBI Director Wray testifies before Congress on PRC cyber actor pre-positioning against American civilian infrastructure."
    }
  ]
}