07/27/2023
This article was published in May of this year, but it's new to me. Sharing for expanded awareness as it covers many topics beneficial to DFIR and cybersecurity.
👉 Volt Typhoon is categorized as a state-sponsored actor based in China that typically focuses on espionage and information gathering.
👉 Threat actor puts strong emphasis on stealth in this campaign, relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity.
👉 Volt Typhoon has been active since mid-2021 and has targeted critical infrastructure organizations.
👉 National Security Agency (NSA) has also published a Cybersecurity Advisory - hyperlink to PDF is contained in the article.
Chinese state-sponsored actor Volt Typhoon is using stealthy techniques to target US critical infrastructure, conduct espionage, and dwell in compromised environments.