What is Volt Typhoon?
Volt Typhoon is a Chinese state-sponsored hacking group that has, since at least 2021, quietly gained access to networks of critical infrastructure, such as energy, water, telecoms and transport, in order to be able to disrupt them in a major conflict. Unlike espionage, the goal is not to steal information but pre-positioning: setting up access for later sabotage. The group uses hardly any malware and works with the victim’s own admin tools (living off the land), which makes detection very difficult. In some networks Volt Typhoon remained undetected for more than five years.
🗓️ How did Volt Typhoon come to light?
| Date | Event |
|---|---|
| May 2023 | Microsoft and the Five Eyes countries disclose the group |
| December 2023 – January 2024 | The FBI dismantles the KV botnet of hijacked routers the group used |
| 7 February 2024 | CISA, NSA, FBI and partners warn of pre-positioning in critical infrastructure in advisory AA24-038A |
| 2024–2025 | New reports of activity at energy and water utilities, including on Guam |
🔧 How does Volt Typhoon operate?
- Initial access via edge devices — vulnerabilities in VPN gateways, firewalls and end-of-life routers from vendors including Cisco and Netgear
- Hiding traffic — through a botnet of hijacked office and home routers, traffic appears to come from legitimate sources
- Credential theft — including copying the Active Directory database (NTDS.dit)
- Living off the land — using standard Windows tools such as PowerShell, WMI, netsh and ntdsutil
- Moving towards OT — reconnaissance of systems that provide access to controllers, such as jump servers and historians
🔄 How does Volt Typhoon differ from earlier OT attacks?
| Stuxnet / TRITON | Volt Typhoon | |
|---|---|---|
| Goal | Direct sabotage of one installation | Pre-positioned access in many organisations |
| Means | Purpose-built ICS malware | Legitimate tools and stolen accounts |
| Visibility | Conspicuous when executed | Invisible for years |
| Detection | Anomalous process behaviour | Only through behavioural analysis and logging |
🎯 How do you defend against Volt Typhoon?
- Keep edge devices current and managed — replace routers and VPNs that no longer receive updates; patch internet-facing systems first
- Centralise and retain logs — including PowerShell, authentication and admin activity, fed into a SIEM
- Threat hunting for unusual use of legitimate tools, such as ntdsutil or unexpected RDP sessions
- MFA and privileged access management for admin accounts
- Separate IT and OT with an IDMZ and monitor all connections between them
- Plan for manual operation of critical processes if systems can no longer be trusted
🧠 What does pre-positioning mean for Europe and the Netherlands?
Volt Typhoon focused mainly on the United States and its bases, such as on Guam. The approach, however, is not tied to one country: the same routers, VPNs and Windows environments are used in European energy, water and port companies. The Dutch NCSC and intelligence service AIVD have warned for years about state actors probing critical infrastructure in order to disrupt it in a conflict.
| Sign of pre-positioning | What you can check |
|---|---|
| Unexplained admin accounts or password resets | Periodic review of accounts and rights |
| Use of admin tools at unusual times or on unusual systems | Logging of PowerShell, WMI and RDP |
| Copies of the Active Directory database | Detection of ntdsutil and volume shadow copies |
| Connections from home and office routers abroad | Analysis of VPN logins by origin |
| Reconnaissance of OT documentation and network diagrams | Access logging on file servers |
The Dutch Cybersecurity Act (the national implementation of NIS2) requires essential and important entities to manage such risks and report incidents.
❓ Frequently asked questions
What is Volt Typhoon?
Volt Typhoon is a Chinese state-sponsored hacking group that quietly gains access to networks of critical infrastructure, such as energy, water, telecoms and transport. The goal is not espionage, but setting up access so that the infrastructure can be disrupted or destroyed in a conflict.
What does living off the land mean?
Living off the land means that an attacker does not use their own malware, but the victim’s standard admin tools, such as PowerShell, WMI and Windows command-line tools. Because administrators use these tools too, the activity hardly stands out and is not detected by antivirus software.
Did Volt Typhoon attack OT systems?
According to advisory AA24-038A from CISA and partners, Volt Typhoon in some cases approached OT environments and probed systems that provide access to controllers. There are no publicly confirmed sabotage actions. The concern is precisely that the group is able to intervene in a conflict.
How long did Volt Typhoon go undetected?
In some networks Volt Typhoon went undetected for more than five years. The group uses legitimate accounts and admin tools, hides traffic through hijacked routers and removes traces from log files. Detection therefore requires extensive logging and actively hunting for anomalous behaviour.
What is the KV botnet?
The KV botnet is a network of hijacked office and home routers, mainly end-of-life Cisco and Netgear models, that Volt Typhoon used to hide attack traffic. The traffic therefore appeared to come from legitimate sources. The FBI dismantled the botnet in late 2023 and early 2024.
📌 In summary
Volt Typhoon is a Chinese state group that uses legitimate admin tools to embed itself undetected in critical infrastructure for years, so it can disrupt it in a conflict. Defence does not depend on antivirus, but on well-managed edge devices, extensive logging and actively hunting for anomalous behaviour.
