Saturday, February 22, 2025
HomeCVE/vulnerabilityVolt Typhoon Attacking U.S. Critical Infra To Maintain Persistent Access

Volt Typhoon Attacking U.S. Critical Infra To Maintain Persistent Access

Published on

SIEM as a Service

Follow Us on Google News

Volt Typhoon, a Chinese state-sponsored threat actor, targets critical infrastructure sectors like communications, energy, transportation, and water systems by pre-positions itself in target networks, often exploiting vulnerabilities in operational technology (OT) environments. 

Known for persistence and patient operations, Volt Typhoon has been tracked under various aliases, including BRONZE SILHOUETTE, Voltzite, Insidious Taurus, DEV-0391, UNC3236, and Vanguard Panda.  

It is a sophisticated threat actor that leverages LOTL techniques and manual attacks to establish long-lasting persistence within target systems by exploiting unpatched vulnerabilities, including zero days, to gain initial access.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar

Volt Typhoon Attacking U.S. Critical Infrastructure

To obfuscate their activities, they proxy their traffic through compromised SOHO routers, making it appear legitimate and evading detection by geolocation-based security measures, which enables them to conduct stealthy reconnaissance and maintain a persistent presence in compromised networks.

Volt Typhoon attack diagram

It leverages vulnerabilities in exposed firewalls, VPNs, and web servers, as well as weak credentials and unpatched devices, by exploiting compromised SOHO devices like ASUS, Cisco, Draytek, FatPipe, Fortinet, Netgear, and Zyxel to proxy traffic and launch attacks. 

These devices, often unpatched, misconfigured, or end-of-life, provide easy entry points due to known vulnerabilities and default credentials. Once compromised, they are infected with the KV Botnet malware. 

By using native Windows tools, it minimizes its digital footprint, and by employing techniques like credential dumping with Mimikatz and lateral movement through RDP, the group evades traditional security measures. 

It establishes persistence through Task Scheduler and exfiltrates sensitive data by focusing on shadow copying AD databases and its use of legitimate tools makes it a challenging adversary to detect and mitigate.

Volt Typhoon has exploited multiple critical vulnerabilities in various software solutions, including VPNs, to gain unauthorized access to networks, such as those found in Fortinet FortiOS, Zoho ManageEngine ADSelfService Plus, and Versa Director, which have been actively exploited by the group. 

By leveraging these vulnerabilities, Volt Typhoon can bypass security measures and establish a persistent presence within targeted networks, which highlights the importance of timely patching and robust security practices to mitigate risks associated with these vulnerabilities.

Multiple vulnerabilities exploited by Volt Typhoon have varying levels of public proof-of-concept (PoC) availability. While no public PoC exists for CVE-2021-27860, a partial PoC for CVE-2021-40539 is available on GitHub. 

Public PoCs for Fortinet vulnerabilities (CVE-2022-42475 and CVE-2023-27997) are widely shared, demonstrating remote code execution, as no public PoC is currently available for the newly disclosed Versa Director vulnerability (CVE-2024-39717). 

According to Tenable, it is essential to apply patches in a timely manner and to keep an eye out for potential exploits, as the availability of these proofs of concept varies.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies.

Latest articles

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

ACRStealer Malware Abuses Google Docs as C2 to Steal Login Credentials

The ACRStealer malware, an infostealer disguised as illegal software such as cracks and keygens,...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...