What is Volt Typhoon? FBI warns of 'threat' from Chinese state-backed hacking network

FBI director Christopher Wray recently released a warning about a state-sponsored group of hackers known as Volt Typhoon.

Addressing a US committee, Wray warned that Volt Typhoon was “the defining threat of our generation”, as it aimed to disrupt the US military’s “ability to mobilize”.

Official reports have suggested that the China-backed hacking group has been able to gain access to crucial infrastructure through vulnerable IT networks.

However, instead of stealing information, Volt Typhoon have allegedly “pre-positioned” itself in order to carry out future interference.

Here’s everything we know about Volt Typhoon and the threat it poses.

What is Volt Typhoon?

Volt Typhoon has been identified as a Chinese-backed collective of hackers that have been in operation since around 2021.

It’s an example of one of the many groups of hackers that countries rely on to gather intelligence around the world.

Volt Typhoon appears to work by gaining control of digital devices that have vulnerable security systems, such as modems and routers. The goal, it seems, is to embed in such devices to gain access to more sensitive data and systems.

According to a Microsoft blog released in May 2023, the platform had noticed “malicious” activity linked to the organisation, which suggested “that the threat actor intends to perform espionage and maintain access without being detected for as long as possible”.

microsoft, what is volt typhoon? fbi warns of 'threat' from chinese state-backed hacking network

Christopher Wray recently addressed the threat of Volt Tycoon (Mandel Ngan / AFP via Getty Images)

What has it affected?

As groups such as Volt Typhoon are so secretive, it’s difficult to say exactly what has been affected by the hackers.

Microsoft’s investigation claimed that infrastructure in the US territory Guam and throughout mainland United States may have been affected, in industries such as “communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors”.

The group could potentially have the ability to disrupt heating, energy and water supplies with the intent of damaging infrastructure.

The assessment appeared to suggest that Volt Typhoon had the potential to affect “critical communications infrastructure between the United States and Asia region”.

This is particularly important because of the current political tensions between China and the US over Taiwan.

The Philippines and the Netherlands have also recently identified incidents linked to Chinese-backed hackers.

US authorities have claimed that some of these stealth digital networks may have been embedded in devices for “at least five years”.

Where did it originate?

A number of countries around the world are believed to work with state-sponsored hackers to gather intelligence and infiltrate foreign systems.

In 2023, the US National Security Agency released an advisory paper bringing awareness to the operations of Volt Typhoon.

In the report, the NSA described the group as a “People’s Republic of China (PRC) state-sponsored cyberactor, also known as Volt Typhoon”.

US Cybersecurity and Infrastructure Agency (CISA) Director Jen Easterly recently told lawmakers what a hypothetical cyberattack by China would look like: “Telecommunications going down — People start getting sick from polluted water. Trains get derailed. This is truly an everything, everywhere, all at once scenario,” said Director Easterly.

What is a ‘living-off-the-land’ attack?

Investigations have identified that Volt Typhoon has adopted a ‘living-off-the-land (LotL)’ strategy for its hacking techniques.

The threat actor puts strong emphasis on stealth in this campaign, relying almost exclusively on living-off-the-land techniques and hands-on-keyboard activity

Microsoft

‘Living off the land’ is a term used to describe when malicious players access legitimate, built-in networks to carry out their goals. The hackers don’t need to install any extra code in order to carry out their attacks.

One of many nefarious strategies adopted by hackers, it essentially helps the hacker avoid detection by blending into existing systems.

Register now for one of the Evening Standard’s newsletters. From a daily news briefing to Homes & Property insights, plus lifestyle, going out, offers and more. For the best stories in your inbox, click here.

News Related

OTHER NEWS

Jimmy Carter and all living former first ladies to attend Rosalynn Carter’s memorial service

Former President Jimmy Carter is expected to attend the Tuesday memorial service for his late wife, Rosalynn Carter, in Atlanta, his grandson told CNN – a tribute that will also be ... Read more »

Rob Reiner to Film ‘This Is Spinal Tap' Sequel in February, Says Paul McCartney and Elton John Will Appear

Rob Reiner to Film ‘This Is Spinal Tap’ Sequel in February, Says Paul McCartney and Elton John Will Appear Forty years after making his directorial debut with the 1984 cult ... Read more »

Best Buy's Biggest Cyber Monday Deals on Samsung TVs, Sony Headphones, and Dyson Vacuums

Plus laptops and more last-minute deals you don’t want to miss People / Jaclyn Mastropasqua We have reached Cyber Monday is officially here, and there are loads of great deals ... Read more »

The Joffre Lakes surge returns north of Pemberton

The Joffre Lakes surge is back, much to the dismay of Pemberton and Mount Currie locals. Video footage shared with Pique shows a long line of cars illegally parked on ... Read more »

Activists calling for Gaza ceasefire begin hunger strike outside White House

Photograph: Jim Watson/AFP/Getty Images Leftwing activists including the actor Cynthia Nixon, famous for her role in Sex and the City, have begun a hunger strike outside the White House aimed ... Read more »

We just got a first look at McDonald's secretive new spinoff restaurant CosMc's

A construction site in Bolingbrook, Illinois, presumed to be the first location of CosMc’s. Scott Fredrickson McDonald’s has been reluctant to share many details about its planned new restaurant concept ... Read more »

Conor McGregor’s The Black Forge posts more than $2 million in losses since 2021 opening

Conor McGregor’s The Black Forge posts more than $2 million in losses since 2021 opening Conor McGregor made around a $2 million investment when he purchased the Dublin bar he ... Read more »
Top List in the World