Volt Typhoon in Place to Deny US Infrastructure
An April 18, 2024, Reuters article by Christopher Bing reports on an address given at Vanderbilt University by FBI Director Christopher Wray. Wray disclosed information from Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and FBI that hackers linked to the People’s republic of China (PRC) government have established access to US companies in a campaign called “Volt Typhoon”. The goal is to produce chaos and panic in the US at a time of their choosing by interfering with telecommunications, energy, water and other critical sectors. The article says that as many as 23 US pipeline companies have been targeted.
The People’s Republic of China (PRC) is well known to engage in various levels of shady cyberwarfare on the rest of the world either directly or with other players. Hybrid warfare is a conflict that considers propaganda, misinformation and cyber-attacks as part of the spectrum of total war. In this case, cyber spying and disruption are part of it. Their cyberwarfare activity is not only about theft of intellectual property, spying or causing immediate damage. They are also engaged in placing sleeper code with the target for activation at their leisure. One particularly insidious action is referred to as “Living Off the Land“.
Living off the land is a technique that evades detection by using intermediate infrastructure to shield hostile activity such as command and control activity from local ISP’s.
The actor has executed the following command to gather information about local drives [T1082]: cmd.exe /C “wmic path win32_logicaldisk get caption,filesystem,freespace,size,volumename” This command does not require administrative credentials to return results. The command uses a command prompt [T1059.003] to execute a Windows Management Instrumentation Command Line (WMIC) query, collecting information about the storage devices on the local host, including drive letter, file system (e.g., new technology file system [NTFS]), free space and drive size in bytes, and an optional volume name. Windows Management Instrumentation (WMI) is a built-in Windows tool that allows a user to access management information from hosts in an enterprise environment. The command line version of WMI is called WMIC. Source: CISA, People’s Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
The breadth of Volt Typhoon is much greater than mentioned here. For further information please consult the CISA source.
One particular time of their choosing is likely to be as the PRC prepares to invade Taiwan. Sowing chaos and the denial of resources for the US could alter the outcome of an invasion of Taiwan in PRC’s favor. Taiwan (Formosa) is the part of China that did not fall to the communist takeover under Mao Zedong.