Skip to content
Deep Dive critical OT / ICSCritical InfrastructureCommunicationsTransportGovernment

Volt Typhoon: The Long Game in Western Critical Infrastructure

The February 2024 Five Eyes advisory said something that intelligence professionals had understood for some time but found difficult to express in a form suitable for public release: a Chinese state-sponsored group had spent years embedding itself inside the operational technology networks of American critical infrastructure. Not to steal data. Not to cause disruption. To wait.

That’s the Volt Typhoon story in one sentence. Everything else is context.

Volt Typhoon (also tracked as Bronze Silhouette, Vanguard Panda, and Dev-0391) represents a Chinese strategic doctrine that treats cyber operations as a form of strategic reserve: capability pre-positioned today for conditions that may arise years from now. Understanding what’s actually happening here requires stepping back from the incident-response framing that dominates most cybersecurity discussion and thinking in terms of deterrence theory and great-power competition.

Who Volt Typhoon Is

Western intelligence agencies assess Volt Typhoon as operating under the direction of China’s People’s Liberation Army or State Security apparatus. Specific attribution to a named unit hasn’t been formally published in open source, though the PLA Strategic Support Force’s Network Systems Department and related units have been associated with this activity class. The group has been active since at least 2021, and precursor activity likely goes back further.

What distinguishes Volt Typhoon from most of the APT groups in this publication is not technical sophistication; it’s restraint. The group does not steal intellectual property. It does not conduct ransomware operations. It does not publish embarrassing data to shift political narratives. It gets in, establishes persistence, learns the environment in granular detail, and stays quiet.

Quiet for months. Sometimes years.

Living Off the Land as a Doctrine

The defining technical characteristic is near-exclusive reliance on living-off-the-land techniques: using tools, scripts, and capabilities that already exist in the target environment rather than deploying custom malware.

This is a deliberate defensive posture, not a capability limitation. Custom malware gets detected by endpoint security tools. A WMI command run from a legitimate-looking account, using native Windows tools, generating traffic that blends with normal administration activity: that’s dramatically harder to detect, and the group knows it.

In documented Volt Typhoon intrusions, operators used WMIC for system enumeration, Netsh to manipulate firewall rules and set up port proxies, obfuscated PowerShell scripts with no custom executables, Ntdsutil for Active Directory database manipulation, and credential harvesting techniques against LSASS. All native tools. All legitimate administrative functions that happen to be useful for an adversary who needs to understand what they’re sitting inside.

The consequence for defenders is significant. Standard antivirus and most endpoint detection tools generate almost no signals for this activity. Detection requires behavioural analytics, comprehensive command-line logging, and threat hunters who know specifically what they’re looking for, not passive monitoring waiting for an alert.

Where They Get In

Three categories of entry point recur across documented Volt Typhoon intrusions.

SOHO router compromise. Small office/home office routers (Cisco, NETGEAR, Fortinet) are used as staging infrastructure and traffic relay nodes. Volt Typhoon compromises these devices and routes operational traffic through them, making attribution and detection harder. The devices belong to unsuspecting businesses whose infrastructure is being silently repurposed.

Internet-facing OT systems. Engineering workstations, SCADA interfaces, historian servers, remote access points into operational networks that are internet-facing without adequate protection. These represent direct entry into the environments the group cares most about.

IT/OT boundary exploitation. In most CNI environments, pathways exist between the IT corporate network and the OT operational network: jump servers, historian connections, data diode implementations with management interfaces that turned out to be accessible. Volt Typhoon has demonstrated systematic ability to cross these boundaries once an IT foothold is established. Many organisations believe their IT/OT segmentation is more robust than it actually is when someone is specifically looking for the gaps.

The Targets

Five Eyes advisories have confirmed Volt Typhoon activity across:

Communications. Internet exchange points and telecommunications providers. Access here enables traffic manipulation or intelligence collection at scale, and positioning relevant to any conflict scenario where communications disruption would be a strategic objective.

Energy. Electricity generation and distribution operators, including confirmed intrusions at US power utilities. The ability to cause physical outages is what this access represents.

Water and wastewater. Municipal water systems, typically resource-constrained, operating significant legacy IT/OT infrastructure, and chronically under-resourced for security. Multiple confirmed intrusions.

Transportation. Aviation systems and port operations. Strategic value and potential for physical disruption.

IT and managed services. Managed service providers whose infrastructure provides access to multiple downstream customers simultaneously. Force multiplier targeting.

The pattern is consistent across all of them: organisations that control physical processes on which Western populations depend day-to-day.

What Pre-Positioning Actually Means

The question this campaign raises most directly: pre-positioned for what?

The intelligence community assessment, expressed in the careful language formal advisories require, is that this activity represents seeking to “pre-position itself on IT networks for disruptive or destructive cyberattacks against US critical infrastructure in the event of a major crisis or conflict with the United States.”

In plain terms: China is building the ability to switch off lights, disrupt water supplies, and interfere with transport and communications systems in the event of a confrontation (most plausibly a Taiwan Strait crisis) as part of a deterrence and escalation management strategy. The logic is coherent. If the US military would intervene in a Taiwan conflict, the ability to impose significant domestic disruption on the US mainland creates a deterrent calculation. The cost of intervention (civilian disruption, infrastructure failure, political consequences at home) becomes harder to accept.

This is not unique to China. The US and its allies have developed comparable capabilities. What’s notable about Volt Typhoon is the scale, the patience, and the degree to which it has been documented and publicly disclosed. The disclosure itself is a strategic choice: there are things in the classified versions of those briefings that weren’t put in the advisories.

The Detection Problem

Volt Typhoon’s LOTL approach creates a detection challenge that goes deeper than the technical difficulty of identifying anomalous commands.

If an adversary uses only native tools, generates logs that look like legitimate administration, and triggers no standard detection rules, you might not know it’s there. The absence of an alert is not evidence of the absence of compromise. In environments with incomplete logging and no threat hunting programme, a patient LOTL operator can maintain persistent access indefinitely.

This is particularly acute in OT environments. Logging is often minimal. Behavioural baselines have frequently never been established. Many OT environments don’t have the telemetry infrastructure that would be needed to detect this class of activity even if you were actively looking. That’s not a technical problem alone; it’s a resources and investment problem that predates Volt Typhoon and will outlast any particular advisory.

What CNI Operators Need to Do

The February 2024 advisory contains detailed technical guidance. For leaders, the strategic priorities:

OT logging is a prerequisite, not an option. If your OT environment cannot generate logs that let you reconstruct system activity retrospectively, you cannot detect this threat class. Everything else depends on this. It is not sexy work and it is frequently underfunded.

Threat hunting, not just monitoring. Passive monitoring with automated alerting will not catch LOTL activity conducted by a patient, skilled operator. Scheduled threat hunting exercises using the IOCs and behavioural indicators from Five Eyes advisories are necessary. The question isn’t whether alerts fired; it’s whether someone looked and found nothing, or looked and didn’t look hard enough.

Independently validate your IT/OT segmentation. Commission an external technical assessment of every pathway between IT and OT environments. Don’t accept self-assessment from the teams responsible for those pathways, as they have an obvious incentive to underreport gaps, even unconsciously.

SOHO router hygiene. Any consumer-grade router in your infrastructure (at remote sites, operational buildings, out-of-band management) is in scope for your security programme. That includes equipment that has been there for years and nobody has reviewed.

Engage your sector regulator and NCSC. The confidential briefing content available through sector engagement programmes contains material that cannot appear in public advisories. If you haven’t requested it, that’s the first call to make.

The Volt Typhoon campaign doesn’t have a resolution. Access that’s been discovered has been partially remediated. Access that hasn’t been discovered remains. New access is likely being established right now. The appropriate response is not a one-time remediation project; it’s a permanent elevation of OT security posture and a sustained commitment to threat hunting that most organisations haven’t yet made.

For boards and executives who have treated OT security as a second-order concern: the window for getting ahead of this is narrowing. The adversary has been patient, operating on a timeline measured in years rather than quarters. Most organisations haven’t been patient about anything.