Chinese hackers have been in US infrastructure for at least five years

Share post:

China-backed hacking group Volt Typhoon has been identified as having “persistent” access to various sectors of U.S. critical infrastructure for “at least five years,” marking a concerning escalation in cyber threats. Targeting essential services such as water, transportation, energy, and communications, the hackers have exploited vulnerabilities in routers, firewalls, and VPNs. Utilizing stolen administrator credentials, Volt Typhoon’s operations pose a significant risk of disruption to critical systems.

The U.S. Cybersecurity and Infrastructure Security Agency, along with the National Security Agency and the Federal Bureau of Investigation, issued an advisory highlighting the need for critical infrastructure operators to fortify their cybersecurity measures. Volt Typhoon’s tactics include “living off the land” techniques, which complicate detection efforts by using the network’s own tools and processes against it.

This advisory comes amid growing concerns that China might leverage such cyber intrusions in strategies related to geopolitical tensions, notably the situation with Taiwan. Collaborative efforts from intelligence agencies in Canada, Australia, and New Zealand have also been noted, indicating a broader concern for global critical infrastructure security.

U.S. officials are urging operators to implement security best practices, such as applying software updates, enabling multi-factor authentication, and maintaining activity logs to monitor suspicious behavior. This situation underscores the vulnerabilities in U.S. critical infrastructure and the imperative for comprehensive cybersecurity defenses.

Sources include: Axios

 

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways