Chinese hacking group ‘Volt Typhoon’ spying on US critical infrastructure, says Microsoft
June 4, 2026
  • Read Ecopy
  • Circulation
  • Advertise
  • Careers
  • About Us
  • Contact Us
Android AppiPhone AppArattai
Organiser
  • ‌
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Europe
    • North America
    • South America
    • Africa
    • Australia
  • Editorial
  • International
  • Opinion
  • RSS @ 100
  • More
    • Op Sindoor
    • Analysis
    • Sports
    • Defence
    • Politics
    • Business
    • Economy
    • Culture
    • Special Report
    • Sci & Tech
    • Entertainment
    • G20
    • Azadi Ka Amrit Mahotsav
    • Vocal4Local
    • Web Stories
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Law
    • Health
    • Obituary
  • Subscribe
    • Subscribe Print Edition
    • Subscribe Ecopy
    • Read Ecopy
  • ‌
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Europe
    • North America
    • South America
    • Africa
    • Australia
  • Editorial
  • International
  • Opinion
  • RSS @ 100
  • More
    • Op Sindoor
    • Analysis
    • Sports
    • Defence
    • Politics
    • Business
    • Economy
    • Culture
    • Special Report
    • Sci & Tech
    • Entertainment
    • G20
    • Azadi Ka Amrit Mahotsav
    • Vocal4Local
    • Web Stories
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Law
    • Health
    • Obituary
  • Subscribe
    • Subscribe Print Edition
    • Subscribe Ecopy
    • Read Ecopy
Organiser
  • Home
  • Bharat
  • World
  • Operation Sindoor
  • Editorial
  • Analysis
  • Opinion
  • Culture
  • Defence
  • International Edition
  • RSS @ 100
  • Magazine
  • Read Ecopy
Home International Edition America USA

Chinese hacking group ‘Volt Typhoon’ spying on US critical infrastructure, says Microsoft

The US National Security Agency (NSA) released a Cybersecurity Advisory (CSA) titled "People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection".

WEBDESKWEBDESK
May 25, 2023, 06:00 pm IST
in USA, World, China, Technology
Follow on Google News
(Photo Courtesy: Microsoft & News18)

(Photo Courtesy: Microsoft & News18)

FacebookTwitterWhatsAppTelegramEmail

On May 24, Microsoft released a blog report on its website that they have “…uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organisations in the United States”. They alleged that a Chinese state-sponsored group, “Volt Typhoon”, was behind this attack, and it focused on “espionage” and “information gathering”.

According to Microsoft, the hacking group Volt Typhoon is developing “…capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises”.

Microsoft claimed that this group infects their target’s existing computers to uncover information and retrieve data instead of utilising conventional hacking approaches, which often entail duping a victim into downloading malicious files.

The tech-giant has been tracking this hacking group for quite some time. This group has been active since mid-2021 and “…targeted critical infrastructure organisations in Guam and elsewhere in the United States”. These affected organisations belonged to various different sectors such as communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education. Though it is unclear how many organisations were impacted.

Microsoft said in its report that “mitigating this attack could be challenging”. The US National Security Agency (NSA) released a Cybersecurity Advisory (CSA) titled “People’s Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection” on May 24. The agency stated that they’re trying to identify breaches by working with their partners, including Canada, New Zealand, Australia, and the United Kingdom.

The agencies of these partner countries involved in “hunting” and “detecting” this attack are as follows:

• US Cybersecurity and Infrastructure Security Agency (CISA)
• US Federal Bureau of Investigation (FBI)
• Australian Cyber Security Centre (ACSC)
• Canadian Centre for Cyber Security (CCCS)
• New Zealand National Cyber Security Centre (NCSC-NZ)
• United Kingdom National Cyber Security Centre (NCSC-UK)

Despite the fact that Chinese hackers are known to spy on Western nations, this is one of the largest documented cyber espionage missions targeting American critical infrastructure, as per the reports. CISA Director Jen Easterly said, “For years, China has conducted operations worldwide to steal intellectual property and sensitive data from critical infrastructure organisations around the globe”.

In a statement NSA Cybersecurity Director Rob Joyce said, “A PRC (People’s Republic of China) state-sponsored actor is living off the land, using built-in network tools to evade our defenses and leaving no trace behind”.

The FBI’s Cyber Division Assistant Director Bryan Vorndran stated it would continue “…to warn against China engaging in malicious activity with the intent to target critical infrastructure organisations and use identified techniques to mask their detection”. He added, “We, along with our federal and international partners, will not allow the PRC (People’s Republic of China) to continue to use these unacceptable tactics”.
The NCSC Director of Operations, Paul Chichester, urged UK essential service providers to take action against attackers and follow their guidance “… to help detect this malicious activity and prevent persistent compromise”.

The Head of the Canadian Centre for Cyber Security, Sami Khoury, highlights the importance of working together against this threat, “The interconnected nature of our infrastructures and economies highlights the importance of working together with our allies to identify and share real-time threat information”.

The CSA also mentioned that “their (Volt Typhoon) primary tactics, techniques, and procedures (TTP) of living off the land, the PRC actor uses tools already installed or built into a target’s system. This allows the actor to evade detection by blending in with normal Windows systems and network activities, avoiding endpoint detection and response (EDR) products, and limiting the amount of activity that is captured in default logging configurations”.

The NSA advises network defenders to use the CSA’s detection and hunting guidance, “…such as logging and monitoring of command line execution and WMI events, as well as ensuring log integrity by using a hardened centralised logging server, preferably on a segmented network”.

Topics: USCybersecurity AdvisoryUKBryan VorndranAustraliaNational Cyber Security CentreRob JoyceChinaCSAJen EasterlyFederal Bureau of InvestigationCybersecurity and Infrastructure Security AgencyFBICISACanadaAustralian Cyber Security CentreNew ZealandACSCNSACanadian Centre for Cyber SecurityUnited StatesCCCSVolt Typhoon
Share1TweetSendShareSend
✮ Subscribe Organiser YouTube Channel. ✮
✮ Join Organiser's WhatsApp channel for Nationalist views beyond the news. ✮
Previous News

New Parliament building: BSP supremo Mayawati backs Union Govt; calls Opposition’s boycott ‘unfair’

Next News

Principles of Science came from Vedas, but repackaged as western knowledge, says ISRO Head S Somnath

Related News

Bangladesh’s reported JF-17 push has triggered fresh scrutiny after India’s Ops Sindoor exposed the vulnerabilities of Pakistani-Chinese defence systems and precision strike capabilities

Shadows of Operation Sindoor: Questions loom over Bangladesh’s JF-17 ambitions amid Sino-Pakistani tech vulnerabilities

As Beijing tightens its grip ahead of June 4, dissidents inside China face surveillance and intimidation while activists abroad keep alive the memory of the 1989 Tiananmen crackdown

Tiananmen at 37: How China suppresses remembrance of the massacre through fear, censorship and surveillance

Tiananmen Square Massacre: When Tanks Met Students—The Night China Crushed Its Democratic Hope!

Tiananmen Square Massacre: When Tanks Met Students—The Night Communist China Crushed Its Democratic Hope!

European Commission President Ursula von der Leyen, Chinese President Xi Jinping and US President Donald Trump

Trade Barriers, AI Battles and Military Containment: The European-US strategic front against China takes shape

Australian Deputy Prime Minister and Defence Minister Richard Marles and Defence Minister Rajnath Singh

India-Australia Defence Ministers’ Dialogue: Bilateral synergy on defence research, co-production and maritime security

Australia Defence Minister Richard Marles and Defence Minister Rajnath Singh(File Photo)

India-Australia Defence Dialogue: Co-production, interoperability & catalysing Indo-Pacific security on the agenda

Load More

Latest News

Board outside the office of Karnataka Lokayukta

Karnataka government accused of shielding tainted officials as Lokayukta probes remain stalled

Ritabrata Banerjee Claims LoP Post as Revolt Rocks Mamata Banerjee's Party

TMC vs TMC in Bengal: Expelled leader Ritabrata Banerjee stakes claim to LoP post, deepening crisis in Mamata’s party

DRDO, IAF successfully flight-test indigenous RudraM-II air-to-surface missile

DRDO, IAF conduct successful RudraM-II Missile trials under extreme conditions, boosting India’s defence self-reliance

India receive the fourth squadron of the Russian-made S-400 air defence system

India receives fourth S-400 missile squadron from Russia, bolstering air defence

Union Minister Shivraj Singh Chouhan

Union Minister Shivraj Singh Chouhan pushes farmer-first reforms at national kharif campaign 2026 meet

Firhad Hakim Seeks Resignation as Kolkata Mayor Amid Growing Crisis in Mamata Banerjee's TMC

Another Shock for TMC? Mamata Banerjee’s trusted lieutenant Firhad Hakim seeks to quit as Mayor amid crisis

TCS Nashik Case: Former AIMIM MP Imtiaz Jaleel Mentioned in 1,500-Page Chargesheet; Admits Meeting Nida Khan’s Family

TCS Corporate Jihad Case: Imtiaz Jaleel met Nida Khan’s family while she was absconding, says 1,500-page chargesheet

PM Modi to Overtake Nehru as India's Longest-Serving Elected Prime Minister on June 10

PM Modi set to surpass Nehru’s record, become India’s longest-serving elected Prime Minister

A representative image

West Bengal Joins Ayushman Bharat: CM Suvendu Adhikari announces coverage for 1.36 crore families

Representatives of the Hindu Janajagruti Samiti, advocates associated with the case, and the complainant address a press conference in Pune regarding allegations of religious conversion pressure and workplace harassment at Wipro Technologies.

After TCS, another Corporate Jihad: Hindu employee alleges Shahina pressured to convert, HR Zeeshan forced resignation

Load More
  • Privacy
  • Terms
  • Cookie Policy
  • Refund and Cancellation
  • Delivery and Shipping

© Bharat Prakashan (Delhi) Limited.
Tech-enabled by Ananthapuri Technologies

  • Home
  • Search Organiser
  • Bharat
    • Assam
    • Bihar
    • Chhattisgarh
    • Jharkhand
    • Maharashtra
    • View All States
  • World
    • Asia
    • Africa
    • North America
    • South America
    • Europe
    • Australia
  • Editorial
  • Operation Sindoor
  • Opinion
  • Analysis
  • Defence
  • Culture
  • Sports
  • Business
  • RSS @ 100
  • Entertainment
  • More ..
    • Sci & Tech
    • Vocal4Local
    • Special Report
    • Education
    • Employment
    • Books
    • Interviews
    • Travel
    • Health
    • Politics
    • Law
    • Economy
    • Obituary
  • Subscribe Magazine
  • Read Ecopy
  • Advertise
  • Circulation
  • Careers
  • About Us
  • Contact Us
  • Policies & Terms
    • Privacy Policy
    • Cookie Policy
    • Refund and Cancellation
    • Terms of Use

© Bharat Prakashan (Delhi) Limited.
Tech-enabled by Ananthapuri Technologies