PRC State-Sponsored Attack Advisory

Advisory Details

  • Issue Date:

    February 15, 2024

  • Importance

    Very High

  • Summary

    PRC State-Sponsored Attack Advisory

  • Systems Impacted

    All OT/ICS Environments

On February 7th 2024, CISA released an advisory outlining developments regarding the State-Sponsored cyber threat actor “Volt-Typhoon” linked to the People’s Republic of China (PRC). This group is executing initiatives to infiltrate both IT and OT/ICS Networks in United States critical infrastructure. After infiltrating these networks the potential is to launch a barrage of cyber attacks in the event of conflict with the United States, and have compromised critical infrastructure networks and credentials on standby. Volt Typhoon has been observed moving laterally through critical infrastructure networks conducting discovery while minimizing detection by facility network and asset administrators. 

Towards the end of their attack chain Volt Typhoon gains full domain compromise by extracting the network’s entire Active Directory database. Once the network’s Active Directory has been copied, Volt Typhoon engages in offline password cracking activities to gain elevated access credentials for tactical infiltration of critical systems bleeding into the OT Environment. Volt Typhoon affiliates have expressed interest in targeting United States Energy, Communications, Transportation, and Water/Wastewater related sectors.

Actions and/or Recommendations

  • Apply patches for all internet-facing systems. Prioritize patching critical vulnerabilities in appliances known to be exploited by “Volt Typhoon”.
  • Implement Phishing-Resistant Multi-factor Authentication. Please note, MFA may have operational considerations in your environment.
  • Ensure Logging is turned on for applications, access, security logs, and store logs in a central system.
  • Implement Security Awareness Training/Campaigns.
  • Develop & Test monitoring strategy to identify undesired access or activity on facility networks.
  • Mandatory timed password reset policy is encouraged.
  • Engage Mangan Cybersecurity for assistance with impacted systems and networks.

Mangan Cybersecurity has well established templates and techniques to assist with the above suggestions expediently and effectively. Mangan is a customer of its own products/services recommended within published cybersecurity advisories.

About REAL Matters and Mangan Inc.

REAL Matters advisories are published to communicate cybersecurity threats and risks within the Operational Technology (OT) environment and where Critical Infrastructure vulnerabilities are identified. The purpose of this newsletter is to inform, propose suggested approaches to mitigate the risk as well as provide feedback on how Mangan Cybersecurity is approaching the issue(s) addressed.

Mangan Inc. is a nationally-recognized Specialty Engineering, Automation, and Integration company, providing a full-range of services to the Oil & Gas, Refining, Pipeline, Chemicals, and Life Sciences Industries. Established in Long Beach, California in 1990, Mangan’s multiple office locations include sites in California, Georgia, New Hampshire, North Carolina, Texas, and Louisiana. Mangan’s 350+ employee-owners bring expertise, innovation, and safety as their core mission to some of the largest companies in the world.

Scroll to Top