By Cyber Defense Technologies September 16, 2025 5 min read
Most discussions of nation-state cyber activity focus on espionage: stealing secrets. Since 2023, U.S. and allied agencies have warned about something different. In a February 2024 joint advisory, CISA, NSA and FBI assessed that People's Republic of China (PRC) state-sponsored actors, publicly tracked as Volt Typhoon, were pre-positioning themselves on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.
That is a significant shift. It means some intrusions are not about what attackers can take today, but about what they could do tomorrow.
Public warnings about pre-positioning
-
May 2023
First joint advisory
U.S. and international partners warn of PRC state-sponsored living-off-the-land activity against critical infrastructure.
-
February 7, 2024
Advisory AA24-038A
CISA, NSA and FBI assess that Volt Typhoon is pre-positioning in U.S. critical infrastructure for potential disruption, and publish living-off-the-land hunting guidance.
-
August 27, 2025
Salt Typhoon advisory
Agencies from 13 countries describe state-sponsored compromise of telecommunications and other networks through edge routers.
What the advisories describe
According to advisory AA24-038A and related guidance:
- The actors compromised organizations across multiple critical infrastructure sectors, including communications, energy, transportation, and water and wastewater, in the continental United States and its territories, including Guam.
- In some cases, they maintained access for years.
- They relied heavily on living-off-the-land techniques, using built-in tools and valid accounts rather than custom malware.
- They often gained initial access by exploiting vulnerabilities in internet-facing network devices, such as routers, firewalls and VPNs, including devices that were no longer supported.
- They focused on obtaining administrator credentials and on reaching systems that could provide access to operational technology.
- They used networks of compromised small office and home office devices to route their traffic and hide its origin.
The agencies also described their behavior as inconsistent with typical espionage: the targeting and activity pointed toward preparation for disruption.
Why it matters beyond infrastructure operators
It is easy to read these advisories as relevant only to utilities and telecommunications companies. The implications are broader:
- Defense missions depend on civilian infrastructure. Military installations rely on commercial power, water, communications and transportation. Disruption of those services during a crisis could affect military response.
- Suppliers and service providers are pathways. Managed service providers, equipment vendors and contractors with access to infrastructure networks can be used to reach them.
- The techniques are widely applicable. Living off the land, abusing edge devices and stealing credentials work against any organization.
How to look for it
Because pre-positioning emphasizes stealth, organizations often discover it only by looking deliberately. Priorities include:
Hunt for the published behaviors
The advisories and accompanying guidance list specific behaviors, such as suspicious use of built-in tools, unusual administrative logons and signs of credential database extraction. Use them as hunting hypotheses across endpoints, domain controllers and network devices.
Examine edge devices
Review routers, firewalls and VPNs for unauthorized configuration changes, unknown accounts and signs of exploitation. Replace devices that are past end of support.
Review privileged access
Look for unexpected administrative accounts, unusual privileged logons and credentials that are used from unexpected places.
Protect paths to operational technology
Identify every path from IT networks to OT networks, and tighten and monitor them. Know which accounts can reach control systems.
Keep logs long enough
Long-dwell intrusions require long log retention. If logs cover only a few weeks, an intrusion that began months ago may leave little evidence.
Planning to operate through disruption
For organizations that support critical missions, detection is only part of the answer. Resilience planning should consider:
- how operations would continue if key IT systems or services were disrupted
- manual procedures for essential functions
- dependencies on external providers of power, communications and other services
- exercises that test response to disruptive attacks, not only data breaches
Frequently asked questions
Is this threat still current? The advisories describe ongoing concerns, and related activity by other actors, including against telecommunications networks, has been described in later advisories. Check CISA's advisories for the latest information.
We are a small organization. Would we be targeted? The advisories note that the actors compromised organizations of various sizes, including smaller entities. Size is less important than what an organization is connected to and what it supports.
What is the single most important step? There is no single step, but securing and monitoring internet-facing devices and privileged accounts addresses the most common pathways described.
What to do this week
- Review the behaviors listed in advisory AA24-038A and check which your logging could detect.
- List every connection between IT and OT networks, and who can use it.
- Check how far back your authentication and endpoint logs go.
- Identify edge devices that are past end of support.
- Confirm you have a manual fallback for your most critical operational processes.
How CDT can help
CDT's cyber hunt team hunts for the behaviors described in these advisories, and our embedded and critical system protection and system hardening teams secure OT paths and edge devices. Incident response is available if an intrusion is found.
Sources
- CISA advisory AA24-038A, PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure
- CISA and partners release advisory on PRC-sponsored Volt Typhoon activity and supplemental living off the land guidance
- CISA and partners release joint advisory on countering Chinese state-sponsored actors compromise of networks worldwide (August 2025)