Skip to content
Cyber Defense Technologies

Threat Intelligence

Pre-Positioning in Critical Infrastructure: What Public Advisories Tell Us

U.S. agencies have warned that state-sponsored actors are hiding inside critical infrastructure networks, not to steal data but to be ready to disrupt. What the advisories say, why it matters beyond infrastructure operators, and how to look for it.

By Cyber Defense Technologies September 16, 2025 5 min read

Most discussions of nation-state cyber activity focus on espionage: stealing secrets. Since 2023, U.S. and allied agencies have warned about something different. In a February 2024 joint advisory, CISA, NSA and FBI assessed that People's Republic of China (PRC) state-sponsored actors, publicly tracked as Volt Typhoon, were pre-positioning themselves on IT networks for disruptive or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States.

That is a significant shift. It means some intrusions are not about what attackers can take today, but about what they could do tomorrow.

Public warnings about pre-positioning

  1. May 2023

    First joint advisory

    U.S. and international partners warn of PRC state-sponsored living-off-the-land activity against critical infrastructure.

  2. February 7, 2024

    Advisory AA24-038A

    CISA, NSA and FBI assess that Volt Typhoon is pre-positioning in U.S. critical infrastructure for potential disruption, and publish living-off-the-land hunting guidance.

  3. August 27, 2025

    Salt Typhoon advisory

    Agencies from 13 countries describe state-sponsored compromise of telecommunications and other networks through edge routers.

What the advisories describe

According to advisory AA24-038A and related guidance:

  • The actors compromised organizations across multiple critical infrastructure sectors, including communications, energy, transportation, and water and wastewater, in the continental United States and its territories, including Guam.
  • In some cases, they maintained access for years.
  • They relied heavily on living-off-the-land techniques, using built-in tools and valid accounts rather than custom malware.
  • They often gained initial access by exploiting vulnerabilities in internet-facing network devices, such as routers, firewalls and VPNs, including devices that were no longer supported.
  • They focused on obtaining administrator credentials and on reaching systems that could provide access to operational technology.
  • They used networks of compromised small office and home office devices to route their traffic and hide its origin.

The agencies also described their behavior as inconsistent with typical espionage: the targeting and activity pointed toward preparation for disruption.

Why it matters beyond infrastructure operators

It is easy to read these advisories as relevant only to utilities and telecommunications companies. The implications are broader:

  • Defense missions depend on civilian infrastructure. Military installations rely on commercial power, water, communications and transportation. Disruption of those services during a crisis could affect military response.
  • Suppliers and service providers are pathways. Managed service providers, equipment vendors and contractors with access to infrastructure networks can be used to reach them.
  • The techniques are widely applicable. Living off the land, abusing edge devices and stealing credentials work against any organization.

How to look for it

Because pre-positioning emphasizes stealth, organizations often discover it only by looking deliberately. Priorities include:

Hunt for the published behaviors

The advisories and accompanying guidance list specific behaviors, such as suspicious use of built-in tools, unusual administrative logons and signs of credential database extraction. Use them as hunting hypotheses across endpoints, domain controllers and network devices.

Examine edge devices

Review routers, firewalls and VPNs for unauthorized configuration changes, unknown accounts and signs of exploitation. Replace devices that are past end of support.

Review privileged access

Look for unexpected administrative accounts, unusual privileged logons and credentials that are used from unexpected places.

Protect paths to operational technology

Identify every path from IT networks to OT networks, and tighten and monitor them. Know which accounts can reach control systems.

Keep logs long enough

Long-dwell intrusions require long log retention. If logs cover only a few weeks, an intrusion that began months ago may leave little evidence.

Planning to operate through disruption

For organizations that support critical missions, detection is only part of the answer. Resilience planning should consider:

  • how operations would continue if key IT systems or services were disrupted
  • manual procedures for essential functions
  • dependencies on external providers of power, communications and other services
  • exercises that test response to disruptive attacks, not only data breaches

Frequently asked questions

Is this threat still current? The advisories describe ongoing concerns, and related activity by other actors, including against telecommunications networks, has been described in later advisories. Check CISA's advisories for the latest information.

We are a small organization. Would we be targeted? The advisories note that the actors compromised organizations of various sizes, including smaller entities. Size is less important than what an organization is connected to and what it supports.

What is the single most important step? There is no single step, but securing and monitoring internet-facing devices and privileged accounts addresses the most common pathways described.

What to do this week

  • Review the behaviors listed in advisory AA24-038A and check which your logging could detect.
  • List every connection between IT and OT networks, and who can use it.
  • Check how far back your authentication and endpoint logs go.
  • Identify edge devices that are past end of support.
  • Confirm you have a manual fallback for your most critical operational processes.

How CDT can help

CDT's cyber hunt team hunts for the behaviors described in these advisories, and our embedded and critical system protection and system hardening teams secure OT paths and edge devices. Incident response is available if an intrusion is found.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.