Cybersecurity usually teaches us to look for things that don't belong. A suspicious file, an unfamiliar program, an unexpected login. Those things can be useful clues, but what happens when an attacker inside your network is using tools that look completely legitimate?
That is what makes Volt Typhoon so interesting and so concerning.
Volt Typhoon is a China-linked, state-sponsored threat actor group that has been targeting critical infrastructure organizations across the communications, energy, transportation, and water sectors. Rather than breaking into a network and immediately causing disruption, the group has taken a much more patient approach. It gains access, learns about the environment, moves through systems, and works to maintain that access without attracting attention.
In some cases, U.S. government investigations have found evidence that Volt Typhoon maintained access to compromised environments for years.
That's a long time to have someone inside your network, and it's also a long time for an attacker to learn how everything works.
Microsoft has observed much of the same behavior. Its researchers found that the group has become known for using standard administrative tools and stolen credentials rather than relying exclusively on traditional malware.
That makes the activity harder to distinguish from normal administrative work and helps an attacker maintain access without drawing attention.
The longer that access goes undetected, the more valuable it can become. An attacker who has spent years mapping an environment does not need to guess where critical systems are or which accounts can reach them. They have had time to figure that out.
Volt Typhoon has been active since at least 2021 and is widely assessed to be associated with the People's Republic of China. The group has received significant attention from U.S. cybersecurity and intelligence agencies because of where it operates and how it operates.
The "where" is relatively straightforward. Volt Typhoon has focused heavily on critical infrastructure across the globe. The "how" is where things get more interesting. This technique is often referred to as "living off the land." The concept is simple enough: instead of bringing a suspicious toolkit into the environment, use what is already there.
If an attacker has trusted credentials, they may be able to log into systems without triggering the kind of obvious warning that comes with a brute-force attack. If they need to investigate a machine, they can use the same tools an administrator would normally use. If they need to move around the network, they can use existing remote-access capabilities.
From a security team's perspective, nothing necessarily screams "hacker."
Imagine an administrator logs into a server and opens something such as PowerShell, which is an automation and configuration management system developed by Microsoft. There is nothing particularly alarming about that. It’s a standard administrative tool, so there are countless reasons someone might use it.
Now, imagine that the account belongs to an employee who normally works on one part of the network but suddenly starts accessing systems they have never touched before. From there, the account begins looking for information about other machines and users.
The individual actions may still be legitimate, but the pattern is what starts to become suspicious.
This is one of the biggest challenges presented by Volt Typhoon. The group doesn't necessarily need to introduce anything that security software already recognizes as malicious. It can leverage activity that security teams see every day and rely on context to distinguish normal behavior from something more concerning.
A security team can't simply block PowerShell because an attacker might use it. They can't turn off every remote-access tool because those tools are necessary for modern businesses to function. And they can't assume that every administrator account behaving unusually has been compromised.
Instead, they have to understand the bigger picture: Who is using the account? What systems are they accessing? Is that activity consistent with what the user normally does? What happened before the login, and what happened afterward?
The answers to those questions are often more useful than the individual security alerts themselves, and it’s where it pays to work with a vSOC that has the experience and knowledge to spot anomalies fast.
Critical infrastructure organizations support services that people depend on every day. Communications networks, energy systems, transportation, and water infrastructure all rely on increasingly connected technology. Compromise those environments, and the potential consequences can extend well beyond the organization itself.
That is why U.S. government agencies have been particularly vocal about Volt Typhoon's activity. In a joint advisory, Cybersecurity & Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), National Security Agency (NSA), and international partners warned that the group had been compromising and maintaining access to U.S. critical infrastructure organizations.
The agencies also described activity consistent with "pre-positioning," meaning an attacker establishes access ahead of time so it could potentially be used during a future crisis.
A ransomware operator typically wants to get in and monetize the intrusion as quickly as possible, but Volt Typhoon has demonstrated the value of patience. The longer an attacker can remain undetected, the more they can learn about the environment and the more options they may have.
Instead of asking only, "How do we keep them out?" organizations also need to ask, "How would we know if they were already inside?"
The answer to Volt Typhoon isn't a single security product. No tool can guarantee an attacker will never get through.
This is why good security fundamentals still matter. Organizations need to patch vulnerabilities, protect privileged accounts, enforce strong authentication, limit unnecessary access, segment important systems, and maintain visibility across their environments.
But even the best preventative controls have limitations. Eventually, a credential might be stolen. A vulnerability might be exploited before it can be patched. An account might be compromised, and a trusted system might become the starting point for an intrusion.
This is where detection and response become so important. If an attacker is using legitimate credentials and built-in tools, the goal is no longer to find malware. The goal is to recognize behavior that doesn't make sense.
That requires visibility, but visibility alone isn't enough. Someone must be able to interpret what they're seeing.
RADICL’s approach combines technology with human analysts who can investigate activity across an organization's endpoint, identity, and network environments. Instead of treating every alert as an isolated event, analysts can consider the broader context to determine whether the activity poses a real threat.
But when those things begin to form a pattern, someone needs to recognize it.
That's where threat hunting becomes particularly valuable. Rather than waiting for a security platform to raise its hand and announce an attack, analysts can proactively look for behaviors associated with known threats and investigate activity that falls outside the expected norm.
It's less about finding one bad event and more about understanding what all of the events mean together.
That's why having security tools in place is only part of the equation. Organizations also need the people and processes necessary to investigate what those tools are seeing and determine when normal activity starts to look a little less normal.
An attacker doesn't need to look like an attacker to be dangerous, and Volt Typhoon has demonstrated how effective that approach can be.
For organizations trying to defend against sophisticated threats, the answer isn't to assume everything is malicious. It's to have enough visibility and expertise to recognize when something doesn't add up.
Ready to improve your security posture? Let’s talk.