Volt Typhoon Infrastructure Pre-positioning
First seen Jul 3, 2026 · Updated Jul 3, 2026
Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.
Affected Systems
Fortinet FortiGuard, Cisco routers, SOHO equipment, Windows AD environments
Indicators of Compromise
- ntdsutil abuse
- netsh port forwarding
- Compromised SOHO routers as proxies
- Unusual LDAP from edge devices
Remediation Steps
- 1
Audit Edge Devices
Check for unauthorized config changes and unknown admin accounts
- 2
Replace EOL Routers
Remove all end-of-life SOHO networking equipment
- 3
Enhanced Logging
Enable PowerShell, WMI, and LDAP logging on domain controllers
- 4
Review CISA AA24-038A
Follow comprehensive detection guidance
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.