highAPT

Volt Typhoon Infrastructure Pre-positioning

First seen Jul 3, 2026 · Updated Jul 3, 2026

APTState-SponsoredCritical Infrastructure

Chinese state-sponsored group maintaining persistent access in US energy, water, and telecom networks using living-off-the-land techniques that blend with normal admin activity.

Affected Systems

Fortinet FortiGuard, Cisco routers, SOHO equipment, Windows AD environments

Indicators of Compromise

  • ntdsutil abuse
  • netsh port forwarding
  • Compromised SOHO routers as proxies
  • Unusual LDAP from edge devices

Remediation Steps

  1. 1

    Audit Edge Devices

    Check for unauthorized config changes and unknown admin accounts

  2. 2

    Replace EOL Routers

    Remove all end-of-life SOHO networking equipment

  3. 3

    Enhanced Logging

    Enable PowerShell, WMI, and LDAP logging on domain controllers

  4. 4

    Review CISA AA24-038A

    Follow comprehensive detection guidance

Industries Most Exposed

EnergyWaterTelecommunications

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.