Volt Typhoon is a nation-state cyber espionage group. Their objective is to compromise the United States' critical infrastructure. In this article, we're going to talk about the cyber threat posed by Volt Typhoon, as well as mitigation strategies for financial institutions.

About the Name: Volt Typhoon

The Microsoft Threat Actor Naming Taxonomy was created to help security experts quickly identify threat actors. Anytime you see the word "Typhoon" in a threat actor name, this signals the threat actor is from China. Any words appended to it (like Volt, Flax, Salt, etc.) are added to differentiate among the different threat actor groups.

About the Threat

Volt Typhoon's operations are aimed at gathering intelligence (a.k.a., cyber espionage).

They have historically done this using a technique called "Living off the Land" (LOTL). They get in using compromised credentials or exploiting vulnerabilities, but then use legitimate system tools instead of malware to gather information. This makes their attacks harder to detect because traditional security systems see their actions as "normal" activity.

While Volt Typhoon's focus has centered around espionage, there is concern the access could be used to sabotage the systems, resulting in widespread disruption to critical infrastructure.

Mitigation Strategies

As with many cyber threats, the best strategy involves a layered approach to prevent, detect, and respond to the threat.

Need Help?

If you need assistance with protecting your financial institution from threats like Volt Typhoon, CoNetrix is here to help.

If you would like to learn more about how CoNetrix can help you, Contact Us.

Further Reading