Volt Typhon, a threat actor linked to China, is strategically positioning itself within US critical infrastructure, in anticipation of launching disruptive or destructive cyberattacks during major crises or conflicts, an intelligence advisory cautioned.
The threat actor’s choice of targets and pattern of behaviour strongly suggests that it is not gathering intelligence or engaging in traditional cyberespionage, but rather that it aims to establish a foothold in IT networks for lateral movement to Operational Technology (OT) assets, intending to disrupt critical infrastructure functions.