Published 04/01/2024
U.S. Critical Infrastructure
CISA, NSA, and FBI have confirmed that Volt Typhoon has compromised the IT environments of multiple critical infrastructure organizations—primarily in Communications, Energy, Transportation Systems, and Water and Wastewater Systems Sectors—in the continental and non-continental U.S. and its territories, including Guam.
Volt Typhoon’s choice of targets and pattern of behavior are not consistent with traditional cyber espionage or intelligence-gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT assets to disrupt functions.
These actors could use their network access to achieve disruptive effects in the event of geopolitical tensions and/or military conflicts. (Cybersecurity and Infrastructure Security Agency, 2024)
In December 2023, an operation disrupted a botnet comprising hundreds of U.S.-based small office/home office (SOHO) routers that were hijacked by state-sponsored hackers from the People’s Republic of China (PRC). The hackers, known to the private sector as “Volt Typhoon,” used privately owned SOHO routers infected with the “KV Botnet” malware to conceal the PRC origin of subsequent hacking activities targeting the U.S. and other foreign victims. These further hacking activities included a campaign targeting critical infrastructure organizations in the U.S. and elsewhere, which was the subject of a May 2023 advisory from the FBI, the National Security Agency, and CISA (Office of Public Affairs, 2024).
The KV Botnet primarily targets Cisco and Netgear routers, exploiting a vulnerability due to their “end of service” status. This means they were no longer receiving security patches or software updates from the manufacturer. The operation removed the KV Botnet malware from the routers and took additional steps to sever their connection to the botnet, including blocking communications with other devices used to control it (Office of Public Affairs, 2024).
Volt Typhoon employs a multi-faceted approach to infiltrate and compromise target networks, starting with comprehensive pre-compromise reconnaissance to understand the network architecture and operational protocols. They exploit vulnerabilities in public-facing network appliances to gain initial access, then aim to escalate privileges within the network, often targeting administrator credentials. Using valid credentials, they move laterally across the network, leveraging remote access services such as Remote Desktop Protocol (RDP) to reach critical devices, including domain controllers (DCs). Volt Typhoon conducts discovery within the network, utilizing stealthy tactics such as living-off-the-land (LOTL) binaries and PowerShell queries on event logs to extract critical information while minimizing detection. LOTL tools like ntdsutil, netsh, and systeminfo were used to gather information about the network service and system details. Also, Volt Typhoon implanted binary files such as SMSvcService.exe and Brightmetricagent.exe that can open reverse proxies between a compromised device and malicious C2 servers. The PowerShell script logins.ps1 was also observed collecting successful logon events on infected systems without being noticed. (Cybersecurity and Infrastructure Security Agency, 2024).
After achieving full domain compromise, Volt Typhoon extracts the Active Directory database (NTDS.dit) from the DC using techniques such as Volume Shadow Copy Service (VSS) to bypass file locking mechanisms. Additionally, Volt Typhoon uses offline password-cracking methods to crack hashed passwords, enabling elevated access within the network. With elevated credentials, Volt Typhoon focuses on strategic network infiltration, aiming to access Operational Technology (OT) assets, such as sensors and control systems. Volt Typhoon was observed testing access to OT systems using default vendor credentials and exploiting compromised credentials obtained through NTDS.dit theft. This access grants them the ability to disrupt critical infrastructure systems, such as HVAC and energy controls, posing a significant threat to infrastructure security (Cybersecurity and Infrastructure Security Agency, 2024).
The second vulnerability, CVE-2024-1708, is related to CWE-22 – Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’). Although it is considered less severe as it is unlocked by CVE-2024-1079, it must not be underestimated (Team Huntress, 2024). This vulnerability involves manipulating ZIP file paths when extracting its contents. Attackers can then modify these contents and execute malicious code (Poudel, 2024). To do this, a malicious actor needs to have both administrative credentials and create a malicious extension inside C:Program Files (x86)ScreenConnectApp_Extensions to write files anywhere within the folder (Team Huntress, 2024). Team Huntress showed that this ZipSlip attack was not necessary, as malicious actors can run code by accessing a ScreenConnect feature called “Extensions”. This could easily go unnoticed in a system, since no other extensions need to be installed (Team Huntress, 2024).
ConnectWise released a patched version of ScreenConnect on February 21st, 2024, and recommends updating all versions from 23.9.7 onward to 23.9.8 (ConnectWise, 2024). As of today, February 22nd, 2024, 3,800 instances of ScreenConnect have been identified as vulnerable and need to be updated to the latest version to prevent malicious actors from accessing the ScreenConnect environment. ConnectWise added that Cloud instances were automatically patched, whereas On-Prem partners need to install all required updates manually to remediate both vulnerabilities (ConnectWise).
CVE-2024-1709
| Type | Indicator |
| PowerShell Script | C:{redacted}logins.ps1 |
| Folder Path | C:UsersPublicpro |
| Folder Path | C:WindowsTemptmpActive Directoryntds.jfm |
| Folder Path | C:WindowsTemptmpActive Directoryntds.dit |
| Folder Path | C:UsersPublicDocumentssysteminfo.dat |
| Folder Path | C:UsersPublicDocumentsuser.dat |
| Folder Path | Folder Path C:Users{redacted}DownloadsHistory.zip |
| Folder Path | C:WindowsSystem32rult3uil.log |
| File Name | comsvcs.dll |
| File Name | NTDS.dit |
| File Name | SMSvcService.exe |
| File Name | Brightmetricagent.exe |
| SHA256 Hash |
edc0c63065e88ec96197c8d7a40662a15a812a9583dc6c82b18ecd7e43b13b70 |
| SHA256 Hash |
99b80c5ac352081a64129772ed5e1543d94cad708ba2adc46dc4ab7a0bd563f1 |
PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure Cybersecurity and Infrastructure Security Agency CISA. (2024, February 7). https://www.cisa.gov/news-events/cybersecurity-advisories/aa24038a#_Appendix_C:_MITRE
The U.S. government disrupts a botnet, and the People’s Republic of China used to conceal hacking of critical infrastructure. Office of Public Affairs | United States Department of Justice. (2024, January 31). https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical
Contributing Security Analysts: Alessandro Lovadina, Joy Boddu, Likhitha Duggi