Critical Infrastructure Intelligence  ·  CISA AA24-038B  ·  FBI · NSA

Volt Typhoon
Texas Infrastructure

China MSS-affiliated threat actor pre-positioning inside Texas energy, water, and pipeline OT networks since mid-2022. Not financial crime — sabotage preparation. Living-off-the-land (LOLBins) tradecraft evades every signature-based detection tool your team is running today.

3+ yrs Pre-positioning
timeline
Energy
Water
Pipeline
TX sectors
confirmed
LOLBin Evasion
primary
Sabotage Stated
objective

Published: June 15, 2026  ·  Sources: CISA AA24-038B, FBI AA25-016, NSA Cybersecurity Report 2025, IBM X-Force Threat Intelligence Index 2026

This is not a ransomware threat. Volt Typhoon is not encrypting files for ransom — it is establishing persistent, undetected access to operational technology (OT) networks that control physical infrastructure. The objective is sabotage, not disruption. Texas grid operators, water utilities, and midstream pipeline companies are in their targeting set. If your network touches any of these sectors, assume you are already in their environmental footprint.

Who is Volt Typhoon?

Attribution
China MSS
Aliases
VOLT STORM, DEV-0391
Active Since
Mid-2022
Objective
Sabotage

Operational Profile

  • China's Ministry of State Security (MSS)-directed cyber actor operating with intelligence community coordination
  • Distinct from financial cybercrime — mission is infrastructure pre-positioning, not extortion
  • Pre-positioning activity confirmed by CISA, FBI, NSA in joint advisory AA24-038B (Feb 2024)
  • Maintains persistent access by exploiting internet-facing devices (VPN appliances, firewalls, edge routers)
  • Resists eviction — designed to survive credential resets and standard incident response
  • Texas-specific targeting: energy generation/transmission, water treatment/distribution, natural gas pipeline SCADA
  • DoD, defense contractors, and telecommunications are adjacent targets; TX critical infrastructure is the core

Primary Target Profile — Texas

  • ERCOT grid operators, power generation facilities (gas-fired peakers, utility-scale solar)
  • Municipal water utilities with SCADA/ICS deployments (treatment plant automation, lift stations)
  • Natural gas pipeline operators (midstream and distribution) with telemetry and control systems
  • Industrial IT networks adjacent to OT (HMI workstations, historian servers, engineering workstations)
  • Vendors and MSPs serving any of the above — supply chain pivot vector confirmed
  • CJIIS-connected systems in utility operations (incident reporting networks)

Why Not Ransomware — The Distinction

  • Volumetric ransomware targets data and extorts money — Volt Typhoon targets physics
  • Disabling a pipeline control system at a critical moment is worth more to Beijing than $10M in bitcoin
  • TTPs are designed specifically to avoid detection tools that catch encryption-based attacks
  • State-aligned motivation means rule of engagement is geopolitical, not economic

How Volt Typhoon Gets In and Stays

Volt Typhoon uses living-off-the-land binaries (LOLBins) and legitimate credentials to blend into normal network traffic. Standard EDR, AV, and SIEM rules designed for ransomware signatures will not flag this activity. Below are the confirmed techniques from CISA AA24-038B.

Technique ID Description TX Exposure Severity
Valid Accounts T1078 Uses harvested or purchased credentials for VPN, firewall, and O365 logins to establish initial access. No malware to detect. All sectors — especially VPN appliances at utility IT/OT boundary HIGH
Exploit Public-Facing Application T1190 Leverages unpatched VPN gateways (CVE-2018-13379 FortiGate, Pulse Connect Secure) and edge devices to gain initial foothold. IT/OT boundary devices, remote access infrastructure HIGH
Native Binary Proxy Execution T1218 Uses wmic.exe, mshta.exe, certutil.exe, bitsadmin.exe — all Windows-native, signed binaries. EDR misses these by design. Windows OT workstations, engineering workstations, HMI servers HIGH
Web Session Cookie Hijacking T1539 Steals session tokens to maintain persistence after credential resets — invalidates the standard "just rotate passwords" response. IT/OT management platforms, SCADA web interfaces HIGH
Disable Security Tools T1562 Disables Windows Defender, modifies WMI filters, adds exclusion paths via GPO — using legitimate admin tools, not malware. IT domain controllers, engineering workstations HIGH
Network Sniffing T1040 Captures domain credentials from network traffic to move laterally — passive, no noise on network sensors. Flat OT networks, shared IT/OT switch segments MEDIUM
Software Deployment Tools T1072 Leverages IT management tools (PDQ Deploy, SCCM, Intune) already deployed on the network as a transport mechanism for lateral movement. Organizations with unified IT/OT management platforms HIGH
Scheduled Transfer T1029 Schedules data staging and exfiltration at low-traffic intervals (weekends, nights) — data may not be "exfil" but staging for sabotage. OT historian servers, process data repositories MEDIUM

Where Volt Typhoon Is Already Inside

CISA and FBI confirm Volt Typhoon has targeted the Operational Technology (OT) networks of energy, water, and pipeline organizations across the United States. Texas is disproportionately exposed given its role as the nation's largest energy producer, second-largest water consumer, and primary node for interstate natural gas pipeline infrastructure.

Energy

ERCOT operates the only independent US grid — no federal oversight of security standards during normal operations. Texas generates 30%+ of the nation's wind power and is the largest gas-fired generation state. Volt Typhoon targeting grid management systems, generation control, and transmission SCADA.

ERCOT grid operators (not federally regulated)
Independent power producers (IPPs) — solar, gas, wind
Transmission utility SCADA (not NERC CIP exempt)
Demand response and load management systems
Electric substation automation (IEC 61850, DNP3)
💧
Water & Wastewater

Texas water systems face compounding threats: aging infrastructure, limited cybersecurity budgets, and EPA oversight that does not mandate OT-specific security controls. Disrupting water treatment or distribution has direct human impact and is a high-value sabotage target.

Large municipal water utilities (100K+ connections)
Regional water supply districts (Brazos, Trinity, etc.)
SCADA/ICS for treatment plant automation (Allen-Bradley, Siemens)
Lift station and distribution pressure control systems
EPA SDWA reporting systems (CJIIS-adjacent)
🏭
Pipeline (Midstream)

Texas hosts the nation's largest pipeline network for natural gas, crude oil, and refined products. Texas pipelines serve as the delivery mechanism for roughly 25% of U.S. domestic energy supply. TSA SD 2021-01F applies but compliance is uneven at midstream operators.

Natural gas interstate pipeline control centers
LNG export terminal SCADA (Cheniere, Freeport LNG, Corpus Christi LNG)
Crude oil gathering systems (Permian Basin midstream)
Pipeline pressure monitoring and valve automation
Compressor station automation (Solar Turbines, GE)
⚖ Applicable Regulatory Obligations — Texas OT Operators
NERC CIP (if applicable) Ongoing — if bulk electric system
TSA SD 2021-01F (Pipeline) Security plan on file + annual update
EPA SDWA (Water) Risk and resilience assessment required
ERCOT Protocols (Energy) No cybersecurity standard — voluntary posture
TX SB 820 — Critical Infrastructure Notification within 48 hrs of breach
CISA AA24-038B Reporting Voluntary — strongly recommended

Confirmed Activity & Sector Incidents

The following incidents are confirmed in CISA/FBI joint reporting or attributed by government agencies. TX-specific exposure derived from published advisories and CISA ICS-CERT advisories.

Incident / Activity Date Sector TX Relevance
Volt Typhoon — OT Network Pre-positioning (AA24-038B) 2022–present Energy, Water, Pipeline Direct — TX energy/water/pipeline confirmed in targeting set
SALT TYPHOON — Telecom Infrastructure (AA25-016) 2022–present Telecom / Critical Infra Indirect — CJIS-connected utility comms at risk
TSA SD 2021-01F — Pipeline Security Directive 2022–present Pipeline Direct — applies to all TX pipeline operators
OT/ICS Edge Device Exploitation (CISA Alert) 2023–2025 Cross-sector Direct — OT edge devices (PLCs, RTUs) targeted
Volt Typhoon — Guam Military Infrastructure (DoD) 2021–2023 Defense Indirect — TX defense contractors may have similar exposure
SCADA/ICS Vulnerabilities — TX Water Utilities (EPA) 2024–2025 Water Direct — EPA SDWA reporting gap, limited OT security
Intrusion Set BRICKSTORM — OT Network Activity 2024–2025 Energy, Manufacturing Moderate — IBM X-Force confirmed OT targeting in TX region
CISA AA24-038B — 24-Month Persistence Campaign 2022–2024 All Critical Infra Direct — 24-month dwell confirmed; TX operators in scope

Why Your SOC Can't See Volt Typhoon

Detection Gap Why It Fails What CoreRecon Does
EDR Signature Detection Volt Typhoon uses only OS-native binaries (LOLBins) — no malware to flag Behavioral EDR with OT-aware rules + anomaly detection on admin tool usage
SIEM Rule Engines Traffic patterns mimic legitimate admin activity — no anomalous signatures OT network segmentation monitoring + lateral movement anomaly scoring
Threat Intel Feeds Volt Typhoon infrastructure is low-profile — not flagged in standard IOC feeds CISA AA24-038B IOC integration + FBI liaison reporting + dedicated OT hunts
VPN / Remote Access Valid credentials used — no brute force, no anomaly at the auth layer Session anomaly detection + JA4+ fingerprinting + out-of-band verify
OT/ICS Network Monitoring Flat OT networks — no segmentation, no east-west visibility Passive OT network monitoring (Claroty, Dragos protocol analysis) + asset discovery
Credential Reset Response Web session cookie theft invalidates password rotation as remediation Full credential invalidation protocol + session token audit + identity validation

8 Actions Before the Next Briefing

Ordered by immediate impact. These are specific, executable actions — not generic hardening advice.

01 Audit OT/IT Boundary — Assume Compromised

Assume Volt Typhoon is already inside your network. Conduct OT network architecture review — map every connection between IT and OT networks. Identify VPN appliances, jump servers, and engineering workstations that bridge both environments. CoreRecon OT assessment includes passive network monitoring of IT/OT boundary traffic.

CRITICAL
02 Rotate All VPN / Edge Device Credentials

VPN appliances, firewalls, and remote access solutions (Fortinet, Pulse Secure, Citrix, Palo Alto GlobalProtect) are the primary ingress vector. Force credential rotation on all remote access accounts. Enable hardware MFA (FIDO2/Yubikey) on all VPN access — TOTP is phishable and MFA fatigue attacks have been used against this actor.

CRITICAL
03 Deploy OT-Aware Passive Monitoring

Active scanning of OT networks can cause disruption. Deploy passive monitoring (Claroty, Dragos, Nozomi, or CoreRecon's OT-aware SOC) to analyze live traffic on IT/OT segments. Identify anomalous Modbus, DNP3, IEC 61850 traffic. Set up alerts for工程师 workstation anomalies — Volt Typhoon uses legitimate admin tool chains that blend into normal traffic.

CRITICAL
04 Segment OT Networks — VLAN Isolation

Most Texas OT networks are flat — one VLAN for engineering workstations, SCADA servers, and corporate IT. Enforce physical separation between OT and IT at the network layer. PLCs, RTUs, and SCADA servers should be on isolated VLANs with no direct path to corporate IT. If a workstation on the IT side is compromised, OT must not be reachable from it.

HIGH
05 Conduct OT-Specific Incident Response Drill

Your IR plan does not account for OT environments if it was written for IT-only operations. Develop and tabletop test a scenario where Volt Typhoon has compromised your HMI or SCADA server. Key question: can you isolate OT from IT without disrupting physical operations? This requires coordination between IT security, OT operations, and facilities. CoreRecon Command tier includes OT IR playbook development.

HIGH
06 Patch OT Edge Devices and VPN Gateways

FortiGate (CVE-2018-13379, CVE-2022-42475), Pulse Connect Secure, Citrix ADC, Palo Alto PAN-OS — all confirmed exploitation vectors. Patch these within 72 hours of any new CVE disclosure. For OT devices that cannot be patched (legacy PLCs, RTUs), implement compensating controls: network segmentation, jump server access, and enhanced monitoring.

HIGH
07 Report to CISA — AA24-038B IOC Integration

If you identify any Volt Typhoon indicators (anomalous wmic.exe / certutil.exe / bitsadmin activity on OT segments, unauthorized use of IT management tools for OT transport, session anomalies on SCADA web interfaces), report to CISA via CISA Services portal or call 1-844-NCCIC-1. CoreRecon maintains a continuously updated IOC feed derived from CISA AA24-038B, FBI liaison channels, and IBM X-Force research.

HIGH
08 TSA SD 2021-01F Compliance — Pipeline Operators

If you operate a pipeline, TSA SD 2021-01F requires a current cybersecurity plan submitted to TSA. The May 2, 2026 compliance window for SD 2021-01F has passed — operators should ensure annual review and update cycle is current. CoreRecon's pipeline cybersecurity package includes SD 2021-01F alignment, SCADA security assessment, and TSA reporting support.

HIGH (Pipeline Only)

OT-Aware SOC for Critical Infrastructure

CoreRecon's Sentinel and Command tiers include specific capabilities designed for Volt Typhoon detection and OT/IT convergence risk — not available from standard MSSPs running signature-based detection.

Capability Sentinel Command Why It Catches Volt Typhoon
24/7 OT-Aware SOC Included Included Analysts trained on LOLBin activity in OT environments — not just IT signatures
CISA AA24-038B IOC Feed Included Included Continuously updated indicators from CISA, FBI liaison, IBM X-Force
Behavioral EDR (OT-safe) Included Included Anomaly scoring on native binary usage — catches LOLBin without blocking OT ops
Passive OT Network Monitoring Add-on Included No active scan — passive analysis of Modbus, DNP3, IEC 61850, BACnet traffic
OT Incident Response Plan Not Included Included Custom IR plan for OT environments with isolation protocols
TSA SD 2021-01F Alignment Not Included Included Pipeline cybersecurity plan development and annual review
vCISO (OT/IT Convergence) Not Included Included Board-level reporting on OT/IT convergence risk with Volt Typhoon context
Quarterly OT Threat Hunt Not Included Included Active threat hunt focused on OT network segments — assumes pre-positioning

Assume they're already inside.

CoreRecon's OT-aware SOC closes the detection gap that signature-based tools can't address.

No spam. One PDF, sent immediately. CoreRecon will not sell your information.
CISA AA24-038B — February 2024 Joint Advisory

📄
Brief sent.

Check your inbox for the full Volt Typhoon Texas Infrastructure Threat Brief PDF. If it doesn't arrive in 5 minutes, check your spam folder or email john@corerecon.com.