Menu Close

NSA: Volt Typhoon Campaign a Failure in Its Attempt to Persist in U.S. Critical Infrastructure

Image Credentials: Image Title: NSA: Volt Typhoon Campaign a Failure in Its Attempt to Persist in U.S. Critical Infrastructure Source: (sora.chatgpt) Date: June 2025  Attribution: Created by AI-generated imagery (sora.chatgpt), it does not depict a real-world scene.

By Staff Writer | Open Chronicle  with Agencies

At a recent International Conference on Cyber Security at Fordham University in New York City, senior officials from the National Security Agency (NSA) and the FBI discussed the ongoing threat of Chinese cyber campaigns targeting critical U.S. infrastructure. Among the key topics was Volt Typhoon, a Chinese cyber effort aimed at prepositioning assets within U.S. systems for potential disruptive or destructive attacks, particularly in the event of a conflict centered around Taiwan.

Volt Typhoon: A Threat That Wasn’t Successful

Kristina Walter, the Director of the NSA’s Cybersecurity Collaboration Center, provided an update on Volt Typhoon, describing the Chinese actors behind it as having been unsuccessful in their efforts to infiltrate U.S. critical infrastructure. The goal of Volt Typhoon was to gain long-term access to these systems, allowing for rapid disruption when needed.

“The good news is, they failed,” Walter said. She further explained that the Chinese actors were attempting to persist quietly on domestic networks, but the NSA, alongside the FBI and private sector partners, was able to identify their presence and thwart their efforts. Walter mentioned that the NSA and its partners had successfully uncovered how the actors were using legitimate credentials to maintain persistence on U.S. systems and ensured the private sector and government were equipped to detect and eliminate them.

Collaboration Across Sectors

Walter stressed that collaboration between public and private entities played a significant role in the success of this mission. After releasing a public advisory in 2024, the NSA saw critical infrastructure operators reaching out for assistance, confirming the presence of Volt Typhoon, and requesting guidance on how to safeguard their networks. This collective effort from government agencies and private cybersecurity entities significantly reduced the threat posed by Volt Typhoon.

FBI’s Role and Efforts to Expose Chinese Hacking Groups

Brett Leatherman, recently appointed assistant director for cyber at the FBI, echoed Walter’s remarks. He emphasized the targeted nature of Volt Typhoon, which specifically focused on critical infrastructure associated with the U.S. Navy, particularly in island regions like Guam. Leatherman discussed how U.S. efforts to publicize Chinese hacking activities forced Chinese groups to change tactics, preventing them from maintaining the same level of access.

“This made them burn their previous methods and come up with new ways to breach U.S. organizations,” Leatherman explained. “Public attribution is important because it helps identify and disrupt these operations before they do significant damage.”

FBI Engagement in Cyberwarfare

Leatherman also detailed a notable incident involving the FBI’s engagement in “true cyberwarfare” against Chinese cyber actors. He recounted an effort to take down a botnet used by China’s Flax Typhoon, a campaign tied to the Integrity Technology Group, a now-indicted Chinese cybersecurity company. After successfully disabling the botnet’s command and control infrastructure, the FBI was targeted by a DDoS attack by the hackers, only for the FBI to regain control and push back with a public splash page.

“Once they saw the FBI splash page, they realized who they were attacking and burned down their infrastructure,” Leatherman said, showcasing the FBI’s willingness to confront cyber adversaries head-on.

China’s Cyber Ecosystem

Both Walter and Leatherman highlighted the complex, multi-layered ecosystem of Chinese cyber activity. Rather than a singular effort by the Chinese government, the attacks involve a web of state-sponsored actors, private companies, and academic institutions all working to exploit vulnerabilities in U.S. systems.

“When we look at the Chinese cyber ecosystem, it’s not just the government targeting the United States,” Walter noted. “It’s this giant network of companies, research institutions, and other entities, all aiming to gain access for the government.”

Strategic Gains and Future Threats

The efforts to expose Volt Typhoon’s activities and disrupt their plans were seen as a significant win in the ongoing cyber conflict with China. Walter pointed out that the failure of Volt Typhoon to maintain persistent access had forced China to reassess its approach. “They had to go back to the drawing board,” Walter said. “They were forced to re-evaluate how they could infiltrate U.S. systems, and that friction slows them down.”

Leatherman added, “Even if we can’t dismantle their entire apparatus, by exposing their methods and slowing their efforts, we’re protecting national security. Our ultimate goal is to keep them guessing and force them to start from scratch.”

The NSA and FBI’s coordinated efforts have proven effective in pushing back against Volt Typhoon and similar Chinese cyber campaigns targeting U.S. infrastructure. While these operations are far from over, the success in exposing and disrupting these efforts sends a strong message: the U.S. is prepared to defend its critical systems and will continue to adapt and innovate in the fight against cyber threats from foreign adversaries.

Leave a Reply

Your email address will not be published. Required fields are marked *