According to Microsoft, a state-sponsored Chinese actor is conducting an “attack” on critical US infrastructure – Fox Business

AFPI Senior Fellow Steve Yates reacts to the Chinese Commerce Secretary and US Secretary of Commerce meeting, the Mikron ban, Biden’s foreign policy and the Chinese threat.

According to Microsoft, the state-sponsored Chinese cyber player Volt Typhoon is targeting critical infrastructure organizations in the United States.

Microsoft warned Wednesday that Volt Typhoon, a cyber player with ties to the People’s Republic of China, is targeting critical infrastructure organizations in the United States (iStock / iStock)

Microsoft said in a Wednesday post that the company has uncovered “stealthy and targeted malicious activity focused on post-compromise access to credentials and discovery of network systems, targeting critical infrastructure organizations in the United States.”

ANALYSIS SHOWS CHINA-BASED FENTANYL SUPPLIERS SHOW MILLIONS RECEIVED IN CRYPTO

“The attack is being carried out by Volt Typhoon,” Microsoft said. Volt Typhoon is a state-sponsored Chinese actor focused on “espionage and intelligence gathering.”

CLICK HERE TO GET THE FOX NEWS APP

Microsoft reported Wednesday that it had discovered that state-sponsored Chinese cyber actor Volt Typhoon was targeting American critical infrastructure organizations. (David Paul Morris/Bloomberg via Getty Images / Getty Images)

tickerSecurityLastChangeChange %
MSFTMICROSOFT CORP.313.85-1.41-0.45%

“Microsoft is moderately confident that this Volt Typhoon campaign seeks to develop capabilities that could disrupt critical communications infrastructure between the United States and the Asian region in future crises,” the statement said.

CHINA imposes restrictions on US companies over ‘national security risks’ as chip war escalates

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) and international cybersecurity agencies have issued a joint Cybersecurity Advisory (CSA), warning authorities that Typhoon Volt, which they say is linked to the People’s Republic of China , could apply “the same techniques” against infrastructure networks in the US and “other sectors worldwide”.

The US Cybersecurity and Infrastructure Security Agency (CISA) admitted it was aware of Volt Typhoon activities threatening critical infrastructure organizations in the US and issued an alert along with international cybersecurity agencies. (Jakub Porzycki/NurPhoto via Getty Images / Getty Images)

The CSA stated that Volt Typhoon’s primary Tactics, Techniques and Procedures (TTPs) are to “live off the land,” which allows it to evade detection by using built-in network management tools to log into regular Windows Inject systems and fly under third-party radar Third-party endpoint detection and response products.

GET FOX BUSINESS ON THE GO by CLICK HERE

The authorities recommend companies to take measures to improve their cybersecurity in light of the threat, such as: For example, securing domain controllers, monitoring event logs, restricting port proxy usage, investigating unusual IP addresses, and checking firewall configurations.