What to know

  • The February 2024 advisory reported compromises and separately assessed preparation for possible disruption.
  • Legitimate accounts and ordinary administrative activity require context to evaluate.
  • Map critical service dependencies and test the boundaries between business and operational systems.

Keep the historical finding precise

On February 7, 2024, CISA, NSA, FBI, and partners published advisory AA24-038A about Volt Typhoon. The U.S. authoring agencies reported compromises of critical-infrastructure IT environments and assessed with high confidence that the actors were positioning themselves for potential disruption of operational functions. Those are related findings, but confirmed access and assessed future intent are not identical claims.

This article examines the defensive lessons of that 2024 warning. It does not report a new incident or establish that every compromised organization suffered a destructive operational attack. The distinction matters because the practical concern was the option that persistent access could create. Defenders needed to investigate the paths available to an intruder before visible disruption made their significance obvious.

Source: Joint Advisory AA24-038A: PRC State-Sponsored Actors and U.S. Critical Infrastructure, February 7, 2024

Ordinary tools can appear in extraordinary activity

The advisory described use of valid accounts and living-off-the-land techniques, in which actors used tools already available in the environment. The lesson is that the presence or absence of an unfamiliar executable cannot settle the investigation. A legitimate account and a familiar administrative action still need to be understood in relation to the system, purpose, and surrounding activity.

Consider a hypothetical utility employee account that usually handles a narrow support task. Its use to inspect unrelated administrative systems deserves an explanation even if every program involved is approved software. The useful question is whether the sequence fits authorized work. A detection process should give responders the context to investigate that question instead of treating tool familiarity as a final verdict.

Source: Joint Advisory AA24-038A: PRC State-Sponsored Actors and U.S. Critical Infrastructure, February 7, 2024

Draw the route to the essential service

For an infrastructure operator, begin with a concrete service and identify the systems that support it. Trace the business systems, remote access arrangements, engineering workstations, and administrative relationships that can affect the service. The purpose is to reveal consequential connections, including those that exist for maintenance or emergencies and may receive less everyday attention.

In a hypothetical pumping operation, a contractor’s support path may be more important to review than an ordinary office application. The assessment should establish what the contractor can reach, who authorizes access, and whether that path can be disabled without losing visibility into the process. This is an illustrative review scenario, not a description of a victim identified in the advisory.

Source: Joint Guidance: PRC State-Sponsored Cyber Activity, Actions for Critical Infrastructure Leaders, March 2024

Ask what evidence would survive

Persistent access is difficult to assess when the organization cannot reconstruct relevant actions. The February advisory recommended centralized logging alongside other mitigations. A practical follow-up is to verify which important events actually reach the protected logging system and how long they remain useful. A logging setting that appears enabled is weaker evidence than a demonstrated record of the activity defenders need to understand.

For the pumping example, conduct a controlled administrative task and inspect the resulting records. Can the team identify the account, destination, action, and relevant time? Can another team correlate those records without relying on memory? Document blind spots and prioritize those that affect important access paths. Collecting more data is useful only when the data can answer a consequential question.

Source: Joint Advisory AA24-038A: PRC State-Sponsored Actors and U.S. Critical Infrastructure, February 7, 2024

Make leadership own the operating trade-offs

The March 2024 companion guidance for critical-infrastructure leaders framed the issue as a business risk and called for informed organizational action. That is a useful reminder that system owners cannot resolve every dependency through a configuration change. Maintenance constraints, procurement, staffing, and the ability to operate during an incident all require decisions beyond the security team.

A leadership exercise can ask what service would be reduced if a suspicious access path had to be isolated. Who decides, what evidence supports the choice, and what alternatives exist? The hypothetical operator might discover that an emergency procedure depends on the same identity system under investigation. Finding that dependency during planning creates an opportunity to improve it before a real response.

Source: Joint Guidance: PRC State-Sponsored Cyber Activity, Actions for Critical Infrastructure Leaders, March 2024

Turn concern into a tested boundary

Select a small number of high-consequence paths and establish whether their controls work. Verify authorized access, denial of unnecessary access, visibility into administrative changes, and the procedure for withdrawing authority. Any testing that touches operational systems needs coordination with the responsible operators and must fit the environment’s safety constraints. The aim is evidence of a boundary, not disruption created by the assessment itself.

The enduring value of the 2024 warning is the shift from asking only whether a service is working to asking whether the organization understands who could affect it. A quiet network can still contain consequential access. A useful defensive program makes that access explainable, observable, and removable while maintaining the ability to deliver essential services under difficult conditions.

Source: Joint Guidance: PRC State-Sponsored Cyber Activity, Actions for Critical Infrastructure Leaders, March 2024

Sources & further reading

  1. Joint Advisory AA24-038A: PRC State-Sponsored Actors and U.S. Critical Infrastructure, February 7, 2024
  2. Joint Guidance: PRC State-Sponsored Cyber Activity, Actions for Critical Infrastructure Leaders, March 2024

Factual statements are grounded in the linked material. Interpretation and illustrative examples are Byte Watchr analysis. Vendor claims are identified as claims, rather than independent testing.

This article belongs to Byte Watchr’s launch collection. The edition date organizes evergreen coverage and does not imply historical publication. Actual publication is recorded above.

Corrections policy · About this byline