Saudi Press

Saudi Arabia and the world
Saturday, Mar 07, 2026

China state-sponsored actor carries out 'attack' on US critical infrastructure, Microsoft says

China state-sponsored actor carries out 'attack' on US critical infrastructure, Microsoft says

Microsoft says that Volt Typhoon is a state-sponsored actor of the PRC

China state-sponsored cyber actor Volt Typhoon is targeting critical infrastructure organizations in the U.S., according to Microsoft.

Microsoft warned Wednesday that Volt Typhoon, a cyber actor linked to the People's Republic of China, is targeting critical infrastructure organizations in the U.S.


Microsoft said in a Wednesday post that the company has "uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States."

"The attack is carried out by Volt Typhoon," Microsoft said. Volt Typhoon is a Chinese state-sponsored actor that focuses on "espionage and information gathering."

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the statement reads.

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) and international cybersecurity authorities issued a joint Cybersecurity Advisory (CSA) warning the agencies believe Volt Typhoon, which they noted is associated with the People's Republic of China, "could apply the same techniques" against infrastructure networks across the U.S. and "other sectors worldwide."

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) acknowledged it is aware of Volt Typhoon's activities threatening U.S. critical infrastructure organizations and issued warning along with international cybersecurity authorities.


The CSA explained Volt Typhoon's primary tactics, techniques and procedures (TTPs) is "living off the land," which allows it to avoid detection by using built-in network administration tools to blend in with normal Windows systems and fly under the radar of third-party endpoint detection and response products.

The agencies recommend organizations take steps to tighten up their cybersecurity in light of the threat, such as hardening domain controllers, monitoring event logs, limiting port proxy usage, investigating any unusual IP addresses and reviewing firewall configurations.

Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
U.S. Justice Department Pursues Criminal Cases Against Cuban Officials in New Legal Push
Abrupt Cancellation of U.S. Army Exercise Sparks Speculation Over Possible Middle East Deployment
Saudi Arabia Led OPEC Output Surge Ahead of Iran Strikes, Survey Finds
Cristiano Ronaldo Travels to Spain for Hamstring Treatment After Injury in Saudi Pro League Match
Saudi Aramco Reroutes Oil to Red Sea as Strait of Hormuz Disruptions Hit Gulf Exports
Saudi Arabia Presses Ahead With Economic Diversification Despite Fiscal and External Deficits
Middle East Conflict Puts Bahrain and Saudi Arabian Formula One Races at Risk
Iran Targets Israeli Diplomatic Site in Bahrain and US Air Base in Qatar as Regional Conflict Expands
Saudi Arabia Intercepts Three Ballistic Missiles Targeting Prince Sultan Air Base
Iran Launches Fresh Missile and Drone Attacks Across Middle East as Regional War Intensifies
Saudi Arabia Opens Direct Communication Channel With Iran in Bid to Prevent Wider Regional War
Saudi Arabia Maintains Strong Fiscal Position Despite Global Uncertainty, Finance Ministry Says
Saudi Arabia Considers Response After Iranian Drone Strike Hits Major Northern Oil Refinery
Saudi Carrier Flynas Plans Limited Flight Resumption to Dubai Amid Regional Tensions
Saudi Arabia and UAE Pledge Close Coordination to Secure Oil Supplies for Japan
Middle East Conflict Casts Doubt Over Bahrain and Saudi Arabian Formula One Races
Iran Rejects Claims of Attacks on Türkiye, Azerbaijan, Saudi Arabia and Oman
Saudi Arabia Condemns Iranian Strikes Targeting Türkiye and Azerbaijan
Saudi Pro League Orders Clubs to Continue Matches Despite Escalating Regional Conflict
U.S. Embassy in Riyadh Issues Emergency Security Alert After Drone Strike and Escalating Regional Threats
Saudi Arabia Scrambles to Redirect Oil Exports as Gulf Storage Nears Capacity
Iran Expresses Gratitude to Saudi Arabia for Closing Airspace During Escalating Conflict
Saudi Arabia Fears Iranian Strikes Could Target Senior Leaders as Regional War Escalates
Iran Says Its Strikes Target Only U.S. Military Assets and Denies Attacking Saudi Arabia
Drone Strike Hits U.S. Embassy in Riyadh as Middle East Conflict Escalates
Tom Brady’s Saudi Flag Football Event May Shift to U.S. as Middle East Conflict Disrupts Plans
Iran War Strikes Saudi Arabia at a Critical Moment for Its Economic Transformation
Saudi Cabinet Declares Kingdom Will Take All Necessary Measures to Defend National Security
United States Urges Citizens to Leave Fourteen Middle Eastern Countries as Iran War Escalates
Saudi Aramco’s Ras Tanura Refinery Targeted Again in Second Drone Attack Within Two Days
Saudi Pro League Orders Clubs to Continue Fixtures Despite Rising Middle East Conflict
Trump Pursues Major Civil Nuclear Agreement With Saudi Arabia Amid Regional Turmoil
Mass Drone Attacks Strike Gulf States as Iran Conflict Spreads Across Region
No Verified Confirmation of Ronaldo Departure Linked to Iran Conflict or AFC Suspension
No Verified Evidence of Israeli Intelligence Arrests in Qatar or Saudi Arabia
Drone Attack Forces Temporary Shutdown of Saudi Arabia’s Largest Oil Refinery
Israel Intensifies Air Campaign in Tehran as Iran Expands Regional Retaliation
Iranian Strikes Escalate Middle East Conflict, Drawing Saudi Arabia Closer to Wider War
No Verified Confirmation of Drone Strike on King Fahd Causeway Amid Regional Tensions
No Verified Evidence Saudi Crown Prince Is Seeking to Weaken Israel Amid Regional Tensions
Reports Emerge of Drone Strike Near US Embassy in Saudi Arabia as Americans Told to Shelter
Saudi Arabia Weighs Strategic Options as Tensions With Iran Intensify
Iran Expands Strikes on Saudi and Qatari Infrastructure, Opening a New Front in Gulf Conflict
Western Navies Sound Alarm as Russian Shadow Tankers Transit NATO Waters in Defiance of Sanctions
U.S. Embassy in Riyadh Struck by Drones Amid Escalating Iran Conflict
Imola Emerges as Standby Venue if Bahrain or Saudi Arabia Grands Prix Are Cancelled
Uncertainty Clouds $24 Billion Gulf Investment Linked to Paramount–WBD Deal
Middle East Strikes Disrupt Qatar LNG, Saudi Refining and Israeli Energy Fields
Gulf States Signal Possible Collective Action Over Iran’s Escalating Strikes
Saudi Arabia Summons Iranian Ambassador After Cross-Border Attacks
×