Saudi Press

Saudi Arabia and the world
Monday, Mar 23, 2026

China state-sponsored actor carries out 'attack' on US critical infrastructure, Microsoft says

China state-sponsored actor carries out 'attack' on US critical infrastructure, Microsoft says

Microsoft says that Volt Typhoon is a state-sponsored actor of the PRC

China state-sponsored cyber actor Volt Typhoon is targeting critical infrastructure organizations in the U.S., according to Microsoft.

Microsoft warned Wednesday that Volt Typhoon, a cyber actor linked to the People's Republic of China, is targeting critical infrastructure organizations in the U.S.


Microsoft said in a Wednesday post that the company has "uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States."

"The attack is carried out by Volt Typhoon," Microsoft said. Volt Typhoon is a Chinese state-sponsored actor that focuses on "espionage and information gathering."

"Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises," the statement reads.

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) and international cybersecurity authorities issued a joint Cybersecurity Advisory (CSA) warning the agencies believe Volt Typhoon, which they noted is associated with the People's Republic of China, "could apply the same techniques" against infrastructure networks across the U.S. and "other sectors worldwide."

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) acknowledged it is aware of Volt Typhoon's activities threatening U.S. critical infrastructure organizations and issued warning along with international cybersecurity authorities.


The CSA explained Volt Typhoon's primary tactics, techniques and procedures (TTPs) is "living off the land," which allows it to avoid detection by using built-in network administration tools to blend in with normal Windows systems and fly under the radar of third-party endpoint detection and response products.

The agencies recommend organizations take steps to tighten up their cybersecurity in light of the threat, such as hardening domain controllers, monitoring event logs, limiting port proxy usage, investigating any unusual IP addresses and reviewing firewall configurations.

Newsletter

Related Articles

Saudi Press
0:00
0:00
Close
Trump to Deliver Keynote Address at Saudi-Backed Investment Summit in Miami Beach
Saudi Arabia and Kuwait Press Ahead With Energy Agreements Despite Regional Conflict
Can Saudi Arabia’s Yanbu Port Replace Hormuz? Capacity Limits Test Critical Oil Lifeline
Saudi Arabia Detects Ballistic Missiles as Regional Tensions Escalate in Gulf
Saudi Aramco Reduces Oil Shipments to Asia for Second Consecutive Month
Saudi Aramco Reduces Oil Shipments to Asia for Second Consecutive Month
Saudi Arabia and UAE Push Ahead With Major Deals Despite Iran-Related Uncertainty
Formula One Cancels Bahrain and Saudi Arabia Grands Prix Amid Escalating Regional Tensions
Pakistan Signals Strategic Realignment Toward Saudi Arabia Amid Regional Tensions
Saudi Arabia Cuts Oil Shipments to Asia as Regional Conflict Disrupts Key Export Routes
Saudi Arabia Moves to Contain Regional Escalation as Houthis Signal Readiness to Join Conflict
Saudi Arabia Signals Independent Nuclear Strategy Unaffected by Iran Tensions
Saudi Arabia Signals Independent Nuclear Strategy Unaffected by Iran Tensions
Egypt Reaffirms Strong Support for Saudi Arabia as Sisi Condemns Iran’s Gulf Attacks
Saudi Stocks Close Higher as Tadawul Index Gains 0.55% on Broad Sector Strength
Iran Fires Ballistic Missiles Toward Riyadh as Gulf Conflict Intensifies
Barcelona Midfielder Marc Casadó Attracts €40 Million Interest from Saudi Clubs
Strait of Hormuz Tensions Rise as Saudi Arabia Opens Key Air Base to US Forces
Saudi Arabia Confronts Strategic Turning Point as Iran Conflict Redefines Regional Alliances
Saudi Arabia Intercepts Missile as Two Others Land in Remote Area Without Casualties
Saudi Expulsion of Iranian Military Attaché Raises Doubts Over Fragile Riyadh–Tehran Rapprochement
Saudi Arabia’s Strategic East–West Pipeline Gains Global Attention as Energy Routes Face Growing Risks
Iran Reportedly Reduces Strikes on Saudi Arabia Amid Concerns Over Strong Retaliation
Saudi Arabia Criticises Israeli Strikes in Southern Syria Amid Rising Regional Tensions
Egypt and Saudi Arabia Warn Iran’s Actions Threaten Stability Across the Gulf
Egypt and Saudi Arabia Warn Iran’s Actions Threaten Stability Across the Gulf
Saudi Arabia Unveils Comprehensive 2026 Roadmap to Streamline Company Formation
Saudi-UAE Tensions Reveal Emerging Rivalry at the Heart of Gulf Power Dynamics
Saudi Arabia Launches Gulf Maritime Support Initiative to Safeguard Shipping
Saudi Arabia Expands US Military Access as UAE Braces for Prolonged Iran Conflict
Saudi Arabia Expels Iranian Diplomats Amid Escalating Regional Tensions
Saudi Arabia’s Edarat Wins Major Data Centre Deal with Regional Bank
Iran Intensifies Gulf Offensive as Saudi Arabia Intercepts Dozens of Drones
Regional Powers Hold Security Talks as Turkey Seeks New Strategic Pact
Asian Refiners Urge Saudi Arabia to Revise Oil Pricing Mechanism Amid War-Driven Volatility
Gulf States Weigh US Base Access and Military Alignment as Iran War Intensifies
IRGC Claims Strikes on Israel, Kuwait and Saudi Arabia as Conflict Widens
Remains of Fallen Soldier Repatriated Following Death in Saudi Arabia
Saudi Arabia Intercepts Multiple Drones Amid Continued Iranian-Linked Attacks
Iran Tensions Challenge Saudi Arabia’s Strategic Shift to Red Sea Oil Exports
Saudi Arabia Turns to Alternative Export Routes as Hormuz Disruption Strains Oil Flows
Saudi Arabia and UAE Move Closer to Backing US-Israeli Campaign Against Iran
Saudi Arabia Signals Readiness for Military Response as Iran Tensions Escalate
Saudi Arabia Warns Oil Could Surge Beyond $180 as Iran Conflict Disrupts Global Supply
Saudi Arabia Reports Drone Strike on Key Red Sea Refinery in Yanbu
United States Urges Citizens to Leave Saudi Arabia Amid Escalating Regional Conflict
Former Media Executive Chronicles Rise of Saudi Crown Prince in New Book
Saudi Aramco–Exxon Refinery in Yanbu Targeted in Latest Wave of Iranian Attacks
Greek-Operated Patriot System Intercepts Iranian Missiles Over Saudi Arabia
Asian Refiners Urge Saudi Arabia to Revise Oil Pricing as War Upends Markets
×