Chinese Hackers Plant 'Digital Bombs' in US Critical Infrastructure
The state-sponsored group Volt Typhoon has infiltrated water, energy, and transport sectors to prepare for destructive attacks during future conflicts.
The Chinese state-sponsored hacking group Volt Typhoon has spent years infiltrating U.S. critical infrastructure to prepare for potential destructive attacks. This strategic pre-positioning targets essential sectors, including water, energy, and transportation, creating a dormant threat that could be triggered during a geopolitical crisis.
According to CISA and the FBI, the group has been active since at least mid-2021. To remain undetected, Volt Typhoon employs "living off the land" (LotL) techniques, which involve using built-in network administration tools such as PowerShell and wmic rather than deploying custom malware that security software typically flags. To further mask the People's Republic of China (PRC) origin of its traffic, the group utilized a botnet consisting of hundreds of compromised U.S.-based small office/home office (SOHO) routers, specifically targeting end-of-life Cisco RV320 and Netgear ProSafe devices.
The Potential for Physical Chaos
While traditional cyber espionage focuses on the theft of intellectual property or state secrets, the objectives of Volt Typhoon have shifted toward physical disruption. A simulated war game reported by journalist Andy Greenberg involving insurance executives illustrated the catastrophic potential of these intrusions. The simulation revealed that a coordinated cyberattack on water utilities could result in burst water mains and the forced evacuation of hospitals.
CISA Director Jen Easterly warned that these actors are "burrowing deep into our critical infrastructure to be ready to launch destructive cyber-attacks in the event of a major crisis or conflict with the United States." FBI Director Christopher Wray echoed this urgency, stating that these cyber threats represent "real-world threats to our physical safety."
A Shift in Cyber Warfare
This activity represents a fundamental shift toward the deployment of "digital bombs"—dormant access points designed to incite chaos and panic within the U.S. population. By crippling essential services, the PRC aims to deter the United States' ability to respond militarily or politically during a conflict, particularly in the Asia-Pacific region.
The risk is amplified by the inherent vulnerability of civilian infrastructure. Many local utilities are underfunded and rely on outdated hardware, creating significant national security gaps that state-sponsored actors can exploit to bypass modern defenses.
The Path Forward
U.S. agencies continue to monitor the extent of the infiltration, though the use of LotL techniques makes complete eradication difficult. The primary focus for security professionals has shifted toward hunting for these stealthy footprints and hardening the legacy systems that manage the nation's most basic necessities. What remains to be seen is how quickly local utility providers can update their aging infrastructure before these dormant access points are activated.