Adversary Intelligence — 2026-05-14

Talos Intelligence Details State-Sponsored Actors Targeting Critical Infrastructure OT Systems Using Living-Off-the-Land Techniques

Cisco Talos Intelligence published a report on May 12 detailing how state-sponsored actors use valid credentials and native administrative tools, including PowerShell, WMI, and PsExec, to maintain persistent access inside targeted networks without deploying custom malware. The report cites CISA's prior assessment that Volt Typhoon pre-positioned access within U.S. critical infrastructure during peacetime and notes that Salt Typhoon accessed lawful intercept systems, deriving intelligence value from the access itself without taking disruptive action. Talos specifies logging requirements, including Windows process creation and PowerShell script block logging, Sysmon deployment, and NetFlow analysis, as necessary preconditions for detecting this activity. The report also recommends OT network segmentation, CISA-aligned behavioral baselines, and zero trust architecture as pre-incident defensive requirements.

Analysis
Per Cisco Talos alone, state-sponsored actors using valid credentials and native tools have inverted the core defensive assumption: no malware signature is not evidence of no intrusion. Volt Typhoon's documented peacetime pre-positioning means OT defenders lacking the logging architecture Talos specifies, including process creation, PowerShell script block, Sysmon, and NetFlow, cannot determine whether persistent access already exists. Salt Typhoon's penetration of lawful intercept systems makes the sharper point: where access is the collection, there is no action phase that crosses conventional detection thresholds. The same techniques are equally prevalent in criminal ransomware, and the report may overstate actor sophistication in ways that delay triage of commodity threats.
2 sources
  1. State-sponsored actors better known as the friends you dont want - Cisco Talos Intelligence
  2. State-sponsored actors, better known as the friends you don't want - Cisco Blogs

View in full brief →

UNCLASSIFIED // OPEN SOURCE