Talos Intelligence Details State-Sponsored Actors Targeting Critical Infrastructure OT Systems Using Living-Off-the-Land Techniques
Cisco
Per Cisco Talos alone, state-sponsored actors using valid credentials and native tools have inverted the core defensive assumption: no malware signature is not evidence of no intrusion. Volt Typhoon's documented peacetime pre-positioning means OT defenders lacking the logging architecture Talos specifies, including process creation, PowerShell script block, Sysmon, and NetFlow, cannot determine whether persistent access already exists. Salt Typhoon's penetration of lawful intercept systems makes the sharper point: where access is the collection, there is no action phase that crosses conventional detection thresholds. The same techniques are equally prevalent in criminal ransomware, and the report may overstate actor sophistication in ways that delay triage of commodity threats.
2 sources
- State-sponsored actors better known as the friends you dont want -
Cisco Talos Intelligence - State-sponsored actors, better known as the friends you don't want -
Cisco Blogs