Microsoft and U.S. officials said China-linked threat groups Volt Typhoon and Flax Typhoon used living-off-the-land techniques and legitimate software to quietly compromise targets while minimizing detection. Volt Typhoon was tied to intrusions affecting U.S. critical infrastructure, with reporting describing the group as breaching networks through stealthy post-compromise activity rather than malware-heavy tradecraft. U.S. agencies later warned that the campaign appeared aimed at pre-positioning inside critical infrastructure for potential disruptive or destructive operations.
Microsoft separately reported that Flax Typhoon targeted organizations in Taiwan for cyber-espionage, relying on valid credentials, remote access tools, and other trusted utilities to maintain persistence and blend into normal network activity. Subsequent reporting and later tracking indicated that Volt Typhoon remained active against U.S. infrastructure, reinforcing concerns that Chinese state-linked operators are sustaining long-term access across strategically important environments while using native tools and legitimate software to evade defenders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
A 2026 analysis said Volt Typhoon was still active in U.S. critical infrastructure, indicating the campaign had persisted beyond the initial 2023 disclosures. The report framed the threat as ongoing rather than historical, underscoring continued concern about long-term access and resilience risks.
U.S. authorities warned that China-linked hackers associated with Volt Typhoon were pre-positioning in critical infrastructure networks to enable potential disruptive or destructive attacks during a future crisis. The warning marked an escalation from earlier public reporting focused primarily on stealthy access and espionage.
Follow-on reporting summarized Microsoft's disclosure that Flax Typhoon used legitimate tools for cyber-espionage against Taiwanese organizations. The reports emphasized the actor's reliance on living-off-the-land techniques and legitimate remote access software to reduce visibility.
Microsoft disclosed a separate China-linked espionage group, Flax Typhoon, describing its use of legitimate software and quiet access methods against organizations in Taiwan. The company said the actor focused on espionage and persistence while blending into normal administrative activity.
Media reporting on the same day highlighted Microsoft's findings that Chinese hackers had breached U.S. critical infrastructure networks in stealthy attacks. The coverage reinforced that the campaign relied on built-in tools and compromised small office/home office network equipment to evade detection.
Microsoft reported that the China-linked threat actor Volt Typhoon had targeted U.S. critical infrastructure organizations and used living-off-the-land techniques to maintain stealthy access. The activity was described as focused on espionage and persistence across sectors including communications, manufacturing, utilities, transportation, construction, maritime, government, information technology, and education.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
cybelangel.com
Open sourcetherecord.media
Open sourcehackread.com
Open sourcemicrosoft.com
Open sourcemicrosoft.com
Open sourcebleepingcomputer.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.