Skip to main content
Back to Threat Watch
Threat Intelligence

China-Linked Threats to Critical Infrastructure

Published Updated

Government advisories describe distinct China-linked campaigns against critical infrastructure and telecommunications. They deserve attention without assuming that every organization has been targeted or that every compromised provider exposes all customer communications.

This article draws on the February 2024 Volt Typhoon advisory and December 2024 communications-infrastructure guidance. It is a dated perspective, not a statement of the latest campaign activity.

Two campaigns, different contexts

The joint Volt Typhoon advisory describes compromises of U.S. critical infrastructure, including communications, energy, transportation, and water and wastewater systems. It documents the use of legitimate tools and valid accounts to blend into ordinary activity, often called living off the land, and assesses that the actors were pre-positioning for possible disruption.

The December 2024 joint communications guidance describes PRC-affiliated actors compromising major telecommunications providers for espionage. It recommends improving visibility and hardening network infrastructure. The affected systems and access determine the consequences; provider compromise alone does not establish the exposure of every customer's traffic.

Review the access your organization depends on

For a utility, agency, contractor, or enterprise, a useful question is which systems and outside relationships could provide access to sensitive work. Review remote administration, service-provider accounts, and connections between ordinary business systems and critical operations.

Use the advisories to inform a review of your environment. Avoid treating all China-linked activity as one campaign or interpreting a sector warning as proof that your own systems were compromised.

Practical defensive priorities

1. Make logs useful to responders. Confirm that relevant authentication, administration, and network activity is recorded, retained, and accessible to the team responsible for investigation. Choose logging settings with that team rather than assuming that enabling a single feature provides coverage.

2. Restrict management access. Keep infrastructure administration on controlled paths and remove unnecessary internet exposure. Review who can reach those paths and which accounts can change configurations.

3. Enforce network boundaries. Separate sensitive systems and permit only the communications they need. VLAN labels alone do not establish isolation; verify the access rules and permitted routes.

4. Review privileged and vendor accounts. Remove obsolete access, limit privileges, and use appropriately protected authentication. Agree on how temporary vendor access is approved, monitored, and removed.

5. Maintain a response plan. Know who investigates suspicious activity and how to contact relevant government or sector resources. Follow the advisory's incident guidance if evidence indicates a compromise.

These measures support defense against the documented techniques. They also require ongoing operation, testing, and a team that can act on the information collected.

Get the next issue in your inbox

Harborcoat Threat Watch sends concise cybersecurity analysis for business and IT leaders when there is something worth your time.

More from Threat Watch