# FBI Warns Volt Typhoon Threatens US Infrastructure

Published: 2024-04-18 · Severity: high · Sectors: energy, telecommunications, infrastructure, government-national, transportation
Canonical: https://vorant.io/reports/a479d5b4-ff32-5f07-992f-015e27ada2e3/fbi-warns-volt-typhoon-threatens-us-infrastructure

> FBI Director Wray warns Chinese state-sponsored hackers, including Volt Typhoon, have pre-positioned in US critical infrastructure networks for potential future disruption.

FBI Director Christopher Wray, speaking at the Vanderbilt Summit on Modern Conflict and Emerging Threats, described the Chinese government's cyber activity against U.S. critical infrastructure as broad and unrelenting. He cited historical examples including 2011 reconnaissance against 23 pipeline operators, the 2021 Microsoft Exchange Server mass-exploitation campaign that deployed webshells across numerous sectors, and the more recent Volt Typhoon intrusions into telecommunications, energy, water, and other infrastructure networks, which the FBI assessed as pre-positioning for potential future disruptive attacks tied to tensions over Taiwan.

Wray detailed FBI-led disruption efforts, including a court-authorized operation with Microsoft to remove webshells from compromised Exchange servers, and a separate court-authorized operation to remove Volt Typhoon malware from infected routers and sever the actor's control of that botnet. He also referenced the SolarWinds supply-chain compromise as an example of hardware/software supply chain risk requiring vendor vetting.

The remarks are primarily a policy and awareness speech emphasizing public-private partnership, incident reporting, and resiliency planning rather than a new technical disclosure. No new indicators of compromise or vulnerabilities were disclosed; the piece reiterates known campaigns (Volt Typhoon, Exchange webshell attacks, SolarWinds) as illustrative examples of the sustained Chinese state-sponsored threat to U.S. critical infrastructure sectors.

## Mentioned in this report

- Threat actors: Volt Typhoon
- Malware: Volt Typhoon malware
- Campaigns: Microsoft Exchange Server hack (2021), SolarWinds supply chain compromise, Volt Typhoon

Source reporting: https://www.fbi.gov/news/stories/chinese-government-poses-broad-and-unrelenting-threat-to-u-s-critical-infrastructure-fbi-director-says

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a479d5b4-ff32-5f07-992f-015e27ada2e3/fbi-warns-volt-typhoon-threatens-us-infrastructure.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
