Security News OT Attacks on US Critical Infrastructure Could Disrupt Military Operations and Physical Processes

Brownie2019

Level 23
Verified
Well-known
Forum Veteran
US critical infrastructure faces an operational technology threat that extends beyond civilian service outages.

State-sponsored intrusions and direct attacks on industrial controllers could disrupt physical processes and undermine military operations by targeting electricity, water, telecommunications, transportation, fuel, manufacturing, and logistics providers outside installation boundaries.

Disabling a supporting utility or transportation system could interrupt essential services, constrain logistics, or complicate mobilization, making infrastructure resilience a national-security concern.

China’s Volt Typhoon illustrates the strategic dimension. In their joint advisory, CISA, NSA, and FBI assess with high confidence that the actor is pre-positioning inside critical infrastructure IT networks to enable subsequent disruption of OT functions during a potential crisis or conflict.

Confirmed compromises span communications, energy, transportation, and water systems, including Guam.

Volt Typhoon attack exploits public-facing network appliances, uses valid administrative credentials, and relies on living-off-the-land techniques rather than conspicuous malware.
Read more:
 
Read more: (link omitted)


Hi Brownie2019. The strategic point is sound: an attacker does not need to breach a military installation directly if it can interrupt the civilian power, communications, fuel, water or transport services on which that installation depends.

One important evidence boundary is worth preserving. The joint CISA/NSA/FBI advisory confirms Volt Typhoon compromises in critical-infrastructure IT environments, including Guam, and assesses with high confidence that the group is pre-positioning for movement toward OT and possible disruption during a crisis. That is strong evidence of preparation and capability, but it is not public proof that Volt Typhoon has already manipulated industrial controllers or caused a physical outage.

The reliance on valid credentials and “living off the land” makes this particularly awkward to detect. PowerShell, RDP, WMI and ordinary administration tools are not inherently malicious, so searching only for malware files or antivirus alerts misses much of the problem.

For operators, the priorities should be:

  • Remove direct internet exposure from PLCs, HMIs and engineering workstations.
  • Broker remote access through monitored gateways or jump hosts, with phishing-resistant MFA and time-limited privileges.
  • Enforce tightly controlled IT-to-OT conduits rather than treating segmentation as a line on a network diagram.
  • Hunt for unusual administrative logins, VPN sessions, RDP movement and collection of network or engineering documentation.
  • Maintain tested offline copies of controller logic, configurations and recovery procedures.
  • Exercise manual operation and continuity plans with external utilities and logistics providers—not merely internal cyber-response plans.

CISA’s secure OT connectivity principles are relevant here. The uncomfortable lesson is that resilience must follow the operational dependency chain beyond the organization’s own perimeter; the attacker is unlikely to respect the neat boxes on an ownership chart.

Sources
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top