Desk live·
ForensicPost
Nation-state/Infrastructure/File 23-0524

Five Eyes Advisory Says a PRC Actor Is Living off the Land Inside Critical Infrastructure

No malware to find, because the tooling was Windows itself. The May 2023 advisory described an actor using built-in administrative utilities to hold quiet access across communications, energy, transport and water — and said the point was to be there later, not to act now.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetUS critical infrastructure
ActorVolt Typhoon
D. Kennedy12 min readConfidence: high2 sources reviewed

In May 2023 CISA, the NSA and the FBI, together with partner agencies in Australia, Canada, New Zealand and the United Kingdom, published a joint advisory on activity attributed to a People’s Republic of China state-sponsored actor tracked as Volt Typhoon.

The advisory describes the actor living off the land — using utilities already present on Windows systems rather than deploying tooling of its own — across critical infrastructure including communications, energy, transportation and water and wastewater systems.

There Is Nothing To Detect

Every detection approach in this database assumes something arrives: a file, a process, a connection to somewhere unusual. Living off the land removes that assumption. The commands are administrative commands, run by administrative accounts, on systems where administrators run them daily.

The corpus records the same evasion problem in commercial form at 25-0421b, where adversaries logged in with valid credentials in 56% of engagements. Here it is a deliberate operational doctrine rather than a convenience.

Pre-Positioning Is Not An Attack

The advisory’s framing is that the access is being maintained for potential disruption during a future crisis. That makes this the only file in this database where the recorded harm is entirely prospective.

The desk has thought carefully about how to grade that. Nothing was destroyed, no data is established as taken, and no service was interrupted. It is recorded SEV 5 because severity in this corpus tracks the harm the position enables, and the position is inside the systems that deliver water and power.

Water Enters The Database Here

The water and wastewater sector appears in this advisory as a named target, and the corpus goes on to record actual disruption at 23-1125 in Pennsylvania and 26-0727 in Minnesota, and federal guidance at 26-0729.

Read in sequence, those files describe a sector that was warned first, attacked second and given device-level guidance third. The warning preceded the incidents by two and a half years.

How we reported this

Built on the joint CISA/NSA/FBI and Five Eyes advisory and contemporaneous reporting of it. The attribution to a PRC state-sponsored actor, the living-off-the-land tradecraft, the named utilities and the sector list are the advisory’s. The characterisation of the activity as pre-positioning for disruption during a crisis is the advisory’s assessment, reported as such and not independently established by this desk. No victim organisations are named: the advisory does not name them. Later advisories extended this reporting; this file records the May 2023 position and does not backfill later findings into it. No indicators are reproduced — the advisory carries them and is linked. Graded high. Corrections: corrections@forensicpost.com.

Sources
  1. Agencies Warn of State-Sponsored Volt Typhoon’s Hacking TacticsNextgov/FCW
  2. Five Eyes Joint Advisory on Chinese State-Sponsored Threat Actor Volt TyphoonInfoblox
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary