Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Cyber Tactics
    • Leadership & Management
    • Security Talk
    • Career Intelligence
    • Leader to Leader
    • Cybersecurity Education & Training
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
    • Podcasts
    • Polls
    • Photo Galleries
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Continuing Education
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecurityManagementLogical SecuritySecurity & Business Resilience

Living off the land in a victim’s network

By Matt Malarkey
Light blue connections

Image via Unsplash

May 31, 2024

In January of this year, the directors of the United States Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA) and Federal Bureau of Investigation (FBI) appeared before a committee on Capitol Hill. During their testimonies, they attested to the present and growing cyber threat that Chinese state-sponsored cyber attackers, such as Volt Typhoon, pose to U.S. critical national infrastructure (CNI) — primarily communications, energy, transportation systems and water and wastewater systems sectors. 

The directors emphasized how Volt Typhoon’s choice of targets and pattern of behavior has not been consistent with traditional cyber espionage or intelligence gathering operations. Rather, the U.S. government officials believe that this surreptitious actor is simply pre-positioning themselves on CNI IT networks and waiting to exploit their access through lateral movement to OT assets to disrupt critical infrastructure during military conflicts or geopolitical tensions. 

Despite sophisticated threat and detection tools, such cyber adversaries have proven that they are able to establish and maintain a presence on a victim’s network for extended periods of time. One CNI organization was said to have been compromised for over five years unbeknownst to the network owner before finally being discovered. So, how can malicious cyber actors remain undetected for so long? 

According to a recent U.S. government advisory, one of the primary tactics, techniques, and procedures (TTPs) used by cyber attackers like Volt Typhoon to establish and sustain a clandestine presence in a network is living off the land (LOTL). It’s an effective technique that requires a strong focus on stealth that allows the adversary to maintain long-term, undiscovered persistence on a victim network.

LOTL uses built-in network administration tools that enable the attacker to evade detection by blending in with normal system and network activities, avoiding endpoint detection and response (EDR) products, and limiting the amount of activity that is captured in default logging configurations. So, the challenge for the network defender is that many of the behavioral indicators of LOTL can also be legitimate system administration commands that appear in benign activity. 

Additionally, many organizations do not implement security and network management best practice capabilities — such as established baselines — that support detection of such malicious LOTL activity. This makes it even harder for network defenders to discern legitimate behavior from malicious behavior.

Volt Typhoon typically targets and gains initial access to a victim’s network through network infrastructure devices, especially internet-connected ones — for example, firewalls and routers. Which is why the advisory recommends using tools and technology that helps detect anomalies that could represent an IOC in these devices. 

They are targeted because they are the backbone of a network, and they are where threat actors can escalate their privileges and then proliferate across a network enterprise. For these devices, any changes to their configurations could be representative of malicious activity which would not necessarily trigger alerts in typical security solutions. But, considering importance of secure and segmented infrastructure to the overall resilience of the enterprise, all of these changes should be analyzed to firstly determine whether or not they were planned or unplanned — the latter being a potential IOC — and then proactively assessed to determine whether these changes have introduced new vulnerabilities.

Hardening the network can stop or limit LOTL TTPs

Although it’s critical to detect potential IOCs that could represent the possible presence of an adversary utilizing the LOTL approach, it is equally important to harden and ensure the resilience of the network — both to prevent the adversary from infiltrating in the first place and to also limit their ability to move laterally within the network should they be successful in gaining access. For this reason, additional attention should be focused on network infrastructure appliances. 

For hardening these devices against a LOTL TTP, recently published guidance, developed by the U.S. government alongside several other U.S. agencies and international partners, recommends:

  • Reviewing current configurations against a known, secure baseline. This can catch IOCs that may not get reverted through regular group policy updates, such as firewall changes, adding/removing users, and privilege escalation.
  • Ensuring that device configurations adhere to vendor-provided or industry, sector, or government (e.g., U.S. National Institute of Standards and Technology (NIST)) hardening guidance to reduce the attack surface.
  • Properly implementing and managing network segmentation, limiting only allowed traffic to systems and protocols that require access, in accordance with zero trust principles.

Continuous monitoring is key

Assessing network infrastructure intermittently, or worse, sampling a subset of devices, to draw conclusions for the security posture of all devices in the enterprise is a flawed approach. This has been the way that some CNI organizations have assessed their routers, switches and firewalls. But it is simply insufficient for critical infrastructure, which is increasingly being targeted by the most sophisticated cyber attackers, to harden their networks or detect the presence of an adversary in this way. 

This is why CNI organizations should adopt technology solutions that continuously monitor for configuration change across all network appliances in the enterprise. Any unplanned changes to device configurations, even if they appear to be benign in nature, could be a sign of compromise and should be reviewed to ensure segmentation fidelity remains as intended. Even better, these solutions should proactively assess any configuration changes against trusted hardening benchmarks to alert to any new vulnerabilities or identify any misconfigurations that could be exploited in the future. Without this continuous and proactive approach to configuration security, threat actors like Volt Typhoon will continue to leverage weaknesses in network infrastructure, use LOTL to blend into normal network activity and reconfigure these devices to enable their proliferation and to strategically preposition themselves for future attacks on U.S. critical national infrastructure. 

KEYWORDS: detecting cyber vulnerabilities network network monitoring network security threat landscape

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Matt malarkey headshot

Matt Malarkey is VP, Strategic Alliances at Titania. Image courtesy of Malarkey

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Security's Top Cybersecurity Leaders 2024

    Security's Top Cybersecurity Leaders 2024

    Security magazine's Top Cybersecurity Leaders 2024 award...
    Top Cybersecurity Leaders
    By: Security Staff
  • cyber brain

    The intersection of cybersecurity and artificial intelligence

    Artificial intelligence (AI) is a valuable cybersecurity...
    Logical Security
    By: Pam Nigro
  • artificial intelligence AI graphic

    Assessing the pros and cons of AI for cybersecurity

    Artificial intelligence (AI) has significant implications...
    Logical Security
    By: Charles Denyer
Manage My Account
  • Security eNewsletter & Other eNews Alerts
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Sureview screen
    Sponsored bySureView Systems

    The Evolution of Automation in the Command Center

  • Crisis Response Team
    Sponsored byEverbridge

    Automate or Fall Behind – Crisis Response at the Speed of Risk

  • Perimeter security
    Sponsored byAMAROK

    Why Property Security is the New Competitive Advantage

Popular Stories

Rendered computer with keyboard

16B Login Credentials Exposed in World’s Largest Data Breach

Verizon on phone screen

61M Records Listed for Sale Online, Allegedly Belong to Verizon

Security’s 2025 Women in Security

Security’s 2025 Women in Security

blurry multicolored text on black screen

PowerSchool Education Technology Company Announces Data Breach

Half closed laptop

Sudo Vulnerability Discovered, May Exposes Linux Systems

Events

August 7, 2025

Threats to the Energy Sector: Implications for Corporate and National Security

The energy sector has found itself in the crosshairs of virtually every bad actor on the global stage.

August 27, 2025

Risk Mitigation as a Competitive Edge

In today’s volatile environment, a robust risk management strategy isn’t just a requirement—it’s a foundation for organizational resilience. From cyber threats to climate disruptions, the ability to anticipate, withstand, and adapt to disruption is becoming a hallmark of industry leaders.

View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Related Articles

  • Stranger in a Strange Land: Finding the New Normal of Security Culture - Security Magazine

    Stranger in a Strange Land: Finding the New Normal of Security Culture

    See More
  • SEC0720-Cyber-Feat-slide1_900px

    Zero trust further considered - another benefit of living in the times of AI

    See More
  • Security newswire default

    Living with Terrorism in the US: How Americans are Adapting

    See More

Related Products

See More Products
  • Physical-Security-and-Safet.gif

    Physical Security and Safety: A Field Guide for the Practitioner

  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

  • intelligent.jpg

    Intelligent Network Video: Understanding Modern Video Surveillance Systems, Second Edition

See More Products
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • eNewsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2025. All Rights Reserved BNP Media.

Design, CMS, Hosting & Web Development :: ePublishing