VOLTZITE: A Critical Wake-Up Call for OT Cybersecurity

The VOLTZITE threat group has emerged as a sophisticated adversary targeting critical infrastructure, highlighting the growing urgency for robust cybersecurity in operational technology (OT) environments. This article explores who VOLTZITE is, its operation, and practical strategies to safeguard against its tactics.

Who is VOLTZITE and How Do They Operate?

VOLTZITE, as identified by Dragos, is a highly skilled threat group that overlaps with multiple threat groups: Volt Typhoon (Microsoft), BRONZE SILHOUETTE (Secureworks ), and Vanguard Panda ( CrowdStrike). The group has been Active since at least 2021, VOLTZITE targets critical industries such as electricity, telecommunications, emergency management services, and defense. Their approach prioritizes detection evasion and long-term network persistence.

VOLTZITE uses "living off the land" (LOTL) techniques, relying on native tools within compromised systems to minimize its footprint. The group engages in deliberate reconnaissance, exploits credential theft, and leverages vulnerabilities in widely used tools like VPNs, SOHO routers, and ICS management systems. This has enabled them to exfiltrate sensitive data, including GIS information and SCADA configurations, which could be weaponized for future disruptions.

What CISA Has Found

In May 2023, the U.S. Cybersecurity and Infrastructure Security Agency issued warnings about a similar group known as the Volt Typhoon, which shares operational parallels with VOLTZITE. CISA's analysis underscored the importance of vigilance in protecting IT and OT environments, emphasizing the strategic value adversaries find in GIS data, operational schematics, and other critical OT assets.

Dragos' Key Findings on VOLTZITE

Building on CISA’s insights, Dragos uncovered critical information about VOLTZITE:

  • Industries Impacted: The electric sector, emergency services, telecommunications, and defense are key targets.
  • Tactics and Techniques: The group uses stealthy methods for command-and-control operations, such as web shells and reverse proxies.
  • Global Operations: VOLTZITE's activities extend beyond the U.S., with evidence of African operations.
  • ICS Implications: While they haven't executed Stage 2 ICS Cyber Kill Chain attacks, their exfiltration of sensitive data could facilitate future disruptions.

Why OT Security Must Evolve

Operational technology is the heart of critical infrastructure, from energy grids to emergency response systems. Compromising OT systems can have far-reaching consequences, including service outages and public safety risks. VOLTZITE’s targeting of OT assets underscores the need for organizations to bridge IT and OT security gaps.

The Need for IT-OT Collaboration

VOLTZITE exploits IT networks to access OT assets, emphasizing the interconnectedness of modern infrastructures. IT and OT teams must collaborate on unified security protocols to ensure comprehensive protection. Such alignment enables faster threat detection, efficient incident response, and a stronger overall security posture.

Dragos, Inc. Recommendations

To combat threats like VOLTZITE, Dragos offers the following recommendations:

  • Network Visibility and Monitoring: Deploy protocol-aware tools for continuously monitoring ICS environments.
  • Defensible Architecture: Implement segmentation between IT and OT networks to prevent lateral movement.
  • Secure Remote Access: Ensure all remote access points are identified, secured, and monitored and that multi-factor authentication (MFA) is enforced.
  • Risk-Based Vulnerability Management: Patch and monitor critical vulnerabilities in externally facing systems.
  • Incident Response Readiness: Develop and regularly exercise an ICS-focused incident response plan.

InnovAKT Recommendations: A Foundation Before Visibility

While Dragos' recommendations are robust, organizations must ensure that their foundational cybersecurity practices are in place.

Here's our perspective on enhancing their approach:

  • Start with Risk Assessment: Before implementing advanced monitoring solutions, assess the current risk landscape. Identify vulnerabilities and prioritize mitigation efforts based on potential impact.
  • Secure the Basics: Establish a secure network architecture that supports visibility. Advanced tools may fail to provide actionable insights without proper segmentation, asset inventory, and baseline security measures.
  • Develop an Enterprise OT Cybersecurity Program covering everything from assessment to Incident response and business continuity. This program has been invited to Align OT security efforts with enterprise initiatives. This ensures that OT cybersecurity is not isolated but integrated into the broader organizational strategy, fostering collaboration between IT and OT teams.

Get in Touch Today

VOLTZITE's activities underscore the need for proactive and collaborative cybersecurity approaches. Organizations can avoid emerging threats by combining foundational strategies with advanced monitoring and detection capabilities.

If your organization is ready to fortify its defenses and align OT cybersecurity with enterprise goals, don't wait. Contact us today to begin building a resilient and comprehensive security program. Together, we can safeguard critical operations and navigate the complexities of today's threat landscape.

Previous
Previous

The Global Cybersecurity Outlook 2025: In-Depth Analysis and Key OT Cybersecurity Predictions

Next
Next

Thoughts on Complexity in OT Systems