The National Cyber Security Centre (NCSC) has issued a warning about state-sponsored cyber-attackers hiding on critical infrastructure networks.
The warning comes in collaboration with partners from the US, Australia, Canada, and New Zealand, and sheds light on how threat actors have been exploiting built-in tools and processes within computer systems, a tactic known as ‘living off the land’, to gain persistent access while evading detection.
In response, the NCSC is urging critical infrastructure operators in the UK to implement recommended actions like implementing logging and aggregate logs in out-of-band centralised locations, use automation to continually review all logs against a baseline of network activity, and more listed in the full release.
Another advisory specifically identifies China state-sponsored and Russia state-sponsored actors as among those observed utilising ‘living off the land’ techniques to infiltrate compromised critical infrastructure networks. Furthermore, it highlights the activities of China state-sponsored actor Volt Typhoon, which has been employing similar tactics to compromise critical infrastructure systems in the US.
“Earlier this week, I announced an independent review to look at cybersecurity as an enabler to build trust, resilience and unleash growth across the UK economy,” continued Dowden.
By driving up the resilience of our critical infrastructure across the UK we will defend ourselves from cyber-attackers that would do us harm.”
The new advisory and joint guidance serve as updates to previous warnings issued in May of last year, highlighting China state-sponsored activity observed against critical infrastructure networks in the US that could potentially impact networks worldwide.
Recommended reading
- NCSC Releases New SMB Cybersecurity Guide
- What’s the State of Cybersecurity Automation in 2023?
- NCSC Warns Ransomware Threat to Rise with AI
“It is vital that operators of UK critical infrastructure heed this warning about cyber-attackers using sophisticated techniques to hide on victims’ systems,” said Paul Chichester, NCSC director of operations.
“Threat actors left to carry out their operations undetected present a persistent and potentially very serious threat to the provision of essential services.”
“Organisations should apply the protections set out in the latest guidance to help hunt down and mitigate any malicious activity found on their networks.”





