Persistent Access and Strategic Cyber Pre-positioning by Hostile States

PURPOSE: A threat-led, public-evidence review for government security assurance. The focus is not the spectacular end-state attack, but the quieter activity that creates and preserves the option to act later.
CENTRAL QUESTION: What changes if we treat persistent, privileged and difficult-to-evict access as a strategic capability in its own right, rather than merely as an unfinished incident?
Some images in this article
are generated by

EU AI Act Regulation 2024/1689
- Executive summary
- What “the long game” means
- The current UK picture: pre-positioning is now an explicit threat assessment
- How patient state actors preserve access
- Evidence matrix: cases that fit the long-game pattern
- Case studies
- Volt Typhoon: access as a wartime option
- Salt Typhoon and the 2025 global router campaign: persistence in the communications nervous system
- The UK Electoral Commission: quiet access to a democratic institution
- APT10 / Cloud Hopper: compromise the people who already have privileged access
- SolarWinds: from trusted update to identity trust
- SVR cloud tradecraft: dormant accounts, tokens and attacker-enrolled devices
- Snake / Turla: a twenty-year persistence programme
- Cyclops Blink and Jaguar Tooth: the security boundary becomes the implant
- Ukraine’s power grid: months of preparation, minutes of effect
- NotPetya and Viasat: latent access converted into strategic effect
- Barracuda and Ivanti: defenders versus an actor that expects remediation
- Nortel: the cautionary tale that refuses to become obsolete
- “Degrade, do not detonate”: what the evidence supports
- Implications for UK government assurance
- Indicators of a “quiet foothold” problem
- Conclusion: persistent access is a stored capability
- Sources and evidence base
Executive summary
| KEY JUDGEMENT The public evidence strongly supports a “long game” threat model. Hostile-state operators repeatedly seek access that is durable, covert, privileged and resilient to remediation. In critical infrastructure, official UK and Five Eyes assessments explicitly describe this as pre-positioning for possible future disruptive or destructive action. |
The most important shift is conceptual. A hostile state does not need to cause an outage today for an intrusion to be strategically successful. If it can quietly retain access to identity systems, routers, firewalls, remote-access gateways, management platforms, software distribution channels or operational networks, it has acquired an option. The value of that option may increase during a diplomatic crisis, a military confrontation, or a domestic emergency.
This is not hypothetical language imposed on ambiguous incidents. In June 2026 the NCSC stated that adversaries are “prepositioning today”, establishing footholds in technology underpinning critical national infrastructure that could enable rapid exploitation during conflict. The NCSC also reported more than 200 incidents affecting UK CNI and its supporting ecosystem in the year to May 2026, with around three quarters believed to be linked to state actors. [1–2]
The strongest public examples show recurring behaviours: living off the land to blend with legitimate administration; use of valid or dormant accounts; registration of attacker-controlled devices; abuse of cloud tokens and federation trust; modification of router ACLs, authentication settings and exposed services; compromise of security appliances; persistence across reboot, patching and firmware updates; supply-chain access; and active monitoring of defenders during incident response. The last point matters: a patient actor may change or remove visible artefacts when scrutiny increases rather than obligingly remain still for investigation. [3–6,9–14]
The evidence for deliberate, gradual degradation of controls is also meaningful, but should be stated precisely. Public reporting clearly documents actors weakening or bypassing controls to preserve access: altering ACLs, opening ports, changing AAA settings, creating security exclusions, disabling defensive tools, clearing logs, planting backdoors inside firewalls and VPNs, abusing trusted identity mechanisms and reducing the defender’s visibility. Public evidence is thinner for a deliberate strategy of subtly degrading service performance or introducing low-level data corruption for long periods before an overt event. That is plausible, and destructive campaigns show the capability exists, but it should not be presented as equally well evidenced. [5,28]
| ASSURANCE CONSEQUENCE A clean vulnerability scan, a successful patch, or even a password reset does not prove eviction. For high-value systems, assurance has to ask whether an adversary could survive the remediation action, regain access through another trust path, or observe the response from a compromised management plane. |
What “the long game” means
For this report, the long-game pattern has six related components. They can occur together or separately:
• Persistent access: The actor can return without repeating the original exploit, often through credentials, tokens, implants, altered configuration or trusted infrastructure.
• Privilege growth: The actor moves from an edge foothold or user account towards identity, management, network or operational-control planes.
• Defence evasion: Activity is made to resemble legitimate administration, is routed through compromised infrastructure, or is hidden in appliances and systems that defenders monitor poorly.
• Control erosion: Security policy or monitoring is weakened enough to preserve access: ACLs change, ports open, logs become less useful, trusted devices or OAuth applications are added, or security appliances themselves become hostile terrain.
• Adaptive concealment: The actor learns how the organisation detects and responds, monitors the investigation where possible, and may remove, restore or alter visible artefacts when scrutiny increases so that concern appears to have been misplaced.
• Strategic pre-positioning: Access is maintained because it may be useful later for intelligence collection, disruption, sabotage, coercion or support to military operations.
Evidence grading
| Grade | Basis | Interpretation |
| A | Official attribution / joint advisory | Strong public evidence. UK, Five Eyes or another government agency attributes the actor or documents the tradecraft. |
| B | Official victim or government reporting | The incident and dwell/persistence are well evidenced, but public attribution or technical detail is incomplete. |
| C | High-quality vendor or investigative reporting | Useful and often technically detailed, but state linkage is an analytic assessment rather than a public government attribution. |
Practitioner evidence note. The anonymised practitioner vignette in section 7 is included as an assurance observation, not as evidence of attribution and not as a substitute for the public sources graded above.
The current UK picture: pre-positioning is now an explicit threat assessment
The 2026 NCSC assessment is unusually direct. Its CEO described adversaries as establishing footholds today in the technology that underpins CNI, creating the ability to exploit those footholds rapidly during conflict. The same speech warned that vulnerabilities tolerated in peacetime are precisely the vulnerabilities likely to be exploited when circumstances worsen. [1]
This matters because the public conversation still tends to measure cyber harm by visible outcomes: systems unavailable, data stolen, ransomware notes displayed, or operational technology manipulated. The hostile-state model requires another metric: how much latent access and optionality has the adversary accumulated without producing a headline?
NCSC reporting has also stressed living-off-the-land tradecraft, where state-sponsored actors use built-in administrative tools and legitimate processes so that their activity blends into normal operations. This makes “absence of malware” an especially weak assurance claim. [3]
| THE AWKWARD IMPLICATION The quietest intrusion may be the strategically most worrying one. Noise is often evidence of use; silence may simply mean the actor still values the access more than the effect. |
How patient state actors preserve access
Live off the land and look like an administrator
Volt Typhoon is the clearest public example. Five Eyes agencies describe use of valid accounts, native tools and strong operational security to achieve long-term undiscovered persistence. Some victim environments showed indications of access lasting at least five years. The hostile actor invested in reconnaissance and continued learning the environment after compromise. [3–4]
Own the edge, then own the view
Routers, firewalls, VPN concentrators and email-security gateways are unusually valuable footholds. They sit on trust boundaries, see traffic that endpoints do not, often run specialist operating systems, and may have poorer EDR coverage. Cyclops Blink persisted on WatchGuard firewalls across reboot and legitimate firmware updates. Jaguar Tooth provided unauthenticated access to compromised Cisco routers. China-linked actors have repeatedly targeted Ivanti and Barracuda security appliances and adapted when defenders attempted remediation. [11–14,19–20]
Move into identity, tokens and trust
Identity is itself a persistence plane. SolarWinds follow-on activity included abuse of federation trust and forged SAML tokens; CISA warned that where administrative credentials or federation were compromised, isolated fixes might not remove the actor and full reconstitution of identity and trust services could be necessary – something that many organisations have neither experience of, nor expertise in. The SVR has also been observed using dormant accounts, service accounts, cloud tokens and attacker-enrolled devices to regain or preserve access. [9–10,15]
Modify controls rather than merely bypass them once
The 2025 multinational advisory covering China state-sponsored activity overlapping with Salt Typhoon describes actors modifying router ACLs to permit their infrastructure, opening ports, using multiple methods of access and taking steps to protect established access. It warns that defenders may need simultaneous eviction measures because partial response can reveal the investigation and encourage the actor to conceal or preserve alternative footholds. [5–6]
Know the defender: concealment can look like remediation
The same 2025 advisory contains an unusually important incident-response warning. Partial defensive action may alert the actor to an investigation; the actor may then conceal activity, preserve alternative access paths or react elsewhere. It also reports actors compromising mail servers or administrator devices and accounts specifically to monitor for signs that their access has been detected. This creates a counter-intuitive assurance problem: an anomaly that disappears after scrutiny begins is not necessarily reassuring. It may be ordinary self-correction or an undocumented human fix, but it can also be consistent with an adaptive resident actor reducing its observable footprint. [5]
Compromise the supplier or update path
SolarWinds and NotPetya demonstrate two very different outcomes from the same strategic idea: trusted software distribution can bypass the perimeter and arrive already blessed. The SVR used SolarWinds to select high-value victims for follow-on espionage; NotPetya used a compromised Ukrainian software update mechanism as the delivery path for destructive effect. [9,16]
Evidence matrix: cases that fit the long-game pattern
| READING THE TABLE Not every incident was aimed at the UK, and not every actor intended destruction. The relevance is the repeatable tradecraft: durable access, access to strategic systems, resilience to remediation, or a demonstrated transition from preparation to effect. |
China-linked and China-nexus cases
| Case | Actor | Target / sector | Long-game relevance | Evidence Grade |
| Volt Typhoon | PRC state-sponsored | US CNI; energy, transport, water | LOTL, valid accounts, extensive recon; footholds observed for >=5 years; explicit pre-positioning concern [3–4] | A |
| Salt Typhoon / overlapping 2025 campaign | PRC state-sponsored | Telecoms, government, transport, military; UK cluster | Router modification, multiple access methods, long-term persistence, defender monitoring; strategic communications collection [5–6] | A |
| UK Electoral Commission | China state-affiliated actor | UK democratic infrastructure | Systems compromised 2021–2022; email and Electoral Register data likely accessed/exfiltrated over extended period [7] | A |
| APT10 / Cloud Hopper | Chinese MSS-linked | MSPs and downstream UK/global organisations | Compromise of privileged service providers to obtain broad and durable access to many customer networks [8] | A |
| Barracuda ESG / UNC4841 | China-nexus espionage; Mandiant high confidence PRC support | Government and private sector worldwide | Security appliance foothold; changed malware and persistence in response to remediation; replacement recommended [19] | C |
| Ivanti Connect Secure / UNC5221 family | Suspected China-nexus espionage | VPN/security gateways; defence and other sectors | Backdoors, credential theft, trojanised files, LOTL; attempts to persist across upgrades, patches and factory resets [20] | C |
| Nortel | Attackers operating from China; state role not publicly proven | Telecoms technology company | Reported access from ~2000 to 2009 (when Nortel collapsed into Administration); executive credentials, R&D and email; rootkits still present years after discovery [21–22] | C |
Russia-linked cases
| Case | Actor | Target / sector | Long-game relevance | Evidence Grade |
| SolarWinds / SVR | Russian SVR | Government, technology and other high-value targets | Trusted update compromise; selective follow-on; identity/SAML abuse; actor assessed capable of resisting eviction [9–10] | A |
| SVR cloud campaigns | Russian SVR | Government, military, law enforcement, aviation, education | Dormant/service accounts, stolen tokens, MFA fatigue, attacker device enrolment; observed re-entry after password reset [15] | A |
| Snake / Turla | Russian FSB Center 16 | NATO governments and other targets | Nearly 20-year malware programme; indefinite stealth persistence; some hosts remained infected despite remediation attempts [12] | A |
| Cyclops Blink | Sandworm / Russian GRU | WatchGuard firewalls and network devices | Firmware-level persistence across reboot and legitimate updates; modular capability and covert C2 [11] | A |
| Jaguar Tooth | APT28 / Russian GRU | Cisco routers incl. US government and European targets | Router compromise for recon and unauthenticated access; exploitation of poorly maintained devices [13] | A |
| Ukraine grid 2015/2016 | Russian state-sponsored / GRU | Electricity distribution/transmission | At least months of recon and persistence, credential harvesting and privilege escalation before physical disruption [17] | A |
| NotPetya / M.E.Doc | Russian military | Ukraine; global collateral impact | Trusted software update route weaponised for destructive action timed to strategic context [16] | A |
| Viasat KA-SAT | Russia; Russian military involvement assessed | Military/civil satellite communications | Destructive effect initiated about one hour before invasion; demonstrates pre-positioned access converted into operational effect [18] | A |
| Kyivstar 2023 | Russia suspected by SBU | Ukraine mobile telecoms | SBU said attackers were present since at least May before December destructive attack; core systems wiped [23] | B |
| AUTHENTIC ANTICS / APT28 | Russian GRU | Microsoft cloud account users | Persistent endpoint access designed to blend with legitimate login activity; token theft and covert email exfiltration [24] | A |
Case studies
Volt Typhoon: access as a wartime option
Actor: PRC state-sponsored | Evidence: A
The February 2024 Five Eyes advisory is the closest public match to the threat model in this report. The agencies assessed that Volt Typhoon had compromised US critical infrastructure and maintained access to some victim IT environments for at least five years. The actor used valid accounts and living-off-the-land techniques, conducted extensive reconnaissance, tailored activity to the victim and committed continuing resources to understanding the environment over time. [4]
NCSC reporting explicitly warned that targeting of energy, transportation and water networks could be laying the groundwork for future disruptive and destructive attacks. In 2026 the NCSC used Volt Typhoon as the highest-profile example of adversaries pre-positioning within CNI for possible rapid exploitation in conflict. [1,3]
| WHY IT MATTERS This is not “espionage that might accidentally become disruptive”. Official assessments treat the foothold itself as preparation for a future strategic contingency. |
Sources: [1], [3], [4]
Salt Typhoon and the 2025 global router campaign: persistence in the communications nervous system
Actor: PRC state-sponsored; overlaps with industry tracking as Salt Typhoon | Evidence: A
The multinational August 2025 advisory describes PRC state-sponsored actors targeting telecommunications, government, transport, lodging and military networks globally, with tradecraft observed since at least 2021. NCSC reported a cluster of this activity in the UK. [5–6]
The persistence details are especially relevant to assurance. Actors modified router ACLs to allow actor-controlled addresses, opened ports, used several methods of access, obscured source IPs so actions could appear local, and sometimes compromised mail servers or administrator devices/accounts to monitor whether defenders had detected them. The advisory cautions that partial response can alert the actor, encouraging concealment and preservation of other footholds. [5]
The FBI separately described the associated telecommunications compromises as a broad campaign that stole call-data records, some private communications and selected law-enforcement information. [25]
| WHY IT MATTERS An edge or backbone router is not merely another endpoint. If the adversary can modify the device that enforces and observes network policy, it can quietly change the rules from those under which defenders think the network operates. |
Sources: [5], [6], [25]
The UK Electoral Commission: quiet access to a democratic institution
Actor: China state-affiliated actor | Evidence: A
In March 2024 the UK attributed the compromise of the Electoral Commission’s computer systems between 2021 and 2022 to a China state-affiliated actor. NCSC assessed that email data and Electoral Register data were highly likely accessed and exfiltrated during this period. [7]
This is principally an espionage case rather than evidence of planned sabotage. Its relevance is the duration and strategic target selection: a state actor could remain inside an institution central to democratic administration long enough to collect data at scale without needing a noisy disruptive event.
| WHY IT MATTERS For government assurance, long dwell in a politically important system is itself consequential even where the attacker never changes a byte. Integrity and availability are not the only strategic security properties. |
Sources: [7]
APT10 / Cloud Hopper: compromise the people who already have privileged access
Actor: Chinese Ministry of State Security-linked APT10 | Evidence: A
The UK and allies attributed APT10’s global campaign to the Chinese Ministry of State Security. APT10 targeted managed service providers and outsourcing providers, using those trusted relationships to obtain extensive access to customer networks. NCSC reported continued malicious activity affecting UK organisations. [8]
The lesson is not merely “supply chain risk”. MSPs naturally accumulate privileged credentials, remote-management tooling, broad connectivity and knowledge of customer estates. Compromising one provider can turn legitimate support architecture into a persistence and lateral-movement mechanism across many organisations.
| WHY IT MATTERS Third-party administration is a privileged access path, not a contractual footnote. If it is not independently monitored and constrained, it can become an adversary’s long-lived bridge into multiple estates. |
Sources: [8]
SolarWinds: from trusted update to identity trust
Actor: Russian SVR | Evidence: A
The UK and US attributed the SolarWinds supply-chain compromise to Russia’s SVR. The initial compromise of trusted Orion software provided access to many organisations, after which the actor selected a smaller set for deeper follow-on operations. [9]
The important persistence story came after initial access. CISA documented changes to federation trust, attacker-controlled SAML signing, forged tokens that could impersonate users and bypass MFA, and the possibility that the actor had had administrative access for months. Its remediation guidance warned that if administrative credentials or SAML trust were compromised, simply fixing individual hosts or accounts was unlikely to evict the actor; the entire identity trust boundary might need to be treated as compromised. [10]
| WHY IT MATTERS A sophisticated actor does not necessarily keep to the door it first entered through. It may use the first foothold to acquire a new key or keys to the building. |
Sources: [9], [10]
SVR cloud tradecraft: dormant accounts, tokens and attacker-enrolled devices
Actor: Russian SVR | Evidence: A
NCSC and partners described the SVR adapting to cloud environments by targeting service accounts, dormant accounts, cloud tokens and device enrolment. NCSC observed cases where, after an organisation forced a password reset during incident response, the actor logged into inactive accounts and followed the reset process to regain access. [15]
The same advisory describes token use that avoids repeated password authentication and cases where the actor registered its own device in a victim cloud tenant after defeating account authentication. These are low-noise, administratively plausible routes to persistence.
| WHY IT MATTERS Joiners-movers-leavers, service-account governance, token lifetime and device enrolment are not housekeeping. Against a state actor, they are persistence controls. |
Sources: [15]
Snake / Turla: a twenty-year persistence programme
Actor: Russian FSB Center 16 | Evidence: A
In 2023 the US Department of Justice described Snake as the FSB’s premier long-term cyber-espionage implant. Versions had been used for nearly twenty years against hundreds of systems in at least fifty countries, including NATO governments. [12]
The DOJ stated that Snake could persist indefinitely on a compromised computer, typically without the owner noticing, and that the FBI had observed it remain on particular systems despite remediation attempts. Turla repeatedly revised the malware to keep it viable after public disclosures and mitigations.
| WHY IT MATTERS Persistence is not an incidental feature here. It was a product requirement maintained across generations of tooling. |
Sources: [12]
Cyclops Blink and Jaguar Tooth: the security boundary becomes the implant
Actor: Russian GRU / Sandworm and APT28 | Evidence: A
Cyclops Blink was deployed to WatchGuard firewall devices and engineered to survive both reboot and the legitimate firmware-update process. NCSC analysis highlighted the malware’s modularity, encrypted command-and-control and deliberate persistence. [11]
Jaguar Tooth, attributed to APT28/GRU, was deployed to compromised Cisco routers and enabled unauthenticated access after exploitation of a known vulnerability. Victims included European organisations and US government institutions. [13]
| WHY IT MATTERS A compromised endpoint is bad. A compromised firewall, router or VPN gateway can redefine what “inside”, “outside”, “trusted” and “logged” mean for everything behind it or attached to it. |
Sources: [11], [13]
Ukraine’s power grid: months of preparation, minutes of effect
Actor: Russian state-sponsored / GRU | Evidence: A
US government analysis of the 2015 Ukraine electricity attack describes at least six months of reconnaissance. Spear-phishing established BlackEnergy access; attackers harvested credentials, escalated privileges and maintained persistent access before using legitimate HMI capabilities to operate breakers. They also interfered with operators’ ability to respond. [17]
The 2016 Industroyer/CrashOverride attack went further by using malware specifically designed to disrupt power-grid operations. UK government reporting attributes these campaigns to GRU Unit 74455. [26]
| WHY IT MATTERS This is the cleanest historical demonstration of the long-game sequence: learn, enter, persist, escalate, understand the operational environment, then act quickly when the decision is made. |
Sources: [17], [26]
NotPetya and Viasat: latent access converted into strategic effect
Actor: Russian military / Russia | Evidence: A
NotPetya was delivered through the trusted update mechanism of the widely used Ukrainian M.E.Doc tax software. The UK attributed the destructive attack to the Russian military. Although the malware spread far beyond Ukraine, the primary targets were Ukrainian financial, energy and government sectors. [16]
The Viasat KA-SAT operation began about one hour before Russia’s full-scale invasion of Ukraine on 24 February 2022. NCSC assessed Russia was almost certainly responsible; the attack disrupted military and civilian communications and had wider European effects. [18]
These cases matter because they show why persistence and pre-positioning cannot be assessed only through present-day impact. Access acquired earlier can become strategically valuable at a particular hour.
| WHY IT MATTERS The absence of current disruption is not evidence that the adversary lacks disruptive intent. Sometimes the timing is the capability. |
Sources: [16], [18]
Barracuda and Ivanti: defenders versus an actor that expects remediation
Actor: China-nexus espionage actors | Evidence: C
Mandiant assessed with high confidence that UNC4841’s Barracuda ESG campaign supported PRC espionage. After public disclosure and remediation activity, the actor rapidly altered malware, deployed additional persistence and attempted lateral movement. Barracuda ultimately recommended replacement of compromised appliances rather than reliance on patching. [19]
In the Ivanti campaigns, Mandiant observed suspected China-nexus actors trojanising legitimate appliance components, deploying web shells and credential stealers, using living-off-the-land techniques and attempting persistence across system upgrades, patches and factory resets. CISA separately required US federal agencies to disconnect, rebuild, rotate certificates/keys/passwords and assume related domain accounts were compromised. [14,20]
| WHY IT MATTERS A patch closes a vulnerability. It does not necessarily remove an adversary who has already converted that vulnerability into credentials, trust, configuration changes or a second foothold. |
Sources: [14], [19], [20]
Nortel: the cautionary tale that refuses to become obsolete
Actor: Attackers operating from China; state sponsorship alleged but not publicly proven | Evidence: C
Contemporary reporting based on Nortel’s internal investigation described attackers using stolen credentials of senior executives and maintaining widespread access from around 2000 until the company’s collapse in 2009. They obtained technical papers, R&D reports, business plans and email. Rootkits were reportedly still present years after the breach was first identified. [21–22]
The attribution needs discipline. The activity was traced to Chinese infrastructure and former Nortel investigators suspected state involvement, but there is no equivalent public UK/Five Eyes attribution assigning the operation to the Chinese state. The value of the case is the dwell time and the organisational failure to treat discovery as evidence of a systemic compromise.
The timing raises a harder question. Nortel entered insolvency proceedings in 2009, at the end of the same decade in which attackers reportedly enjoyed extensive access to executive accounts, email, technical papers, R&D material and business plans. Access of that breadth could expose considerably more than individual pieces of intellectual property: product roadmaps, strategic priorities, commercial assumptions, emerging technologies and potentially negotiating positions. It is therefore legitimate to ask whether prolonged compromise contributed to Nortel’s competitive decline, rather than treating the intrusion solely as a confidentiality loss. [21–22]
Public evidence does not establish that causal link. Nortel’s collapse had multiple documented causes, and the available reporting does not prove that information obtained through the intrusion was supplied to competitors or materially caused the company’s insolvency. The more defensible assurance conclusion is nevertheless important: persistent strategic espionage can produce cumulative commercial and technological harm whose effects emerge over years and may eventually be impossible to distinguish cleanly from ordinary competitive or organisational failure. The absence of a single identifiable cyber “impact event” does not mean that a decade-long compromise was economically inconsequential. [21–22]
| WHY IT MATTERS The most expensive part of an intrusion may be the years in which the victim believes a password change was a sufficient response. |
| FULL DISCLOSURE I worked for Nortel and was made redundant two days before the company entered administration in 2009. I consequently became a creditor of the estate and remained one throughout the extraordinary seventeen-year (!) insolvency process, ultimately receiving less than half of what I was owed. The global insolvency proceedings reportedly consumed more than US$2 billion in professional and administrative costs. I therefore have a personal interest in the Nortel case; that experience informs my interest in the questions it raises, but is not evidence that the cyber compromise caused or contributed to the company’s collapse. |
Sources: [21], [22]
“Degrade, do not detonate”: what the evidence supports
The user-visible idea of “degradation” needs separating into two categories.
The first is security-control degradation: changes made to reduce the effectiveness of access control, monitoring, trust or incident response. This is strongly evidenced.
The second is covert operational degradation: subtly making a service slower, less reliable or less trustworthy, or introducing data corruption while trying to remain undiscovered. This is technically credible, but less frequently documented in public state-attribution material before an overt operation.
Security-control degradation is visible in the record: China-linked actors modifying router ACLs and opening services; SolarWinds follow-on activity altering federation trust; security-appliance actors modifying legitimate files and persistence mechanisms; SVR actors using dormant accounts and attacker-controlled device enrolment; and sophisticated actors watching mail servers or administrator systems to detect the defenders’ investigation. [5,10,15,19–20]
Operational degradation is harder to prove because a competent operator would prefer it to resemble ordinary failure, technical debt or human error. Public incident reports naturally become clearest when the operator crosses the line into an observable effect, such as Ukraine grid disruption, NotPetya, Viasat or Kyivstar.
This evidential asymmetry should make assessors cautious in both directions: do not claim subtle sabotage without evidence, but do not assume the absence of public examples means the capability is uninteresting.
The vanishing anomaly: disappearance is not explanation
A security-relevant anomaly that vanishes without an accountable remediation has not been explained; it has merely ceased to be observable.
In a high-threat environment, the correct evidential state is therefore “unexplained and no longer observable”, not “resolved”. There are many benign reasons for apparent self-remediation: cache expiry, failover, automatic rollback, delayed configuration management or an administrator making an undocumented change. But CISA explicitly warns that capable state-sponsored actors may notice partial incident response, conceal their activity and preserve alternative access. Disappearance should therefore change the investigation, not automatically end it. [5]
| ANONYMISED PRACTITIONER OBSERVATION A sensitive real-world experience illustrates the assurance problem. Security-relevant anomalies in a network disappeared without an attributable remediation after scrutiny increased. The network owner treated the disappearance as closure. An alternative hypothesis was that a resident threat actor had noticed the attention and removed the visible symptoms, having had sufficient dwell time to understand how the organisation would react. This vignette is not used here as evidence of hostile-state attribution; its value is methodological: An unexplained clean-up is itself an event to preserve, timestamp and correlate with other evidence. |
Control weakening: the adversary may change the game board
Weakening a control does not require switching it off. The more attractive change may be one that leaves the control apparently present while reducing its effective scope: an ACL that quietly permits one additional source, AAA redirected or relaxed, an endpoint-security exclusion, shorter log retention, a missing telemetry source, a new trusted certificate or device, a privileged account whose ownership is hazy, or a management path that bypasses the normal route. The 2025 PRC router advisory documents ACL modification, weaker authentication configurations, log clearing and other changes intended to preserve access and evade detection. A separate CISA case involving Iranian government-sponsored actors on a U.S. federal network documented a Windows Defender exclusion covering the entire C: drive and manual disabling of Defender. [5,28]
Correlation: several trivial events may be one non-trivial campaign
Most individual instances of configuration drift have innocent explanations. That is precisely why a patient adversary benefits from small changes. One temporary firewall rule, one EDR exclusion, one missing log source, one unexplained privileged-group change or one relaxed conditional-access policy can each be dismissed as operational noise. Several such events that cluster around the same identities, management plane, time period or access path should be treated differently. The assurance requirement is therefore not merely to detect control failure, but to correlate reductions in control effectiveness across systems and over time. This is a defensive inference from the documented tradecraft, not a claim that ordinary configuration drift is evidence of hostile activity. [5,29]
| ASSURANCE RULE A control that still exists can nevertheless have been weakened. An anomaly that has disappeared can nevertheless remain unexplained. Treat changes in the effectiveness of controls, and unexplained changes in the observability of a problem, as security events in their own right. |
| IMPORTANT DISTINCTION The strongest claim supported by public evidence is not “hostile states are routinely slowing systems down by 3%”. It is that they deliberately preserve privileged access, weaken or bypass controls, conceal their presence and, in some campaigns, pre-position for later disruptive or destructive use. |
Implications for UK government assurance
A threat model built around patient adversaries changes what good assurance asks. The following controls are not novel, but their priority and purpose become clearer when the objective is eviction-resistant state access rather than commodity compromise.
• Treat management planes as crown-jewel attack surfaces. Identity providers, MDM, PAM, directory services, hypervisors, routers, firewalls, VPN gateways, cloud control planes and software distribution systems can turn one compromise into many. Their administration should be tightly segmented, strongly authenticated and independently monitored.
• Use dedicated privileged administration paths. High-risk administration should originate from hardened, monitored workstations with minimal software and no routine browsing or email. The goal is to prevent the compromise of ordinary user endpoints becoming the path to Tier 0 or equivalent control.
• Make logs harder for the administrator being watched to alter. Centralise critical audit data out of band where practical. Monitor identity changes, new trust relationships, device enrolment, OAuth/application consent, privileged role changes, router/firewall configuration and security-tool policy changes.
• Baseline configuration and detect security drift. A malicious ACL entry, unexpected open service, changed federation setting or altered security-appliance file may be more important than a malware signature. Know what good looks like and alert on changes to the controls themselves.
• Treat unexplained self-remediation as a signal, not closure. If a security anomaly disappears without a recorded cause or corrective action, preserve the evidence and retain the hypothesis. Record exactly when it vanished and what investigative activity preceded the change.
• Monitor control effectiveness, not merely control presence. A firewall can be running while an ACL quietly opens a path; EDR can be installed while exclusions remove useful coverage; MFA can exist while a trusted-device or conditional-access change weakens the boundary. Assurance should test the effective policy seen by an attacker.
• Correlate low-severity security drift. Feed security-control changes into a common timeline so that individually plausible exceptions across identity, network, endpoint, logging and cloud control planes can be recognised as a pattern rather than closed as unrelated tickets.
• Assume credentials, tokens and keys outlive the original exploit. Post-compromise recovery must consider passwords, service accounts, cloud sessions, refresh tokens, API keys, certificates, SAML signing material, SSH keys and device identities. A patch does not invalidate all of these.
• Design for coordinated eviction. Against a capable actor with several footholds, piecemeal remediation can simply teach the adversary what defenders have found. Incident plans should support careful scoping first, then coordinated revocation, rebuild and monitoring.
• Rebuild high-trust appliances when integrity cannot be established. Security gateways and management appliances deserve a lower threshold for known-good rebuild or replacement. If the device that judges traffic is compromised, an integrity checker on the same platform may not be sufficient evidence.
• Treat temporary exceptions as adversary opportunities. Long-lived beta services, legacy protocols, dormant accounts, unmanaged admin paths and “temporary” remote-access exceptions accumulate precisely the sort of quiet footholds patient actors exploit.
• Assure the supply chain’s privileges, not just its paperwork. MSPs and suppliers should receive only the access they require, from attributable identities, with strong authentication and customer-visible audit. Supplier compromise should not inherit unrestricted administrative reach.
• Test whether the system can detect authorised-but-abnormal behaviour. LOTL and valid-account activity mean prevention and malware detection are insufficient. Baselines, UEBA (User and Entity Behaviour Analytics), privilege telemetry, and threat hunting must be able to notice an administrator doing the wrong thing with technically valid tools.
Questions an assessor should ask
- Could an actor remain after the original vulnerability is patched?
- Could an actor survive a reboot, firmware update, password reset or endpoint rebuild?
- Can a privileged actor create a second route in: a new account, device, OAuth application, token, certificate, trust, ACL, port or remote-management path?
- Are the systems that enforce security policy monitored by something outside their own trust boundary?
- Could a compromised administrator or security appliance suppress, alter or block the logs needed to prove compromise?
- Can the organisation rotate every relevant credential, key, token and certificate after a systemic identity compromise?
- Does incident response support simultaneous eviction across identity, endpoints, network devices, cloud and suppliers?
- Are dormant accounts, service accounts and third-party privileged accounts continuously governed rather than reviewed annually?
- Would living-off-the-land activity look materially different from legitimate administration in available telemetry?
- Can critical configuration be compared with an independently protected known-good baseline?
- When a security-relevant anomaly disappears, can the organisation identify the mechanism or person that caused it to disappear?
- Can the SOC detect a reduction in the effectiveness or coverage of a control even when the control remains nominally enabled?
- Are changes to ACLs, AAA, MFA/conditional access, EDR exclusions, logging/retention, trust stores and privileged groups correlated across systems rather than assessed only as separate low-severity events?
- If a security appliance cannot prove its own integrity, is there a tested rebuild/replacement route?
- Does risk acceptance explicitly consider the value of a weakness as a long-term hostile-state foothold, rather than only the probability of immediate exploitation?
Indicators of a “quiet foothold” problem
- Unexpected administrative access from internal-looking IP addresses or infrastructure that normally hosts routers, VPNs or other edge devices.
- Configuration drift in ACLs, routing, DNS, federation, SSO, conditional access, device enrolment or privileged roles without a corresponding approved change.
- Use of dormant, service or break-glass accounts outside established patterns.
- New OAuth applications, service principals, certificates, SSH keys, API keys or trusted devices with weak ownership evidence.
- Repeated reappearance of access after apparently successful remediation.
- Security-relevant anomalies disappearing or configurations reverting without a corresponding approved change, automated-remediation record or identified human action.
- A sequence of individually minor control relaxations: new exclusions or allow-list entries, reduced logging, altered AAA/MFA policy, unexplained firewall/ACL changes, telemetry gaps or newly trusted identities/devices.
- Short-lived configuration changes or log gaps that coincide with threat hunting, ticket creation, administrator investigation or planned containment activity.
- Security appliances producing fewer or less useful logs than expected, or integrity tools disagreeing with independent telemetry.
- Administrative activity that relies entirely on native tools, legitimate remote-management mechanisms or signed binaries but is behaviourally unusual.
- Incident-response discussions, tickets or email apparently known to the attacker before planned containment actions.
- Edge-device changes that make traffic appear local, reduce attribution value or create hidden ingress routes.
- Long-lived “temporary” exceptions that bypass the normal privileged-access, patching or monitoring model.
Conclusion: persistent access is a stored capability
The public evidence supports the underlying concern. Hostile-state cyber operations are often patient because patience has strategic value. A foothold that survives for years can collect intelligence, reveal organisational habits, expose credentials, map dependencies and wait for a moment when disruption matters more than secrecy.
The clearest modern warning is Volt Typhoon, where official assessments explicitly describe pre-positioning in critical infrastructure for possible future disruptive or destructive use. Salt Typhoon and related router campaigns show how communications infrastructure can be modified for long-term access and intelligence collection. SolarWinds, Snake, Cyclops Blink, SVR cloud tradecraft and the appliance compromises show the same instinct in different technical layers: move from a transient exploit to something that looks legitimate, survives maintenance and is difficult to evict.
For UK government assurance, the practical conclusion is uncomfortable but useful: compromise should be modelled as an adversary trying to acquire durable options, not merely immediate effects. Security controls should therefore be judged partly by whether they deny, expose and evict patient access. A system can be fully available, apparently performant and still be strategically compromised.
The operational corollary is equally important: “it went away” is not a root-cause analysis. Against a patient adversary, apparent self-cleaning and small reductions in control effectiveness may be exactly the events that deserve correlation and preserved evidence, particularly when the actor has had time to learn the organisation and its defenders.
| FINAL RULE Do not ask only “Can they get in?” Ask “If they got in last year, would we know, could they still be here, and what could they quietly change while they wait?” |

Sources and evidence base
Preference has been given to NCSC, GOV.UK, CISA, FBI/DOJ and joint Five Eyes material. Vendor and media reporting is used where it provides detail not available in official public reporting; those cases are explicitly graded lower. Sources checked 25 August 2026.
[1] National Cyber Security Centre, “Richard Horne speaking at the RUSI Annual Security Lecture”, June 2026. https://www.ncsc.gov.uk/speech/richard-horne-speaking-at-the-rusi-annual-security-lecture
[2] National Cyber Security Centre, “NCSC CEO: Hostile states linked to three-quarters of cyber attacks affecting UK’s critical systems”, June 2026. https://www.ncsc.gov.uk/news/ncsc-ceo-hostile-states-linked-to-three-quarters-of-cyber-attacks
[3] National Cyber Security Centre, “NCSC and partners issue warning about state-sponsored cyber attackers hiding on critical infrastructure networks”, 7 February 2024. https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-warning-about-state-sponsored-cyber-attackers-hiding-on-critical-infrastructure-networks
[4] CISA / Five Eyes, “PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A)”, February 2024. https://www.cisa.gov/sites/default/files/2024-02/aa24-038a-jcsa-prc-state-sponsored-actors-compromise-us-critical-infrastructure_1.pdf
[5] CISA and international partners, “Countering Chinese State-Sponsored Actors Compromise of Networks Worldwide to Feed Global Espionage System (AA25-239A)”, 27 August 2025. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a
[6] National Cyber Security Centre, “UK and allies expose China-based technology companies for enabling global cyber campaign against critical networks”, 27 August 2025. https://www.ncsc.gov.uk/news/uk-allies-expose-china-tech-companies-enabling-cyber-campaign
[7] National Cyber Security Centre, “UK calls out China state-affiliated actors for malicious cyber targeting of UK democratic institutions and parliamentarians”, 25 March 2024. https://www.ncsc.gov.uk/news/china-state-affiliated-actors-target-uk-democratic-institutions-parliamentarians
[8] National Cyber Security Centre, “APT10 continuing to target UK organisations”, 20 December 2018. https://www.ncsc.gov.uk/news/apt10-continuing-target-uk-organisations
[9] National Cyber Security Centre, “UK and US call out Russia for SolarWinds compromise”, 15 April 2021. https://www.ncsc.gov.uk/news/uk-and-us-call-out-russia-for-solarwinds-compromise
[10] CISA, “Remediating Networks Affected by the SolarWinds and Active Directory/M365 Compromise”, 2021. https://www.cisa.gov/sites/default/files/publications/AR21-134A_Remediating_Networks_Affected_by_the_SolarWinds_and_Active_Directory_M365_Compromise.pdf
[11] National Cyber Security Centre, “New Sandworm malware Cyclops Blink replaces VPNFilter / malware analysis”, 23 February 2022. https://www.ncsc.gov.uk/files/Cyclops-Blink-Malware-Analysis-Report.pdf
[12] U.S. Department of Justice, “Justice Department Announces Court-Authorized Disruption of Snake Malware Network Controlled by Russia’s FSB”, 9 May 2023. https://www.justice.gov/archives/opa/pr/justice-department-announces-court-authorized-disruption-snake-malware-network-controlled
[13] National Cyber Security Centre, “UK and US issue warning about APT28 actors exploiting poorly maintained Cisco routers”, 18 April 2023. https://www.ncsc.gov.uk/news/uk-and-us-issue-warning-about-apt28-actors-exploiting-poorly-maintained-cisco-routers
[14] CISA, “Supplemental Direction V1: ED 24-01 – Mitigate Ivanti Connect Secure and Ivanti Policy Secure Vulnerabilities”, 1 February 2024. https://www.cisa.gov/news-events/directives/supplemental-direction-v1-ed-24-01-mitigate-ivanti-connect-secure-and-ivanti-policy-secure
[15] National Cyber Security Centre, “SVR cyber actors adapt tactics for initial cloud access”, 26 January 2024. https://www.ncsc.gov.uk/news/svr-cyber-actors-adapt-tactics-for-initial-cloud-access
[16] GOV.UK / NCSC, “Foreign Office Minister condemns Russia for NotPetya attacks”, 15 February 2018. https://www.gov.uk/government/news/foreign-office-minister-condemns-russia-for-notpetya-attacks
[17] CISA, “Understanding and Mitigating Russian State-Sponsored Cyber Threats to U.S. Critical Infrastructure”, 11 January 2022. https://www.cisa.gov/news-events/alerts/2022/01/11/understanding-and-mitigating-russian-state-sponsored-cyber-threats-us-critical-infrastructure
[18] National Cyber Security Centre, “Russia behind cyber attack with Europe-wide impact an hour before Ukraine invasion”, 10 May 2022. https://www.ncsc.gov.uk/news/russia-behind-cyber-attack-with-europe-wide-impact-an-hour-before-ukraine-invasion
[19] Mandiant / Google Cloud, “Barracuda ESG Zero-Day Vulnerability Exploited Globally by Aggressive and Skilled Actor, Suspected Links to China”, 15 June 2023. https://cloud.google.com/blog/topics/threat-intelligence/barracuda-esg-exploited-globally/
[20] Mandiant / Google Cloud, “Cutting Edge: Ivanti Connect Secure exploitation and persistence series”, January-February 2024. https://cloud.google.com/blog/topics/threat-intelligence/investigating-ivanti-exploitation-persistence
[21] IEEE Spectrum, “Nortel Penetrated by Hackers Since at Least 2000”, 14 February 2012. https://spectrum.ieee.org/nortel-penetrated-by-hackers-since-at-least-2000
[22] The Washington Post, “Report: Chinese hackers breach Nortel networks”, 14 February 2012. https://www.washingtonpost.com/business/technology/report-chinese-hackers-breach-nortel-networks/2012/02/14/gIQApXsRDR_story.html
[23] Reuters, republished by The Moscow Times, “Ukraine says Russian hackers breached telecom giant months ahead of cyberattack (Reuters reporting on SBU)”, 4 January 2024. https://www.themoscowtimes.com/2024/01/04/ukraine-says-russian-hackers-breached-telecom-giant-months-ahead-of-cyberattack-reuters-a83638
[24] National Cyber Security Centre, “UK calls out Russian military intelligence for use of espionage tool (AUTHENTIC ANTICS)”, 18 July 2025. https://www.ncsc.gov.uk/news/uk-call-out-russian-military-intelligence-use-espionage-tool
[25] Federal Bureau of Investigation, “FBI Seeking Tips about PRC Targeting of U.S. Telecommunications”, 24 April 2025. https://www.fbi.gov/investigate/cyber/alerts/2025/fbi-seeking-tips-about-prc-targeting-of-us-telecommunications
[26] GOV.UK, “Profile: GRU cyber and hybrid threat operations”, July 2026. https://www.gov.uk/government/publications/profile-gru-cyber-and-hybrid-threat-operations/profile-gru-cyber-and-hybrid-threat-operations
[27] National Cyber Security Centre, “UK and allies expose Russian intelligence campaign targeting western logistics and technology organisations”, 21 May 2025. https://www.ncsc.gov.uk/news/uk-partners-expose-russian-intelligence-campaign
[28] CISA, “Iranian Government-Sponsored APT Actors Compromise Federal Network, Deploy Crypto Miner, Credential Harvester (AA22-320A)”, 16 November 2022. https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-320a
[29] National Cyber Security Centre, “Secure connectivity principles for operational technology (OT) – Principle 7: Ensure all connectivity is logged and monitored”, January 2026. https://www.ncsc.gov.uk/collection/operational-technology/secure-connectivity/principle-7
| SCOPE NOTE This is a public-evidence threat review, not an attribution assessment for any specific UK system. The case studies are used to demonstrate documented hostile-state tradecraft and the assurance consequences of that tradecraft. |
