Volt Typhoon
MITRE ATT&CK: G1017 View on attack.mitre.org
Aliases: BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad, VANGUARD PANDA, VOLTZITE, Dev-0391, Storm-0391, Volt Typhoon
- First seen
- 2021-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-24 07:25:04
- Profile updated
- 2026-07-07 12:34:39
Targeted industries: energy-and-utilities government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:us country_code:gu
Context
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.
Detection coverage
- 14 YARA rules
- 986 Sigma rules
Malware & tools used
- File and Directory Discovery (attack-pattern)
- Identify Roles (attack-pattern)
- Process Discovery (attack-pattern)
- Remote Desktop Protocol (attack-pattern)
- Server (attack-pattern)
- Proxy (attack-pattern)
- Software Discovery (attack-pattern)
- Valid Accounts (attack-pattern)
- Network Devices (attack-pattern)
- Keylogging (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Masquerade File Type (attack-pattern)
- Windows Command Shell (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Credentials from Password Stores (attack-pattern)
- Data Staged (attack-pattern)
- Gather Victim Network Information (attack-pattern)
- Archive via Utility (attack-pattern)
- System Time Discovery (attack-pattern)
- Domain Groups (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Remote System Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- External Remote Services (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Reports & references
- secureworks.com — Chinese Cyberespionage Group Bronze Silhouette Targets Us Government And Defense Organizations (report)
- Microsoft — Volt Typhoon Targets Us Critical Infrastructure With Living Off The Land Techniques (report)
- Palo Alto Unit 42 — Volt Typhoon Threat Brief (report)
- dragos.com — Voltzite (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- blog.cloudflare.com — 2026 Threat Report (report)
- 5943619.hs-sites.com — Dragos 2026 Ot Cybersecurity Report A Year In Review (report)
- MITRE ATT&CK — G1017 (report)
- media.defense.gov — Csa Living Off The Land (report)
- web.archive.org — Chinese Cyberespionage Group Bronze Silhouette Targets Us Government And Defense Organizations (report)
- CISA — Aa24 038A Csa Prc State Sponsored Actors Compromise Us Critical Infrastructure 3 (report)
- justice.gov — Us Government Disrupts Botnet Peoples Republic China Used Conceal Hacking Critical (report)
Attributed from
- KV Botnet Activity (campaign)
- Versa Director Zero Day Exploitation (campaign)
External references
- mitre-attack — G1017
- Cloudflare 2026 Threat Report New Threat Actors March 2026
- Vanguard Panda
- DEV-0391
- UNC3236
- Voltzite
- Insidious Taurus
- DazedToad
- BRONZE SILHOUETTE
- CISA AA24-038A PRC Critical Infrastructure February 2024
- Secureworks BRONZE SILHOUETTE May 2023
- Dragos 2025 Year in Review
- Microsoft Volt Typhoon May 2023
- Joint Cybersecurity Advisory Volt Typhoon June 2023
- DOJ KVBotnet 2024
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy