FORENSIA

THREAT_ACTOR · G1017

Volt Typhoon

Also known as: Volt Typhoon, BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad

Profile

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

MITRE ATT&CK ↗

Techniques

81 ATT&CK techniques attributed to this actor.

T1003.001 LSASS MemoryT1003.003 NTDST1005 Data from Local SystemT1006 Direct Volume AccessT1007 System Service DiscoveryT1010 Application Window DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1016.001 Internet Connection DiscoveryT1018 Remote System DiscoveryT1021.001 Remote Desktop ProtocolT1027.002 Software PackingT1033 System Owner/User DiscoveryT1036.005 Match Legitimate Resource Name or LocationT1036.008 Masquerade File TypeT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1056.001 KeyloggingT1057 Process DiscoveryT1059.001 PowerShellT1059.003 Windows Command ShellT1059.004 Unix ShellT1068 Exploitation for Privilege EscalationT1069 Permission Groups DiscoveryT1069.001 Local GroupsT1069.002 Domain GroupsT1070.004 File DeletionT1070.007 Clear Network Connection History and ConfigurationsT1074 Data StagedT1074.001 Local Data StagingT1078 Valid AccountsT1078.002 Domain AccountsT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1090 ProxyT1090.001 Internal ProxyT1090.003 Multi-hop ProxyT1105 Ingress Tool TransferT1112 Modify RegistryT1113 Screen CaptureT1120 Peripheral Device DiscoveryT1124 System Time DiscoveryT1133 External Remote ServicesT1140 Deobfuscate/Decode Files or InformationT1190 Exploit Public-Facing ApplicationT1217 Browser Information DiscoveryT1218 System Binary Proxy ExecutionT1497.001 System ChecksT1505.003 Web ShellT1518 Software DiscoveryT1552 Unsecured CredentialsT1552.004 Private KeysT1555 Credentials from Password StoresT1555.003 Credentials from Web BrowsersT1560.001 Archive via UtilityT1570 Lateral Tool TransferT1573.001 Symmetric CryptographyT1584.003 Virtual Private ServerT1584.004 ServerT1584.005 BotnetT1584.008 Network DevicesT1587.004 ExploitsT1588.002 ToolT1588.006 VulnerabilitiesT1589 Gather Victim Identity InformationT1589.002 Email AddressesT1590 Gather Victim Network InformationT1590.004 Network TopologyT1590.006 Network Security AppliancesT1591 Gather Victim Org InformationT1591.004 Identify RolesT1592 Gather Victim Host InformationT1593 Search Open Websites/DomainsT1594 Search Victim-Owned WebsitesT1596.005 Scan DatabasesT1614 System Location DiscoveryT1654 Log EnumerationT1680 Local Storage DiscoveryT1685.005 Clear Windows Event Logs

Software

17 malware/tools attributed to this actor.

MimikatzPsExecNetTasklistRegSysteminfoPingipconfignetstatcmdnetshcertutilImpacketNltestWevtutilFRPVersaMem

Related corpus activity

10,231 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Volt Typhoon.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,231.