Volt Typhoon
Also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.
- Known attack methods
- 81
- Origin
- China
- Motive
- Sabotage
- First seen
- 2021
- Last seen
- 2024-08
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 7 used
Resource Development
9 techniques · 3 used
Initial Access
11 techniques · 1 used
Execution
20 techniques · 2 used
Persistence
22 techniques · 2 used
Privilege Escalation
13 techniques · 1 used
Stealth
30 techniques · 8 used
Defense Impairment
18 techniques · 2 used
Credential Access
17 techniques · 3 used
Discovery
34 techniques · 19 used
Lateral Movement
9 techniques · 2 used
Collection
17 techniques · 5 used
Command and Control
18 techniques · 3 used
Exfiltration
9 techniques
Impact
15 techniques
Reconnaissance11
- T1589Gather Victim Identity Information
- T1589.002Email Addresses
- T1590Gather Victim Network Information
- T1590.004Network Topology
- T1590.006Network Security Appliances
- T1591Gather Victim Org Information
- T1591.004Identify Roles
- T1592Gather Victim Host Information
- T1593Search Open Websites/Domains
- T1594Search Victim-Owned Websites
- T1596.005Scan Databases
Resource development7
Initial access1
Execution4
Persistence2
Privilege escalation1
Stealth11
- T1006Direct Volume Access
- T1027.002Software Packing
- T1036.005Match Legitimate Resource Name or Location
- T1036.008Masquerade File Type
- T1070.004File Deletion
- T1070.007Clear Network Connection History and Configurations
- T1078Valid Accounts
- T1078.002Domain Accounts
- T1140Deobfuscate/Decode Files or Information
- T1218System Binary Proxy Execution
- T1497.001System Checks
Defense impairment2
Credential access6
Discovery23
- T1007System Service Discovery
- T1010Application Window Discovery
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1016.001Internet Connection Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1046Network Service Discovery
- T1049System Network Connections Discovery
- T1057Process Discovery
- T1069Permission Groups Discovery
- T1069.001Local Groups
- T1069.002Domain Groups
- T1083File and Directory Discovery
- T1087.001Local Account
- T1087.002Domain Account
- T1120Peripheral Device Discovery
- T1124System Time Discovery
- T1217Browser Information Discovery
- T1518Software Discovery
- T1614System Location Discovery
- T1654Log Enumeration
- T1680Local Storage Discovery
Lateral movement2
Collection6
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.