Hacker groupG1017

Volt Typhoon

Also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

Known attack methods
81
Origin
China
Motive
Sabotage
First seen
2021
Last seen
2024-08
Source
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

VersaMem

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

FRPImpacketMimikatzNetNltestPingPsExecRegSysteminfoTasklistWevtutilcertutilcmdipconfignetshnetstat

Campaigns

KV Botnet ActivityVersa Director Zero Day Exploitation