Volt Typhoon
Also tracked as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.
- Documented techniques
- 81
- Assessed origin
- China
- Assessed motivation
- Sabotage
- First seen
- 2021
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance11
- T1589 Gather Victim Identity Information
- T1589.002 Email Addresses
- T1590 Gather Victim Network Information
- T1590.004 Network Topology
- T1590.006 Network Security Appliances
- T1591 Gather Victim Org Information
- T1591.004 Identify Roles
- T1592 Gather Victim Host Information
- T1593 Search Open Websites/Domains
- T1594 Search Victim-Owned Websites
- T1596.005 Scan Databases
resource development7
initial access1
execution4
privilege escalation1
credential access6
discovery23
- T1007 System Service Discovery
- T1010 Application Window Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1057 Process Discovery
- T1069 Permission Groups Discovery
- T1069.001 Local Groups
- T1069.002 Domain Groups
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1120 Peripheral Device Discovery
- T1124 System Time Discovery
- T1217 Browser Information Discovery
- T1518 Software Discovery
- T1614 System Location Discovery
- T1654 Log Enumeration
- T1680 Local Storage Discovery
lateral movement2
collection6
command and control5
defense impairment2
stealth11
- T1006 Direct Volume Access
- T1027.002 Software Packing
- T1036.005 Match Legitimate Resource Name or Location
- T1036.008 Masquerade File Type
- T1070.004 File Deletion
- T1070.007 Clear Network Connection History and Configurations
- T1078 Valid Accounts
- T1078.002 Domain Accounts
- T1140 Deobfuscate/Decode Files or Information
- T1218 System Binary Proxy Execution
- T1497.001 System Checks
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.