NEW: Group Profiler — instant APT intel lookup. Try it →

Volt Typhoon

G1017 China MITRE ATT&CK →

Also known as: BRONZE SILHOUETTE · Vanguard Panda · DEV-0391 · UNC3236 · Voltzite · Insidious Taurus · DazedToad

Overview

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

Naming & attribution

Volt Typhoon is tracked under 8 names across the industry. It uses 81 documented ATT&CK techniques — more than 97% of the 174 groups tracked here. Activity attributed since at least 2021.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
BRONZE SILHOUETTECounter Threat Unit Research Team
Vanguard PandaCISA et al.
DEV-0391CISA et al.
UNC3236CISA et al.
VoltziteCISA et al.
Insidious TaurusCISA et al.
DazedToadCloudflare

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1552 Unsecured Credentials — used by 1 of 174 groups
  • T1590.006 Network Security Appliances — used by 1 of 174 groups
  • T1592 Gather Victim Host Information — used by 1 of 174 groups
  • T1006 Direct Volume Access — used by 2 of 174 groups
  • T1070.007 Clear Network Connection History and Configurations — used by 2 of 174 groups
  • T1218 System Binary Proxy Execution — used by 2 of 174 groups
  • T1584.003 Virtual Private Server — used by 2 of 174 groups
  • T1596.005 Scan Databases — used by 2 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • OilRig Iran — 34 shared techniques (28% overlap)
  • Chimera China — 31 shared techniques (28% overlap)
  • APT41 China — 35 shared techniques (27% overlap)
  • FIN13 — 27 shared techniques (25% overlap)
  • Turla Russia — 29 shared techniques (24% overlap)
  • Sandworm Team Russia — 30 shared techniques (23% overlap)

Malware families with current indicators

One family attributed to Volt Typhoon, carrying 1 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • Frp 1 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190

TTPs — 81 techniques across 13 tactics

Resource Development

Initial Access

Execution

Persistence

Privilege Escalation

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (17)

netsh · PsExec · ipconfig · Wevtutil · VersaMem · Tasklist · Mimikatz · Ping · Impacket · Systeminfo · netstat · Nltest · certutil · Reg · FRP · cmd · Net

Reporting (3)