Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Volt Typhoon

Also known as: BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad, Storm-0391

Description

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)(Citation: Microsoft Volt Typhoon May 2023)(Citation: Joint Cybersecurity Advisory Volt Typhoon June 2023)(Citation: Secureworks BRONZE SILHOUETTE May 2023). The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.(Citation: DOJ KVBotnet 2024). Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. (Citation: Dragos 2025 Year in Review)

AI Analysis

No AI analysis yet.

ATT&CK Techniques

Collection
6 techniques
Command & Control
5 techniques
Credential Access
6 techniques
Discovery
23 techniques
Execution
4 techniques
Reconnaissance
11 techniques
Resource Development
7 techniques
Stealth
11 techniques

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-512 Hash 3 SHA-1 Hash 3 Filename 3 SHA-256 Hash 3 MD5 Hash 3 IPv4 Address 5

References

  1. Cloudflare 2026 Threat Report New Threat Actors March 2026 — Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
  2. CISA AA24-038A PRC Critical Infrastructure February 2024 — CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.
  3. Secureworks BRONZE SILHOUETTE May 2023 — Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.
  4. Dragos 2025 Year in Review — Dragos. (2026, February). 9TH ANNUAL YEAR IN REVIEW | OT/ICS CYBERSECURITY REPORT . Retrieved April 26, 2026.
  5. Microsoft Volt Typhoon May 2023 — Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.
  6. Joint Cybersecurity Advisory Volt Typhoon June 2023 — NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.
  7. DOJ KVBotnet 2024 — US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.

Intel Summary

81

Techniques

1

Tools

3

Campaigns

68

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
DDoS

Details

MITRE ID
G1017
Type
Unknown
Country of Origin
C
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--174279b4-399f-4ddb-966e-5efedd1dd5f2
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.