ATT&CKGroupsVolt Typhoon

Volt Typhoon

G1017

Threat group.View on attack.mitre.org

About this group

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet..

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

Techniques used81

Procedure examples81

TechniqueProcedure example
T1003.001
LSASS Memory

Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.

T1003.003
NTDS

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1005
Data from Local System

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1006
Direct Volume Access

Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies.

T1007
System Service Discovery

Volt Typhoon has used `net start` to list running services.

T1010
Application Window Discovery

Volt Typhoon has collected window title information from compromised systems.

T1012
Query Registry

Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY.

T1016
System Network Configuration Discovery

Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.

T1016.001
Internet Connection Discovery

Volt Typhoon has employed Ping to check network connectivity.

T1018
Remote System Discovery

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.

T1021.001
Remote Desktop Protocol

Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges.

T1027.002
Software Packing

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.

T1033
System Owner/User Discovery

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1036.005
Match Legitimate Resource Name or Location

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1036.008
Masquerade File Type

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.

View all 81 procedure examples

Software17

Campaigns2

References6

  1. CISA AA24-038A PRC Critical Infrastructure February 2024 Open source
    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.
  2. DOJ KVBotnet 2024 Open source
    US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.
  3. Dragos 2025 Year in Review Open source
    Dragos. (2026, February). 9TH ANNUAL YEAR IN REVIEW | OT/ICS CYBERSECURITY REPORT . Retrieved April 26, 2026.
  4. Joint Cybersecurity Advisory Volt Typhoon June 2023 Open source
    NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.
  5. Microsoft Volt Typhoon May 2023 Open source
    Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.
  6. Secureworks BRONZE SILHOUETTE May 2023 Open source
    Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.