Threat group.View on attack.mitre.org
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet..
Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space. |
| T1003.003 NTDS |
Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes. |
| T1005 Data from Local System |
Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information. |
| T1006 Direct Volume Access |
Volt Typhoon has executed the Windows-native `vssadmin` command to create volume shadow copies. |
| T1007 System Service Discovery |
Volt Typhoon has used `net start` to list running services. |
| T1010 Application Window Discovery |
Volt Typhoon has collected window title information from compromised systems. |
| T1012 Query Registry |
Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY. |
| T1016 System Network Configuration Discovery |
Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`. |
| T1016.001 Internet Connection Discovery |
Volt Typhoon has employed Ping to check network connectivity. |
| T1018 Remote System Discovery |
Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks. |
| T1021.001 Remote Desktop Protocol |
Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges. |
| T1027.002 Software Packing |
Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine. |
| T1033 System Owner/User Discovery |
Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1036.005 Match Legitimate Resource Name or Location |
Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools. |
| T1036.008 Masquerade File Type |
Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.