ATT&CKReferencesMicrosoft Volt Typhoon May 2023

Microsoft Volt Typhoon May 2023

Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
GroupVolt Typhoon

Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.

T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1018
Remote System Discovery
GroupVolt Typhoon

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1059.001
PowerShell
GroupVolt Typhoon

Volt Typhoon has used PowerShell including for remote system discovery.

T1059.003
Windows Command Shell
GroupVolt Typhoon

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.

T1074
Data Staged
GroupVolt Typhoon

Volt Typhoon has staged collected data in password-protected archives.

T1078.002
Domain Accounts
GroupVolt Typhoon

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.

T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1090.001
Internal Proxy
GroupVolt Typhoon

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.

T1497.001
System Checks
GroupVolt Typhoon

Volt Typhoon has run system checks to determine if they were operating in a virtualized environment.

T1584.008
Network Devices
GroupVolt Typhoon

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.

T1588.002
Tool
GroupVolt Typhoon

Volt Typhoon has used legitimate network and forensic tools and customized versions of open-source tools for C2.

T1680
Local Storage Discovery
GroupVolt Typhoon

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.