Home/Threat Actor/Volt Typhoon
Threat Actor

Volt Typhoon

volt_typhoon · china · active since 2021

Volt Typhoon (Vanguard Panda / BRONZE SILHOUETTE / DEV-0391 / UNC3236 / VOLTZITE / Insidious Taurus / DazedToad / G1017) is a People's Republic of China state-sponsored cyber actor active since at least 2021 whose targeting of US critical infrastructure , including water utilities, electric utilities, communications, transportation, and Indo-Pacific military-supporting infrastructure in Guam, has been formally assessed by US and Five Eyes governments as pre-positioning to enable destructive or disruptive operations in a future geopolitical crisis; documented operations include the C0035 KV botnet of compromised end-of-life Cisco and NETGEAR SOHO routers (court-authorized takedown January 2024), the C0039 Versa Director zero-day exploitation (CVE-2024-39717) deploying the VersaMem web shell, and multi-year persistent access (some 5+ years) maintained via living-off-the-land tradecraft, stolen credentials, hands-on- keyboard activity, and compromised victim-region SOHO and VPS infrastructure for command-and-control obfuscation.

china confidence: high 16 aliases MITRE ATT&CK G1017 ↗

Profile

Volt Typhoon is a People's Republic of China state-sponsored cyber actor active since at least 2021 whose targeting of US critical infrastructure has been assessed by US/Five Eyes governments as deliberate pre-positioning, establishing and maintaining access to enable destructive or disruptive operations during a future geopolitical crisis or conflict, rather than near-term espionage. This assessment, formalized in CISA AA24-038A (February 2024), distinguishes Volt Typhoon from the broader universe of PRC espionage actors and elevates it to the top tier of acute Western CTI concern. FBI Director Christopher Wray has publicly cited Volt Typhoon as one of the most pressing national- security cyber threats facing the United States, particularly in the context of a potential Taiwan contingency. Tradecraft is defined by extreme stealth via living-off-the-land (LOTL): heavy use of built-in Windows utilities (PowerShell, WMIC, ntdsutil, netsh, certutil, wevtutil, vssadmin, net, cmd) rather than custom malware.

reliance on stolen valid credentials for persistence (T1078)

hands-on-keyboard operations rather than automated tooling.

selective Windows event log clearing.

and use of compromised end-of-life SOHO routers (Cisco RV-series, NETGEAR ProSAFE, the KV botnet) and victim-network-region VPS infrastructure to obscure command-and-control attribution. Where custom tools are used (Awen web shells, the VersaMem in-memory Java web shell from the Versa Director zero-day campaign, customized open-source FRP and Earthworm proxies), they are packed with UPX and renamed to legitimate filenames (cisco_up.exe, vm3dservice.exe, WmiPrvSE.exe). Initial access leverages n-day and zero-day exploitation of internet-facing edge devices: Fortinet FortiOS SSL-VPN (CVE-2022-42475, CVE-2023-27997), Ivanti Connect Secure (CVE-2023-46805 / CVE-2024-21887 / CVE-2024-21893), Versa Director (CVE-2024-39717), and prior vulnerabilities in NETGEAR, Citrix, Cisco, and Zoho ManageEngine products. Reporting (Dragos 2026) identifies a separate initial-access cluster, SYLVANITE, that hands off access to Volt Typhoon / VOLTZITE for follow-on OT reconnaissance, paralleling the initial-access-broker / deep-access-operator model seen in some Russian actor groupings. Documented sector targeting heavily emphasizes water utilities, electric utilities, communications, transportation, manufacturing, and government, with specific operational focus on Guam given its centrality to Indo-Pacific Command logistics. The January 2024 DOJ-led court-authorized takedown of the KV botnet was a rare public disruption operation targeting state-actor infrastructure.

Aliases

16
volt typhoonvolttyphoonbronze silhouettevanguard pandadev-0391unc3236voltziteinsidious taurusdazedtoadsylvanitekv botnetkv-botnetkvbotnetg1017dev 0391dev0391

Notable Campaigns

7
2026DazedToad Tracking (Cloudflare, 2026)
2024-2026SYLVANITE Initial Access Cluster Hand-off
2024CISA AA24-038A, PRC Actors Maintain Persistent Access to US Critical Infrastructure (Feb 2024)
2024C0039, Versa Director Zero-Day Exploitation (Jun-Aug 2024)
2023CISA AA23-144A, PRC Actor Living Off the Land (May 2023)
2022-2024C0035, KV Botnet Activity (Oct 2022 - Jan 2024)
2021-2024Guam Water and Electric Sector Intrusions

Attribution & Reporting

Attributed by
White HouseUS Department of JusticeFBICISANSAUS Cyber CommandOffice of the Director of National IntelligenceUK NCSCCanadian Centre for Cyber Security (CCCS)Australian Signals Directorate (ASD)Australian Cyber Security Centre (ACSC)New Zealand NCSCFive EyesMicrosoftMandiantGoogle Cloud Threat IntelligenceCrowdStrikeSentinelOneSecureworksLumen Black Lotus LabsDragosCloudflarePalo Alto Networks Unit 42Cisco TalosSymantec / BroadcomRecorded FutureFortinetTrend Micro
Key reporting
reportCISA AA23-144A: People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (May 2023)
reportCISA AA24-038A: PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (February 2024)
reportCISA MAR-10448362-1.v1: Volt Typhoon Malware Analysis Report (February 2024)
reportMicrosoft Threat Intelligence: Volt Typhoon Targets US Critical Infrastructure with Living-off-the-Land Techniques (May 2023)
reportSecureworks CTU: Chinese Cyberespionage Group BRONZE SILHOUETTE Targets US Government and Defense Organizations (May 2023)
reportBlack Lotus Labs (Lumen): Routers Roasting on an Open Firewall, KV-Botnet Investigation (December 2023)
reportBlack Lotus Labs (Lumen): Taking the Crossroads, Versa Director Zero-Day Exploitation (August 2024)
reportUS Department of Justice: US Government Disrupts Botnet PRC Used to Conceal Hacking of Critical Infrastructure (January 2024)
reportFBI Director Christopher Wray: Remarks on Volt Typhoon Takedown (January 2024)
reportFBI Director Wray: The PRC Cyber Threat to Critical Infrastructure (Vanderbilt April 2024)
reportCrowdStrike: Vanguard Panda Tradecraft (June 2023)
reportDragos: VOLTZITE Espionage Operations Targeting US Critical Systems
reportDragos 2026 OT/ICS Cybersecurity Year in Review
reportCloudflare 2026 Threat Report
reportSentinelOne: China, Volt Typhoon and the Emergence of Pacific Rim Cyber Threats
reportEuRepoC: APT Profile, Volt Typhoon
reportRecorded Future / Insikt Group: RedFly, China-Linked Group Targets Electric Grid (Asian sister-cluster tracking)

Operational

State sponsor

People's Republic of China (PRC) state-sponsored.

assessed by US/Five Eyes governments as PRC government-directed pre-positioning.

Motivations
pre_positioning, critical_infrastructure_targeting, destructive_operations_enablement, intelligence_gathering, espionage, geopolitical_signal_sending, operational_technology_compromise, guam_and_indo_pacific_focus
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin