Skip to main content
QUIETLYTIC
Threat Actor

Volt Typhoon

PRC state-sponsored actor, per MITRE ATT&CK, active since at least 2021, pre-positioning within US critical infrastructure using living-off-the-land techniques rather than custom malware.

Threat Level
CRITICAL
Attribution
People's Republic of China (PRC) state-sponsored — per MITRE ATT&CK's group profile, citing CISA advisory AA24-038A
Also Known As
BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad
Targets
US critical infrastructure, including Guam, Operational technology (OT) environments

Overview

Volt Typhoon (MITRE ATT&CK ID G1017) is a People’s Republic of China (PRC) state-sponsored actor MITRE ATT&CK documents as active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories, including Guam. Per MITRE’s profile, citing CISA advisory AA24-038A and Microsoft’s May 2023 reporting, Volt Typhoon’s targeting and behavior have been assessed as pre-positioning to enable lateral movement into operational technology (OT) assets for potential destructive or disruptive attacks. MITRE documents the group’s emphasis on stealth via web shells, living-off-the-land (LOTL) binaries, hands-on-keyboard activity, and stolen credentials — rather than custom malware. MITRE’s data also records that the group leveraged compromised SOHO routers to proxy command-and-control traffic, activity associated with the KV Botnet.

Known tools (per MITRE ATT&CK relationship data)

Consistent with MITRE’s “living off the land” characterization, our ingested data links Volt Typhoon almost entirely to legitimate dual-use system tools rather than custom malware: PsExec, Impacto, Mimikatz, Wevtutil, Nltest, netsh, netstat, Systeminfo, Tasklist, certutil, and cmd — alongside VersaMem and FRP (Fast Reverse Proxy).

Notable techniques (per MITRE ATT&CK relationship data)

Techniques linked to Volt Typhoon in our data include Application Window Discovery (T1010), Botnet (T1584.005), Browser Information Discovery (T1217), Clear Network Connection History and Configurations (T1070.007), Clear Windows Event Logs (T1685.005), and Credentials from Password Stores (T1555) / Credentials from Web Browsers (T1555.003).

Per MITRE ATT&CK’s relationship data, Volt Typhoon is linked to the KV Botnet Activity campaign and “Versa Director Zero Day Exploitation.”

What we don’t have

MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2021” per MITRE’s description text. We have no independent telemetry beyond MITRE’s STIX bundle, and MITRE separately notes a related but distinct initial-access cluster (“SYLVANITE”) that reportedly hands off access to Volt Typhoon — we report this as MITRE documents it, not as confirmed independent fact.

Frequently Asked Questions

What is Volt Typhoon? A PRC state-sponsored actor, per MITRE ATT&CK (citing CISA advisory AA24-038A), active since at least 2021 and assessed to be pre-positioning within US critical infrastructure for potential disruptive attacks.

Does Volt Typhoon use custom malware? Per MITRE ATT&CK’s documented toolset, largely no — the group is characterized by its use of legitimate system administration tools and living-off-the-land techniques rather than custom malware, making detection harder.

What is the KV Botnet’s connection to Volt Typhoon? Per MITRE ATT&CK’s relationship data, Volt Typhoon leveraged compromised SOHO routers (the KV Botnet) to proxy command-and-control traffic and obscure its infrastructure.


Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G1017, aggregated September 11, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Related intelligence


Cross-referenced intelligence


Analyst tools