Volt Typhoon is a China-linked, state-sponsored cyber espionage threat actor focused primarily on long-term access to critical infrastructure, especially in the United States and Guam. The group is widely assessed to support Chinese strategic objectives and is notable for pre-positioning within victim environments in ways consistent with preparation for potential disruptive or destructive operations during a future geopolitical crisis, including a possible conflict involving Taiwan. Reported targeting has included communications, energy, water, transportation, and other operationally significant sectors. Known aliases include BRONZE SILHOUETTE, DEV-0391, Storm-0391, UNC3236, Vanguard Panda, Insidious Taurus, and Voltzite. Some reporting also refers to the cluster as Volt Typhoon APT or Volt Typhoon (G1017). Volt Typhoon is distinguished by stealth, operational patience, and extensive use of living-off-the-land techniques. Rather than relying heavily on custom malware, the actor commonly abuses legitimate administrative tools, valid accounts, native command interpreters, WMI, and other built-in system capabilities to reduce forensic visibility and blend with normal activity. Web shells have been repeatedly associated with the group for persistence and remote command execution. Public reporting also links the actor to the use of Operational Relay Box infrastructure built from compromised edge devices, reflecting a broader Chinese practice of routing operations through layered proxy networks to obscure origin and complicate attribution. Observed post-compromise behavior has included reconnaissance of users, groups, and network resources; credential access and directory theft; export of Active Directory data including NTDS and LDAP-derived information; creation of volume shadow copies; collection of system data; and archiving of stolen material prior to exfiltration. Across multiple intrusions, a recurring sequence has been noted: initial access to an internet-facing system, deployment of a web shell, native-command reconnaissance, extraction of directory data, and compression or staging of collected information. The group has also been associated with short bursts of hands-on-keyboard activity designed to minimize detection opportunities. Initial access has been tied to exploitation of public-facing applications and the abuse of compromised credentials, including environments lacking strong multifactor protections. Reporting has also associated the actor with targeting vulnerabilities in network security products, including Fortinet technologies. More broadly, Volt Typhoon has been repeatedly linked to campaigns against internet-exposed infrastructure and edge devices. Strategically, Volt Typhoon is one of the most prominent Chinese intrusion sets associated with access operations against civilian critical infrastructure rather than conventional intellectual-property theft alone. Its activity is frequently cited by governments and industry as evidence of Chinese efforts to establish latent access inside foreign infrastructure for intelligence collection and possible future disruption. This pre-positioning posture, combined with stealthy tradecraft and reliance on legitimate tools, makes Volt Typhoon a high-priority threat for defenders responsible for operational technology, network edge infrastructure, and critical national services.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 malware families attributed to this actor across reporting.
26 additional families tracked in Mallory.
33 CVEs this actor has used in observed campaigns. 33 of them exploited in the wild.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
In another Secureworks IR engagement in September 2021, the activity was slightly briefer. This time the attackers exploited a public-facing application to obtain initial access. Secureworks surmised that it was likely to have been an exploitation of CVE-2021-40539 against a ManageEngine ADSelfService Plus server.
"Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection." | Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection.
CVE-2024-21762 (CVSS skóre 9,6) Kritická zraniteľnosť CVE-2024-21762 sa nachádza v komponente sslvpnd a umožňuje zapisovať mimo povolené hodnoty vyrovnávacej pamäte. Úspešné zneužitie umožňuje neautentifikovanému útočníkovi ľubovoľné vykonávanie kódu alebo príkazov prostredníctvom špeciálne vytvorených HTTP požiadaviek. Pre zraniteľnosť nie je vydaná dočasná mitigácia... Zraniteľnosť CVE-2024-21762 môže byť aktívne zneužívaná.
28 more CVEs tied to this actor tracked in Mallory.
132 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-linked espionage actor targeting U.S. critical infrastructure using living-off-the-land techniques.
Known for pre-positioning within critical infrastructure for potential disruptive attacks; the article says this group has also adopted ORB networks as part of Chinese APT OPSEC.
Referenced as a Chinese campaign that installed malware in critical infrastructure; used here as an example motivating cross-sector/industry coordination.
Referenced as a Chinese state-backed group associated with pre-positioning or embedding within U.S. critical infrastructure, used here as a real-world analogue for the simulated cyberattack scenario.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.