Volt Typhoon is a China-linked state-sponsored threat actor focused on long-term clandestine access in critical infrastructure environments, particularly in the United States and other Western-aligned countries. The group is widely associated with strategic pre-positioning rather than immediate disruptive or destructive effects, with activity assessed as intended to preserve options for future crisis or conflict scenarios, including potential contingencies involving the Western Pacific. Public reporting and vendor tracking commonly link the actor to the People’s Republic of China and describe it as part of a broader pattern of Chinese cyber operations against operationally significant civilian infrastructure. Known aliases include Bronze Silhouette, DEV-0391, Insidious Taurus, Storm-0391, UNC3236, Vanguard Panda, and Voltzite. Voltzite is also used by Dragos to describe related activity affecting critical infrastructure. No high-confidence public evidence supports a distinct sub-group structure beyond these overlapping vendor designations. Volt Typhoon is best known for intrusions affecting communications, energy, transportation, water, wastewater, and telecommunications sectors, along with broader critical infrastructure and defense-related environments. The actor has been repeatedly described as targeting organizations whose compromise could support intelligence collection, contingency planning, or later disruption of logistics, mobilization, and public services during a geopolitical crisis. Victimology and operational patterns indicate a strong emphasis on infrastructure that underpins military readiness and civil resilience. The group is notable for extensive use of living-off-the-land tradecraft and operational security measures designed to blend into normal administrative activity. Rather than relying heavily on distinctive malware families in every intrusion, Volt Typhoon frequently uses legitimate system tools, native command interpreters, administrative utilities, and compromised edge infrastructure to reduce forensic visibility. Reported behavior includes system and network discovery, registry and software enumeration, file system and drive discovery, credential access, privilege escalation, persistence, lateral movement, and indicator removal. The actor has been observed querying installed software, enumerating storage characteristics, and conducting broad post-compromise reconnaissance consistent with preparation for sustained access. A defining characteristic of Volt Typhoon operations is the use of covert relay infrastructure, especially compromised small-office and home-office routers and other edge devices, to obfuscate operator origin and support stealthy command-and-control. This tradecraft has been publicly linked to botnet-enabled proxy networks used to hide access into victim environments. Law-enforcement disruption activity against such infrastructure has underscored the actor’s dependence on hijacked networking devices as part of its operational model. In ATT&CK terms, reporting commonly associates Volt Typhoon with discovery, credential access, defense evasion, command and scripting interpreter use, masquerading, exploitation for privilege escalation, setuid and setgid abuse in Linux contexts, and extensive use of native administrative tooling. Comparative analyses of Chinese intrusion sets have also found meaningful overlap between Volt Typhoon and actors such as APT41, Mustang Panda, Stone Panda, and Salt Typhoon, especially in post-compromise methodology, suggesting convergence around reusable tooling and standardized enterprise intrusion practices. Overall, Volt Typhoon is best understood as a PRC state-linked intrusion set specializing in stealthy persistence and pre-positioning inside critical infrastructure. Its operational objective is commonly assessed to be maintenance of durable access that could later support espionage, disruption, or strategic coercion, rather than immediate monetization or overt sabotage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 malware families attributed to this actor across reporting.
26 additional families tracked in Mallory.
33 CVEs this actor has used in observed campaigns. 33 of them exploited in the wild.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
"Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection." | Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection.
Exploiting vulnerabilities in widely used software including, but not limited to: CVE-2021-40539—ManageEngine ADSelfService Plus.
Ensure that these products in your environment are updated with the latest patches... Ivanti (CVE-2024-21887 & CVE-2023-46805)
28 more CVEs tied to this actor tracked in Mallory.
108 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point for Chinese government-backed infrastructure penetration and espionage activity, not as part of the main incident.
Mentioned only in passing as part of a related article headline about hypothetical disruption of the US water supply.
Mentioned as a comparison example of a China-affiliated group targeting critical infrastructure.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.