Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagecritical-infrastructure-threatdefense-evasion-methodpersistence-method

China-Linked Volt Typhoon and Flax Typhoon Use Stealthy Access in Critical Sectors

Updated 28d agoFirst seen May 25, 20267 sources

Microsoft and U.S. officials said China-linked threat groups Volt Typhoon and Flax Typhoon used living-off-the-land techniques and legitimate software to quietly compromise targets while minimizing detection. Volt Typhoon was tied to intrusions affecting U.S. critical infrastructure, with reporting describing the group as breaching networks through stealthy post-compromise activity rather than malware-heavy tradecraft. U.S. agencies later warned that the campaign appeared aimed at pre-positioning inside critical infrastructure for potential disruptive or destructive operations.

Microsoft separately reported that Flax Typhoon targeted organizations in Taiwan for cyber-espionage, relying on valid credentials, remote access tools, and other trusted utilities to maintain persistence and blend into normal network activity. Subsequent reporting and later tracking indicated that Volt Typhoon remained active against U.S. infrastructure, reinforcing concerns that Chinese state-linked operators are sustaining long-term access across strategically important environments while using native tools and legitimate software to evade defenders.

Share:
China-Linked Volt Typhoon and Flax Typhoon Use Stealthy Access in Critical Sectors
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
May 10, 20261mo ago

CybelAngel reports Volt Typhoon remains active in US critical infrastructure

A 2026 analysis said Volt Typhoon was still active in U.S. critical infrastructure, indicating the campaign had persisted beyond the initial 2023 disclosures. The report framed the threat as ongoing rather than historical, underscoring continued concern about long-term access and resilience risks.

Feb 7, 20242y ago

CISA and FBI warn Volt Typhoon is pre-positioning for disruptive attacks

U.S. authorities warned that China-linked hackers associated with Volt Typhoon were pre-positioning in critical infrastructure networks to enable potential disruptive or destructive attacks during a future crisis. The warning marked an escalation from earlier public reporting focused primarily on stealthy access and espionage.

Aug 29, 20233y ago

Additional reporting details Flax Typhoon tradecraft

Follow-on reporting summarized Microsoft's disclosure that Flax Typhoon used legitimate tools for cyber-espionage against Taiwanese organizations. The reports emphasized the actor's reliance on living-off-the-land techniques and legitimate remote access software to reduce visibility.

Aug 24, 20233y ago

Microsoft reveals Flax Typhoon targeting Taiwanese organizations

Microsoft disclosed a separate China-linked espionage group, Flax Typhoon, describing its use of legitimate software and quiet access methods against organizations in Taiwan. The company said the actor focused on espionage and persistence while blending into normal administrative activity.

May 24, 20233y ago

Public reporting amplifies Volt Typhoon breach details

Media reporting on the same day highlighted Microsoft's findings that Chinese hackers had breached U.S. critical infrastructure networks in stealthy attacks. The coverage reinforced that the campaign relied on built-in tools and compromised small office/home office network equipment to evade detection.

Microsoft discloses Volt Typhoon intrusions into US critical infrastructure

Microsoft reported that the China-linked threat actor Volt Typhoon had targeted U.S. critical infrastructure organizations and used living-off-the-land techniques to maintain stealthy access. The activity was described as focused on espionage and persistence across sectors including communications, manufacturing, utilities, transportation, construction, maritime, government, information technology, and education.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.