Volt Typhoon is a China-linked state-sponsored threat actor associated with long-term clandestine access operations against critical infrastructure, particularly in the United States and other foreign environments. The group is widely assessed as affiliated with the People’s Republic of China and is known for pre-positioning within victim networks to enable future disruption, intelligence collection, or strategic contingency operations rather than relying solely on conventional espionage objectives. Known aliases include Bronze Silhouette, DEV-0391, Insidious Taurus, Storm-0391, UNC3236, Vanguard Panda, Volt Typhoon APT, Volt Typhoon (G1017), and Voltzite. Voltzite is also used by Dragos to track related activity affecting industrial and critical infrastructure environments. Volt Typhoon is best known for targeting communications, energy, transportation, water, and wastewater sectors, with reporting also linking its activity to telecommunications and broader critical infrastructure. Its operations are frequently characterized as pre-positioning for potential geopolitical crises, including scenarios involving the Western Pacific or Taiwan, by establishing durable access inside infrastructure that could support later disruption of military mobilization, civilian communications, or public confidence. The actor is notable for extensive use of living-off-the-land tradecraft and operational security measures designed to blend into normal administrative activity. Rather than depending heavily on distinctive malware, Volt Typhoon commonly abuses legitimate credentials, native system utilities, administrative tooling, and compromised edge or SOHO network devices to conceal origin and persistence. Publicly documented behavior includes software discovery through Windows Registry queries, host and storage enumeration, and use of common administrative commands and scripting environments. Reporting also describes use of compromised SOHO routers and botnet infrastructure to obscure operations and support covert collection against infrastructure targets. Across ATT&CK-aligned reporting, Volt Typhoon has been associated with post-compromise discovery, credential access, privilege escalation, defense evasion, and persistence behaviors that overlap substantially with other Chinese intrusion sets. Comparative analyses of Chinese threat actors place Volt Typhoon close to APT41 and Mustang Panda in terms of documented TTP overlap, especially in discovery, credential access, and defense evasion. This supports the assessment that the group follows a mature and standardized enterprise intrusion methodology emphasizing stealth, access expansion, and long-term survivability. In industrial and OT contexts, Volt Typhoon is regarded as a significant threat because its low-noise administrative tradecraft can be difficult to distinguish from legitimate engineering or IT activity, particularly on static systems with limited endpoint monitoring. The group has been repeatedly cited as an example of PRC-linked pre-positioning inside critical infrastructure, including energy, water, and telecommunications environments, and remains one of the most prominent Chinese actors associated with strategic access operations below the threshold of overt disruptive attack.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
49 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
31 malware families attributed to this actor across reporting.
26 additional families tracked in Mallory.
33 CVEs this actor has used in observed campaigns. 33 of them exploited in the wild.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
"Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection." | Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection.
Exploiting vulnerabilities in widely used software including, but not limited to: CVE-2021-40539—ManageEngine ADSelfService Plus.
Ensure that these products in your environment are updated with the latest patches... Ivanti (CVE-2024-21887 & CVE-2023-46805)
28 more CVEs tied to this actor tracked in Mallory.
132 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Chinese espionage cluster described as maintaining persistent access in foreign critical infrastructure for potential future contingency use.
China-linked group maintaining long-term access to critical infrastructure including energy and water sectors.
Referenced as a historical case in a course discussion about operational tendencies of different APTs and cyber conflict history.
State-sponsored cluster mentioned as a user of the Raptor Train botnet infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.