Volt Typhoon is a China-linked state-associated cyber espionage actor focused on compromising U.S. critical infrastructure and other American interests. The group is widely characterized by stealthy post-compromise tradecraft, especially extensive living-off-the-land activity that relies on legitimate administrative tools and existing remote management or monitoring capabilities within victim environments rather than conspicuous malware deployment. A notable operational pattern is the compromise of edge infrastructure, including residential and small-office routers, to route operations through residential IP space and reduce attribution visibility. The actor’s targeting has been associated with U.S. entities and critical infrastructure environments. Its tradecraft emphasizes covert access, persistence, defense evasion, and post-exploitation through native system capabilities and intermediary network devices. Volt Typhoon is one of the Chinese government-related intrusion sets tracked under Microsoft’s "Typhoon" naming convention.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.