SentinelLABS reported that China’s Computer Virus Emergency Response Center (CVERC) published another report alleging that the U.S. government, rather than China, was responsible for Volt Typhoon activity, but the analysis found the document offered no new evidence. The report was presented as part of a broader messaging effort that sought to recast a widely tracked cyber-espionage campaign and shift blame away from Beijing.
According to SentinelLABS, the publication fits a recurring state-directed influence pattern in which Chinese cybersecurity firms, CVERC, state media, and official channels amplify accusations of U.S. hacking using older leaked intelligence material. The campaign was assessed as aiming to weaken support for U.S. Section 702 surveillance authorities, bolster efforts to remove foreign technology such as Microsoft from Chinese government systems, and divert attention from recent Chinese espionage incidents in Europe; its release in multiple languages, including Japanese, French, and German, also indicated an effort to shape opinion beyond China.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
China's Computer Virus Emergency Response Center issued a third report claiming the U.S. government, rather than China, was behind Volt Typhoon activity. SentinelLABS assessed that the report provided no new evidence and fit a broader Beijing influence narrative.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.