Microsoft and U.S. government agencies disclosed that the Chinese state-linked threat group Volt Typhoon infiltrated critical infrastructure organizations in the United States and Guam, with activity affecting sectors including communications, manufacturing, utilities, transportation, construction, maritime, government, information technology, and education. The campaign relied on living-off-the-land techniques to blend into normal administrative activity, using valid accounts, built-in command-line tools, and network equipment to maintain persistence and move laterally while minimizing malware use.
Secureworks identified the same actor as BRONZE SILHOUETTE, linking it to cyberespionage operations against U.S. government and defense organizations. Across observed intrusions, the group conducted reconnaissance, collected and exported Active Directory data including ntds.dit and LDAP objects, deployed web shells on edge devices, and compressed stolen information for exfiltration in short bursts designed to evade detection. U.S. defenders warned that the tradecraft appeared intended to support long-term access and potential disruption of critical services during future geopolitical conflict.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2023-06-30, Anvilogic published an analysis of recurring Volt Typhoon behaviors drawn from previously reported intrusions. The article highlighted reconnaissance, Active Directory data export, and archiving for exfiltration as sequence-based detection opportunities.
On 2023-05-24, Secureworks published a report linking BRONZE SILHOUETTE to targeting of U.S. government and defense organizations. The report described the group's cyberespionage activity and victim focus.
On 2023-05-24, Microsoft published research on Volt Typhoon targeting U.S. critical infrastructure with living-off-the-land techniques. The same day, U.S. government agencies released a joint cybersecurity advisory detailing the threat and associated tradecraft.
Secureworks observed intrusions by the Chinese cyberespionage group BRONZE SILHOUETTE over the period from June 2021 to June 2022. The activity targeted U.S. government, defense, and critical infrastructure organizations and used living-off-the-land techniques and web shells.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
anvilogic.com
Open sourcemicrosoft.com
Open sourcesecureworks.com
Open sourcemedia.defense.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.