Cyber threat actor
Volt Typhoon
PRC state-sponsored (MSS-aligned) · active since Mid-2021
Pre-positioning operations against US critical infrastructure (water, energy, transport, communications) with the apparent goal of disruption during a Taiwan contingency.
Aliases
Vanguard PandaBRONZE SILHOUETTEInsidious Taurus
Primary targets
US critical infrastructure Guam telecom Water utilities Energy sector
MITRE ATT&CK techniques
7 techniques mapped · click any technique ID to open the MITRE ATT&CK entry, any CVE to view its NVD record, or any citation for source reporting.
| Tactic | Technique | Procedure | Targets | Citation |
|---|---|---|---|---|
| Initial Access | T1190 Exploit Public-Facing Application | Exploited Fortinet FortiGuard and Cisco/Netgear edge-device CVEs to obtain footholds in US CI networks. | US energy, water, transport, comms | CISA AA24-038A |
| Persistence | T1505.003 Server Software Component: Web Shell | Deployed web shells on perimeter routers and SOHO devices (KV-botnet) for long-term persistence. | ISP/edge routers | Microsoft Volt Typhoon |
| Defense Evasion | T1218 Signed Binary Proxy Execution (LOLBins) | Operated almost exclusively via built-in Windows utilities (wmic, ntdsutil, netsh, PowerShell), no custom malware. | Windows hosts in CI | CISA AA24-038A |
| Credential Access | T1003.003 OS Credential Dumping: NTDS | Used ntdsutil to extract ntds.dit and the SYSTEM hive for offline cracking. | Active Directory DCs | CISA AA24-038A |
| Discovery | T1018 Remote System Discovery | PowerShell and WMIC enumeration of domain hosts and OT-adjacent assets. | - | CISA AA24-038A |
| Command & Control | T1090.003 Multi-hop Proxy (ORB networks) | Routed C2 through compromised SOHO routers (KV-botnet) to blend with residential traffic. | - | Lumen Black Lotus Labs KV-botnet |
| Impact | T1565 Data Manipulation (pre-positioning) | Maintained access without destructive action, assessed as pre-positioning for Taiwan-contingency disruption. | Critical infrastructure | CISA AA24-038A |
Curated incidents
- 2024-02-07·Water / Energy / Transport·United StatesCISA: Volt Typhoon pre-positioned in US critical infrastructure for 5+ years
Joint advisory with NSA, FBI describes living-off-the-land tradecraft.
- 2023-05-24·Telecom / Government·Guam, US PacificMicrosoft attributes Guam telecom intrusion to Volt Typhoon
First public attribution; framed as Taiwan-contingency pre-positioning.
Live feed mentions
- Wed, 07 Feb 2024 14:00:00 GMT · CISA / NSA / FBI advisory AA24-038AAdvisory AA24-038A: Volt Typhoon pre-positioning inside United States critical infrastructure