Volt Typhoon — APT Profile

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.

Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.

Also tracked as

Bronze Silhouette, DEV-0391, Insidious Taurus, UNC3236, VANGUARD PANDA, VOLTZITE, Storm-0391

IntelFusions coverage (2)

Tools & malware

Recent claimed victims

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions