Volt Typhoon — APT Profile
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.Also tracked as
Bronze Silhouette, DEV-0391, Insidious Taurus, UNC3236
Tools & malware
- certutil LOLBin
- cmd Execution
- FRP Tunneling Tool
- Impacket Network Toolkit
- ipconfig Network Reconnaissance
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- netsh LOLBin
- netstat Network Reconnaissance
- Nltest Network Reconnaissance
- Ping Network Reconnaissance
- PsExec Remote Execution
- Reg LOLBin
- Systeminfo Discovery
- Tasklist Discovery
- VersaMem Backdoor
- Wevtutil Discovery
Recent claimed victims
Vendor research
- U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure US Department of Justice
- Introducing the 2026 Cloudflare Threat Report Cloudflare
- Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations Counter Threat Unit Research Team
- 9TH ANNUAL YEAR IN REVIEW | OT/ICS CYBERSECURITY REPORT Dragos
- PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure CISA AA
- Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations Secureworks
- Volt Typhoon targets US critical infrastructure with living-off-the-land techniques Microsoft
- People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection Joint Cybersecurity Advisory Volt Typhoon