G1017: Volt Typhoon
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].
Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]
Security context for executives and security teams
G1017: Volt Typhoon describes [Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. [Volt Typhoon](https://attack.mitre.org/groups/G1017)'s targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. [Volt Typhoon](htt...
Executive priority
G1017: Volt Typhoon is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1017: Volt Typhoon by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1017: Volt Typhoon appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Volt Typhoon
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].
Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1046 | Network Service Discovery | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery.[1] |
| Enterprise | T1083 | File and Directory Discovery | Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings.[1] |
| Enterprise | T1591.004 | Identify RolesSub-technique | Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations.[1] |
| Enterprise | T1057 | Process Discovery | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.[2][4][1] |
| Enterprise | T1021.001 | Remote Desktop ProtocolSub-technique | Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges.[1] |
| Enterprise | T1584.004 | ServerSub-technique | Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.[4][1] |
| Enterprise | T1090 | Proxy | |
| Enterprise | T1518 | Software Discovery | Volt Typhoon has queried the Registry on compromised systems for information on installed software.[3][1] |
| Enterprise | T1078 | Valid Accounts | Volt Typhoon relies primarily on valid credentials for persistence.[1] |
| Enterprise | T1584.008 | Network DevicesSub-technique | Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.[2][3] |
| Enterprise | T1056.001 | KeyloggingSub-technique | Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.[3][4][1] |
| Enterprise | T1036.008 | Masquerade File TypeSub-technique | Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.[4] |
| Enterprise | T1059.003 | Windows Command ShellSub-technique | Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.[2][3][4][1] |
| Enterprise | T1190 | Exploit Public-Facing Application | Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco.[4][1] |
| Enterprise | T1555 | Credentials from Password Stores | Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY.[3] |
| Enterprise | T1074 | Data Staged | Volt Typhoon has staged collected data in password-protected archives.[2] |
| Enterprise | T1590 | Gather Victim Network Information | Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network.[1] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.[4][1] |
| Enterprise | T1124 | System Time Discovery | Volt Typhoon has obtained the victim's system timezone.[1] |
| Enterprise | T1069.002 | Domain GroupsSub-technique | Volt Typhoon has run `net group` in compromised environments to discover domain groups.[4] |
| Enterprise | T1016 | System Network Configuration Discovery | Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.[3] |
| Enterprise | T1018 | Remote System Discovery | Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.[2][4] |
| Enterprise | T1047 | Windows Management Instrumentation | Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.[2][3][4][1] |
| Enterprise | T1133 | External Remote Services | Volt Typhoon has used VPNs to connect to victim environments and enable post-exploitation actions.[1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil.[4] |
| Enterprise | T1570 | Lateral Tool Transfer | Volt Typhoon has copied web shells between servers in targeted environments.[4] |
| Enterprise | T1593 | Search Open Websites/Domains | Volt Typhoon has conducted pre-compromise web searches for victim information.[1] |
| Enterprise | T1680 | Local Storage Discovery | Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.[2][3][4][1] |
| Enterprise | T1589.002 | Email AddressesSub-technique | Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations.[1] |
| Enterprise | T1497.001 | System ChecksSub-technique | Volt Typhoon has run system checks to determine if they were operating in a virtualized environment.[2] |
| Enterprise | T1003.003 | NTDSSub-technique | Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.[2][3][4][1] |
| Enterprise | T1027.002 | Software PackingSub-technique | Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.[1] |
| Enterprise | T1573.001 | Symmetric CryptographySub-technique | Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications.[4] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.[2][1] |
| Enterprise | T1685.005 | Clear Windows Event LogsSub-technique | Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity.[1] |
| Enterprise | T1584.005 | BotnetSub-technique | Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.[1] |
| Enterprise | T1592 | Gather Victim Host Information | Volt Typhoon has conducted pre-compromise reconnaissance for victim host information.[1] |
| Enterprise | T1049 | System Network Connections Discovery | Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.[3][4] |
| Enterprise | T1087.001 | Local AccountSub-technique | Volt Typhoon has executed `net user` and `quser` to enumerate local account information.[1] |
| Enterprise | T1217 | Browser Information Discovery | Volt Typhoon has targeted the browsing history of network administrators.[1] |
| Enterprise | T1059.001 | PowerShellSub-technique | Volt Typhoon has used PowerShell including for remote system discovery.[2][3][1] |
| Enterprise | T1654 | Log Enumeration | Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons.[3][1] |
| Enterprise | T1068 | Exploitation for Privilege Escalation | Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.[1] |
| Enterprise | T1113 | Screen Capture | Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries.[1] |
| Enterprise | T1090.001 | Internal ProxySub-technique | Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.[2][1] |
| Enterprise | T1587.004 | ExploitsSub-technique | Volt Typhoon has exploited zero-day vulnerabilities for initial access.[1] |
| Enterprise | T1090.003 | Multi-hop ProxySub-technique | Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.[1] |
| Enterprise | T1594 | Search Victim-Owned Websites | Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites.[1] |
| Enterprise | T1033 | System Owner/User Discovery | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.[3][4][1] |
| Enterprise | T1112 | Modify Registry | Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG).[1] |
| Enterprise | T1505.003 | Web ShellSub-technique | Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.[4] |
| Enterprise | T1218 | System Binary Proxy Execution | Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.[1] |
| Enterprise | T1059.004 | Unix ShellSub-technique | Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).[1] |
| Enterprise | T1007 | System Service Discovery | Volt Typhoon has used `net start` to list running services.[1] |
| Enterprise | T1069 | Permission Groups Discovery | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.[1] |
| Enterprise | T1584.003 | Virtual Private ServerSub-technique | Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.[1] |
| Enterprise | T1555.003 | Credentials from Web BrowsersSub-technique | Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.[1] |
| Enterprise | T1591 | Gather Victim Org Information | Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.[1] |
| Enterprise | T1590.004 | Network TopologySub-technique | Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies.[1] |
| Enterprise | T1010 | Application Window Discovery | Volt Typhoon has collected window title information from compromised systems.[1] |
| Enterprise | T1069.001 | Local GroupsSub-technique | Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.[3] |
| Enterprise | T1120 | Peripheral Device Discovery | Volt Typhoon has obtained victim's screen dimension and display device information.[1] |
| Enterprise | T1070.004 | File DeletionSub-technique | Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.[4][1] |
| Enterprise | T1588.006 | VulnerabilitiesSub-technique | Volt Typhoon has used publicly available exploit code for initial access.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.[1] |
| Enterprise | T1552 | Unsecured Credentials | Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.[1] |
| Enterprise | T1078.002 | Domain AccountsSub-technique | Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.[2][4][1] |
Groups, software, and campaigns
S0108: netsh
S0029: PsExec
S0100: ipconfig
S0645: Wevtutil
S1154: VersaMem
VersaMem is a web shell designed for deployment to Versa Director servers following exploitation. Discovered in August 2024, VersaMem was used during Versa Director Zero Day Exploitation by Volt Typhoon to target ISPs and MSPs. VersaMem is deployed as a Java Archive (JAR) and allows for credential capture for Versa Director logon activity as well as follow-on execution of arbitrary Java payloads.[1]
S0057: Tasklist
S0002: Mimikatz
S0097: Ping
S0357: Impacket
S0096: Systeminfo
Systeminfo is a Windows utility that can be used to gather detailed information about a computer. [1]
C0035: KV Botnet Activity
KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]
C0039: Versa Director Zero Day Exploitation
Versa Director Zero Day Exploitation was conducted by Volt Typhoon from early June through August 2024 as zero-day exploitation of Versa Director servers controlling software-defined wide area network (SD-WAN) applications. Since tracked as CVE-2024-39717, exploitation focused on credential capture from compromised Versa Director servers at managed service providers (MSPs) and internet service providers (ISPs) to enable follow-on access to service provider clients. Versa Director Zero Day Exploitation was followed by the delivery of the VersaMem web shell for both credential theft and follow-on code execution.[1]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.0 | Current bundle | d0a89811d728… | ||
| 19.1 | 2.0 | Older bundle | 60c198af494e… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]CISA AA24-038A PRC Critical Infrastructure February 2024
CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.
Open source URL - [2]Microsoft Volt Typhoon May 2023
Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.
Open source URL - [3]Joint Cybersecurity Advisory Volt Typhoon June 2023
NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.
Open source URL - [4]Secureworks BRONZE SILHOUETTE May 2023
Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.
Open source URL - [5]DOJ KVBotnet 2024
US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.
Open source URL - [6]Dragos 2025 Year in Review
Dragos. (2026, February). 9TH ANNUAL YEAR IN REVIEW | OT/ICS CYBERSECURITY REPORT . Retrieved April 26, 2026.
Open source URL - [7]BRONZE SILHOUETTE
(Citation: Secureworks BRONZE SILHOUETTE May 2023)(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)
- [8]Cloudflare 2026 Threat Report New Threat Actors March 2026
Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.
Open source URL - [9]DEV-0391
(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)
- [10]DazedToad
(Citation: Cloudflare 2026 Threat Report New Threat Actors March 2026)
- [11]Insidious Taurus
(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)
- [12]UNC3236
(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)
- [13]Vanguard Panda
(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)
- [14]Voltzite
(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)
- [15]mitre-attackG1017Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
