LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1017: Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.CitationCISA AA24-038A PRC Critical Infrastructure February 2024CitationMicrosoft Volt Typhoon May 2023CitationJoint Cybersecurity Advisory Volt Typhoon June 2023CitationSecureworks BRONZE SILHOUETTE May 2023. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.CitationDOJ KVBotnet 2024.

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. CitationDragos 2025 Year in Review

EnterpriseG1017GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Volt Typhoon matters because ATT&CK describes it as a PRC state-sponsored group focused on U.S. critical infrastructure and assessed pre-positioning for possible disruptive or destructive operations against OT. For leaders, the key issue is not a single malware family; it is whether the organization can detect stealthy hands-on-keyboard activity, stolen credential use, web shells, and living-off-the-land administration tools before access reaches critical operations.

Executive priority

Treat this as a resilience and governance question for critical services, not only a SOC alerting problem. Executives should ask whether internet-facing edge devices, SD-WAN/managed service dependencies, domain controllers, and OT-adjacent pathways are inventoried, monitored, and included in incident response playbooks. The relationship context highlights credential capture, compromised SOHO infrastructure used to obscure traffic, and native Windows tools, so budget and audit evidence should prioritize identity security, edge-device lifecycle management, domain controller protection, and logging coverage across IT-to-OT boundaries.

Technical view

ATT&CK provides no group-level detection text or platforms, but relationships show use of Windows credential and administration tooling such as Mimikatz, PsExec, Net, Reg, cmd, netsh, certutil, Nltest, Wevtutil, Impacket, and discovery utilities. Related techniques include LSASS Memory, NTDS, Data from Local System, Direct Volume Access, and System Service Discovery. Detection teams should validate behavior-based coverage for credential access, domain discovery, remote execution, event log interrogation, proxy tooling such as FRP, and web shell activity tied to network devices such as Versa Director in the related campaign context.

Likely telemetry

  • Endpoint process creation with command line, parent process, user, host, and integrity context for Windows native utilities and admin tools
  • Authentication, Kerberos, SMB/RPC, remote service creation, and domain controller security logs
  • Directory services and domain controller telemetry relevant to NTDS access or unusual credential material access
  • EDR or host telemetry for LSASS access attempts, credential dumping tools, and direct volume access indicators
  • Network flow, firewall, proxy, VPN, and SD-WAN/controller logs showing unusual administrative access or proxy patterns

Detection direction

  • Prioritize correlated behavior over static indicators: edge-device access or web shell evidence followed by credential collection, discovery commands, remote execution, and lateral movement attempts is more meaningful than any single utility invocation.
  • Tune carefully for false positives because many related tools are legitimate administrator utilities. Baseline where PsExec, Net, Reg, cmd, netsh, certutil, Nltest, Wevtutil, and Impacket-like activity are expected, then alert on unusual users, hosts, time windows, destinations, or sequences.
  • Validate domain controller and identity telemetry specifically; relationships to LSASS Memory and NTDS make credential access coverage a central detection requirement.
  • Check blind spots around internet-facing network devices, SD-WAN controllers, MSP/ISP dependencies, SOHO infrastructure, and OT-adjacent routing paths, where EDR-level visibility may not exist.
  • Include campaign context in hunts: KV Botnet Activity used compromised SOHO equipment to obscure victim connectivity, and Versa Director Zero Day Exploitation involved credential capture from compromised Versa Director servers.

Mitigation priorities

  • Start with exposure reduction: inventory and harden internet-facing edge devices, SD-WAN controllers, network devices, and retire or isolate end-of-life SOHO equipment where applicable.
  • Protect identity infrastructure: restrict administrative access, reduce standing privilege, monitor domain controllers, and limit conditions that allow LSASS or NTDS credential material exposure.
  • Segment and control IT-to-OT pathways so compromised enterprise credentials or remote administration paths cannot easily reach operational technology assets.
  • Constrain and monitor legitimate administration tooling rather than assuming it can be blocked outright; require accountable administrative workflows and centralized logging.
  • Ensure incident response playbooks cover stealthy living-off-the-land intrusions, credential theft, web shells, proxy infrastructure, and third-party or managed-service access paths.
Additional notes and limits

The supplied ATT&CK object is a group profile with rich relationship context but no official detection guidance and no group-level platforms or tactics. The strongest defensive value comes from combining the official description with linked campaigns, software, and techniques: stealth, stolen credentials, web shells, LOTL binaries, hands-on-keyboard activity, compromised SOHO proxying, and Versa Director exploitation context.

This take does not assess current exposure or active exploitation in any specific environment. Local asset inventory, identity architecture, logging coverage, third-party connectivity, and OT network design are required to determine actual risk and detection coverage. ATT&CK relationship descriptions are partially truncated in the supplied data, so conclusions are limited to the provided fields.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.CitationCISA AA24-038A PRC Critical Infrastructure February 2024CitationMicrosoft Volt Typhoon May 2023CitationJoint Cybersecurity Advisory Volt Typhoon June 2023CitationSecureworks BRONZE SILHOUETTE May 2023. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.CitationDOJ KVBotnet 2024.

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. CitationDragos 2025 Year in Review

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
2.0
Created
Modified
Raw hash
60c198af494ee240...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.