LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1017: Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]

EnterpriseG1017GroupObject v2.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1017: Volt Typhoon describes [Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. [Volt Typhoon](https://attack.mitre.org/groups/G1017)'s targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. [Volt Typhoon](htt...

Executive priority

G1017: Volt Typhoon is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1017: Volt Typhoon by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1017: Volt Typhoon appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].

Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

68 rows
DomainIDNameRelationship / procedure
EnterpriseT1046Network Service Discovery

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for network service discovery.[1]

EnterpriseT1083File and Directory Discovery

Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings.[1]

EnterpriseT1591.004Identify RolesSub-technique

Volt Typhoon has identified key network and IT staff members pre-compromise at targeted organizations.[1]

EnterpriseT1057Process Discovery

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.[2][4][1]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Volt Typhoon has moved laterally to the Domain Controller via RDP using a compromised account with domain administrator privileges.[1]

EnterpriseT1584.004ServerSub-technique

Volt Typhoon has used compromised Paessler Router Traffic Grapher (PRTG) servers from other organizations for C2.[4][1]

EnterpriseT1090Proxy

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.[2][3][1]

EnterpriseT1518Software Discovery

Volt Typhoon has queried the Registry on compromised systems for information on installed software.[3][1]

EnterpriseT1078Valid Accounts

Volt Typhoon relies primarily on valid credentials for persistence.[1]

EnterpriseT1584.008Network DevicesSub-technique

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.[2][3]

EnterpriseT1056.001KeyloggingSub-technique

Volt Typhoon has created and accessed a file named rult3uil.log on compromised domain controllers to capture keypresses and command execution.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.[3][4][1]

EnterpriseT1036.008Masquerade File TypeSub-technique

Volt Typhoon has appended copies of the ntds.dit database with a .gif file extension.[4]

EnterpriseT1059.003Windows Command ShellSub-technique

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.[2][3][4][1]

EnterpriseT1190Exploit Public-Facing Application

Volt Typhoon has gained initial access through exploitation of multiple vulnerabilities in internet-facing software and appliances such as Fortinet, Ivanti (formerly Pulse Secure), NETGEAR, Citrix, and Cisco.[4][1]

EnterpriseT1555Credentials from Password Stores

Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY.[3]

EnterpriseT1074Data Staged

Volt Typhoon has staged collected data in password-protected archives.[2]

EnterpriseT1590Gather Victim Network Information

Volt Typhoon has conducted extensive pre-compromise reconnaissance to learn about the target organization’s network.[1]

EnterpriseT1560.001Archive via UtilitySub-technique

Volt Typhoon has archived the ntds.dit database as a multi-volume password-protected archive with 7-Zip.[4][1]

EnterpriseT1124System Time Discovery

Volt Typhoon has obtained the victim's system timezone.[1]

EnterpriseT1069.002Domain GroupsSub-technique

Volt Typhoon has run `net group` in compromised environments to discover domain groups.[4]

EnterpriseT1016System Network Configuration Discovery

Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.[3]

EnterpriseT1018Remote System Discovery

Volt Typhoon has used multiple methods, including Ping, to enumerate systems on compromised networks.[2][4]

EnterpriseT1047Windows Management Instrumentation

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.[2][3][4][1]

EnterpriseT1133External Remote Services

Volt Typhoon has used VPNs to connect to victim environments and enable post-exploitation actions.[1]

EnterpriseT1140Deobfuscate/Decode Files or Information

Volt Typhoon has used Base64-encoded data to transfer payloads and commands, including deobfuscation via certutil.[4]

EnterpriseT1570Lateral Tool Transfer

Volt Typhoon has copied web shells between servers in targeted environments.[4]

EnterpriseT1593Search Open Websites/Domains

Volt Typhoon has conducted pre-compromise web searches for victim information.[1]

EnterpriseT1680Local Storage Discovery

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.[2][3][4][1]

EnterpriseT1589.002Email AddressesSub-technique

Volt Typhoon has targeted the personal emails of key network and IT staff at victim organizations.[1]

EnterpriseT1497.001System ChecksSub-technique

Volt Typhoon has run system checks to determine if they were operating in a virtualized environment.[2]

EnterpriseT1003.003NTDSSub-technique

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.[2][3][4][1]

EnterpriseT1027.002Software PackingSub-technique

Volt Typhoon has used the Ultimate Packer for Executables (UPX) to obfuscate the FRP client files BrightmetricAgent.exe and SMSvcService.ex) and the port scanning utility ScanLine.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

Volt Typhoon has used a version of the Awen web shell that employed AES encryption and decryption for C2 communications.[4]

EnterpriseT1003.001LSASS MemorySub-technique

Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.[2][1]

EnterpriseT1685.005Clear Windows Event LogsSub-technique

Volt Typhoon has selectively cleared Windows Event Logs, system logs, and other technical artifacts to remove evidence of intrusion activity.[1]

EnterpriseT1584.005BotnetSub-technique

Volt Typhoon has used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations.[1]

EnterpriseT1592Gather Victim Host Information

Volt Typhoon has conducted pre-compromise reconnaissance for victim host information.[1]

EnterpriseT1049System Network Connections Discovery

Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.[3][4]

EnterpriseT1087.001Local AccountSub-technique

Volt Typhoon has executed `net user` and `quser` to enumerate local account information.[1]

EnterpriseT1217Browser Information Discovery

Volt Typhoon has targeted the browsing history of network administrators.[1]

EnterpriseT1059.001PowerShellSub-technique

Volt Typhoon has used PowerShell including for remote system discovery.[2][3][1]

EnterpriseT1654Log Enumeration

Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons.[3][1]

EnterpriseT1068Exploitation for Privilege Escalation

Volt Typhoon has gained initial access by exploiting privilege escalation vulnerabilities in the operating system or network services.[1]

EnterpriseT1113Screen Capture

Volt Typhoon has obtained a screenshot of the victim's system using the gdi32.dll and gdiplus.dll libraries.[1]

EnterpriseT1090.001Internal ProxySub-technique

Volt Typhoon has used the built-in netsh `port proxy` command to create proxies on compromised systems to facilitate access.[2][1]

EnterpriseT1587.004ExploitsSub-technique

Volt Typhoon has exploited zero-day vulnerabilities for initial access.[1]

EnterpriseT1090.003Multi-hop ProxySub-technique

Volt Typhoon has used multi-hop proxies for command-and-control infrastructure.[1]

EnterpriseT1594Search Victim-Owned Websites

Volt Typhoon has conducted pre-compromise reconnaissance on victim-owned sites.[1]

EnterpriseT1033System Owner/User Discovery

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.[3][4][1]

EnterpriseT1112Modify Registry

Volt Typhoon has used `netsh` to create a PortProxy Registry modification on a compromised server running the Paessler Router Traffic Grapher (PRTG).[1]

EnterpriseT1505.003Web ShellSub-technique

Volt Typhoon has used webshells, including ones named AuditReport.jspx and iisstart.aspx, in compromised environments.[4]

EnterpriseT1218System Binary Proxy Execution

Volt Typhoon has used native tools and processes including living off the land binaries or “LOLBins" to maintain and expand access to the victim networks.[1]

EnterpriseT1059.004Unix ShellSub-technique

Volt Typhoon has used Brightmetricagent.exe which contains a command- line interface (CLI) library that can leverage command shells including Z Shell (zsh).[1]

EnterpriseT1007System Service Discovery

Volt Typhoon has used `net start` to list running services.[1]

EnterpriseT1069Permission Groups Discovery

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.[1]

EnterpriseT1584.003Virtual Private ServerSub-technique

Volt Typhoon has compromised Virtual Private Servers (VPS) to proxy C2 traffic.[1]

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Volt Typhoon has targeted network administrator browser data including browsing history and stored credentials.[1]

EnterpriseT1591Gather Victim Org Information

Volt Typhoon has conducted extensive reconnaissance pre-compromise to gain information about the targeted organization.[1]

EnterpriseT1590.004Network TopologySub-technique

Volt Typhoon has conducted extensive reconnaissance of victim networks including identifying network topologies.[1]

EnterpriseT1010Application Window Discovery

Volt Typhoon has collected window title information from compromised systems.[1]

EnterpriseT1069.001Local GroupsSub-technique

Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.[3]

EnterpriseT1120Peripheral Device Discovery

Volt Typhoon has obtained victim's screen dimension and display device information.[1]

EnterpriseT1070.004File DeletionSub-technique

Volt Typhoon has run `rd /S` to delete their working directories and deleted systeminfo.dat from `C:\Users\Public\Documentsfiles`.[4][1]

EnterpriseT1588.006VulnerabilitiesSub-technique

Volt Typhoon has used publicly available exploit code for initial access.[1]

EnterpriseT1105Ingress Tool Transfer

Volt Typhoon has downloaded an outdated version of comsvcs.dll to a compromised domain controller in a non-standard folder.[1]

EnterpriseT1552Unsecured Credentials

Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.[1]

EnterpriseT1078.002Domain AccountsSub-technique

Volt Typhoon has used compromised domain accounts to authenticate to devices on compromised networks.[2][4][1]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0108: netsh

netsh is a scripting utility used to interact with networking components on local or remote systems. [1]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S0100: ipconfig

ipconfig is a Windows utility that can be used to find information about a system's TCP/IP, DNS, DHCP, and adapter configuration. [1]

ToolEnterprise

S0645: Wevtutil

Wevtutil is a Windows command-line utility that enables administrators to retrieve information about event logs and publishers.[1]

Windows
ToolEnterprise

S0057: Tasklist

The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It is packaged with Windows operating systems and can be executed from the command-line interface. [1]

ToolEnterprise

S0002: Mimikatz

Mimikatz is a credential dumper capable of obtaining plaintext Windows account logins and passwords, along with many other features that make it useful for testing the security of networks. [1] [2]

Windows
ToolEnterprise

S0097: Ping

Ping is an operating system utility commonly used to troubleshoot and verify network connections. [1]

ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
CampaignEnterprise

C0035: KV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]

CampaignEnterprise

C0039: Versa Director Zero Day Exploitation

Versa Director Zero Day Exploitation was conducted by Volt Typhoon from early June through August 2024 as zero-day exploitation of Versa Director servers controlling software-defined wide area network (SD-WAN) applications. Since tracked as CVE-2024-39717, exploitation focused on credential capture from compromised Versa Director servers at managed service providers (MSPs) and internet service providers (ISPs) to enable follow-on access to service provider clients. Versa Director Zero Day Exploitation was followed by the delivery of the VersaMem web shell for both credential theft and follow-on code execution.[1]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.0
Created
Modified
Raw hash
d0a89811d7283a37...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.0Current bundled0a89811d728…
19.12.0Older bundle60c198af494e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA AA24-038A PRC Critical Infrastructure February 2024

    CISA et al.. (2024, February 7). PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure. Retrieved May 15, 2024.

    Open source URL
  2. [2]
    Microsoft Volt Typhoon May 2023

    Microsoft Threat Intelligence. (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023.

    Open source URL
  3. [3]
    Joint Cybersecurity Advisory Volt Typhoon June 2023

    NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.

    Open source URL
  4. [4]
    Secureworks BRONZE SILHOUETTE May 2023

    Counter Threat Unit Research Team. (2023, May 24). Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations. Retrieved July 27, 2023.

    Open source URL
  5. [5]
    DOJ KVBotnet 2024

    US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.

    Open source URL
  6. [6]
    Dragos 2025 Year in Review

    Dragos. (2026, February). 9TH ANNUAL YEAR IN REVIEW | OT/ICS CYBERSECURITY REPORT . Retrieved April 26, 2026.

    Open source URL
  7. [7]
    BRONZE SILHOUETTE

    (Citation: Secureworks BRONZE SILHOUETTE May 2023)(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)

  8. [8]
    Cloudflare 2026 Threat Report New Threat Actors March 2026

    Cloudflare. (2026, March 3). Introducing the 2026 Cloudflare Threat Report. Retrieved April 18, 2026.

    Open source URL
  9. [9]
    DEV-0391

    (Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)

  10. [10]
    DazedToad

    (Citation: Cloudflare 2026 Threat Report New Threat Actors March 2026)

  11. [11]
    Insidious Taurus

    (Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)

  12. [12]
    UNC3236

    (Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)

  13. [13]
    Vanguard Panda

    (Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)

  14. [14]
    Voltzite

    (Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)

  15. [15]
    mitre-attackG1017
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.