Threat actor
Volt Typhoon
Last fetched
Volt Typhoon is a threat actor tracked in WhisperGraph's MITRE ATT&CK corpus, observed using 81 techniques and also known as 11 other names.
Also known as
BRONZE SILHOUETTE, VANGUARD PANDA, UNC3236, Insidious Taurus, VOLTZITE, Dev-0391, Storm-0391, Vanguard Panda, DEV-0391, Voltzite, DazedToad
Description
[Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. [Volt Typhoon](https://attack.mitre.org/groups/G1017)'s targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. [Volt Typhoon](https://attack.mitre.org/groups/G1017) has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)(Citation: Microsoft Volt Typhoon May 2023)(Citation: Joint Cybersecurity Advisory Volt Typhoon June 2023)(Citation: Secureworks BRONZE SILHOUETTE May 2023). The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.(Citation: DOJ KVBotnet 2024). Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to [Volt Typhoon](https://attack.mitre.org/groups/G1017), also tracked as VOLTZITE, for follow-on operations. (Citation: Dragos 2025 Year in Review)
Techniques by tactic
Discovery
- T1007 · System Service Discovery
- T1010 · Application Window Discovery
- T1012 · Query Registry
- T1016 · System Network Configuration Discovery
- T1016.001 · Internet Connection Discovery
- T1018 · Remote System Discovery
- T1033 · System Owner/User Discovery
- T1046 · Network Service Discovery
- T1049 · System Network Connections Discovery
- T1057 · Process Discovery
- T1069 · Permission Groups Discovery
- T1069.001 · Local Groups
- T1069.002 · Domain Groups
- T1083 · File and Directory Discovery
- T1087.001 · Local Account
- T1087.002 · Domain Account
- T1120 · Peripheral Device Discovery
- T1124 · System Time Discovery
- T1217 · Browser Information Discovery
- T1497.001 · System Checks
- T1518 · Software Discovery
- T1614 · System Location Discovery
- T1654 · Log Enumeration
- T1680 · Local Storage Discovery
Reconnaissance
- T1589 · Gather Victim Identity Information
- T1589.002 · Email Addresses
- T1590 · Gather Victim Network Information
- T1590.004 · Network Topology
- T1590.006 · Network Security Appliances
- T1591 · Gather Victim Org Information
- T1591.004 · Identify Roles
- T1592 · Gather Victim Host Information
- T1593 · Search Open Websites/Domains
- T1594 · Search Victim-Owned Websites
- T1596.005 · Scan Databases
Stealth
- T1006 · Direct Volume Access
- T1027.002 · Software Packing
- T1036.005 · Match Legitimate Resource Name or Location
- T1036.008 · Masquerade File Type
- T1070.004 · File Deletion
- T1070.007 · Clear Network Connection History and Configurations
- T1078 · Valid Accounts
- T1078.002 · Domain Accounts
- T1140 · Deobfuscate/Decode Files or Information
- T1218 · System Binary Proxy Execution
- T1497.001 · System Checks
Attributed infrastructure
None published. WhisperGraph carries no ATTRIBUTED_TO edge to Volt Typhoon today — this states the absence of a published link, not that Volt Typhoon has no infrastructure.
References
- https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations
- https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/
- https://unit42.paloaltonetworks.com/volt-typhoon-threat-brief/
- https://www.dragos.com/threat/voltzite/
- https://attack.mitre.org/groups/G1017
- https://blog.cloudflare.com/2026-threat-report/
- https://www.cisa.gov/sites/default/files/2024-03/aa24-038a_csa_prc_state_sponsored_actors_compromise_us_critical_infrastructure_3.pdf
- https://web.archive.org/web/20230601025540/https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations
- https://5943619.hs-sites.com/hubfs/312-Year-in-Review/2026/Dragos-2026-OT-Cybersecurity-Report-A-Year-in-Review.pdf?hsCtaAttrib=205683189348
- https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA_Living_off_the_Land.PDF
- https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from Volt Typhoon into its techniques, tactics and any attributed infrastructure.
Queries
Resolves the slug to this actor, merging every duplicate node sharing the same name.
MATCH (a:ACTOR)
WHERE a.name =~ $pattern OR any(x IN a.aliases WHERE x =~ $pattern)
RETURN a.id AS id, a.name AS name, a.aliases AS aliases, a.description AS description,
a.references AS references, a.campaigns AS campaigns
LIMIT 25Run yourself →Techniques this actor uses, grouped by the tactic each one serves.
MATCH (a:ACTOR {name: $name})-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN)
OPTIONAL MATCH (t)-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN t.id AS techniqueId, t.name AS techniqueName, tac.id AS tacticId, tac.name AS tacticName
LIMIT 1000Run yourself →Infrastructure publicly attributed to this actor.
MATCH (n)-[:ATTRIBUTED_TO]->(a:ACTOR {name: $name})
RETURN labels(n)[0] AS kind, n.name AS name
LIMIT 25Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.