Volt Typhoon
G1017APT / State-SponsoredChinaActive
Also known as: BRONZE SILHOUETTE · Vanguard Panda · DEV-0391 · UNC3236 · Voltzite · Insidious Taurus · DazedToad
Overview
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet..
Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.
Campaigns — 2
KV Botnet Activity
ended2022-10 → 2024-01
Source: MITRE C0035
Versa Director Zero Day Exploitation
ended2024-06 → 2024-08
Source: MITRE C0039
T1046Network Service DiscoveryDiscovery
T1083File and Directory DiscoveryDiscovery
T1591.004Identify RolesReconnaissance
T1057Process DiscoveryDiscovery
T1021.001Remote Desktop ProtocolLateral Movement
T1584.004ServerResource Development
T1090ProxyCommand and Control
T1518Software DiscoveryDiscovery
Malware & Tools — 17
netshToolWindows
PsExecToolWindows
ipconfigTool
WevtutilToolWindows
VersaMemMalwareNetwork Devices
TasklistTool
MimikatzToolWindows
PingTool
ImpacketToolLinux / macOS / Windows
SysteminfoTool
T1078
Valid Accounts
Stealth
T1584.008Network DevicesResource Development
T1056.001KeyloggingCollection
T1036.005Match Legitimate Resource Name or LocationStealth
T1036.008Masquerade File TypeStealth
T1059.003Windows Command ShellExecution
T1190Exploit Public-Facing ApplicationInitial Access
T1555Credentials from Password StoresCredential Access
T1074Data StagedCollection
T1590Gather Victim Network InformationReconnaissance
T1560.001Archive via UtilityCollection
T1124System Time DiscoveryDiscovery
T1069.002Domain GroupsDiscovery
T1016System Network Configuration DiscoveryDiscovery
T1018Remote System DiscoveryDiscovery
T1047Windows Management InstrumentationExecution
T1133External Remote ServicesPersistence
T1140Deobfuscate/Decode Files or InformationStealth
T1570Lateral Tool TransferLateral Movement
T1593Search Open Websites/DomainsReconnaissance
T1680Local Storage DiscoveryDiscovery
T1589.002Email AddressesReconnaissance
T1497.001System ChecksStealth
T1003.003NTDSCredential Access
T1027.002Software PackingStealth
T1573.001Symmetric CryptographyCommand and Control
T1003.001LSASS MemoryCredential Access
T1685.005Clear Windows Event LogsDefense Impairment
T1584.005BotnetResource Development
T1592Gather Victim Host InformationReconnaissance
T1049System Network Connections DiscoveryDiscovery
T1087.001Local AccountDiscovery
T1217Browser Information DiscoveryDiscovery
T1059.001PowerShellExecution
T1654Log EnumerationDiscovery
T1068Exploitation for Privilege EscalationPrivilege Escalation
T1113Screen CaptureCollection
T1090.001Internal ProxyCommand and Control
T1587.004ExploitsResource Development
T1090.003Multi-hop ProxyCommand and Control
T1594Search Victim-Owned WebsitesReconnaissance
T1033System Owner/User DiscoveryDiscovery
FRPToolLinux / macOS / Windows