>samit_hota
Back to adversary profiles
G1017CriticalActive

Volt Typhoon: PRC's Critical Infrastructure Sabotage Force

Samit Hota·
Suspected Origin
People's Republic of China
Motivation
Cyberwarfare, Strategic Military Advantage, Pre-positioning for Disruptive Attacks, Espionage
Aliases
BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad
Target Sectors
Communications, Energy, Transportation Systems, Water and Wastewater Systems, Manufacturing, Maritime, Government, Information Technology, Education
Associated Malware
KV Botnet, Impacket (custom), Fast Reverse Proxy (FRP) (custom), Mimikatz
#threat-actor#g1017

Overview

Volt Typhoon, identified by the MITRE ATT&CK ID G1017, is a People’s Republic of China (PRC) state-sponsored threat actor that has been active since at least mid-2021. This highly stealthy group primarily targets critical infrastructure organizations in the United States and its territories, including Guam, with an alarming shift from traditional espionage to pre-positioning capabilities for potential disruptive or destructive cyberattacks during a future crisis. This strategic objective, particularly in the context of potential geopolitical tensions (e.g., over Taiwan), aims to compromise critical communications infrastructure between the US and Asia, or to degrade logistics and delay military deployments.

The group’s targeting extends across vital sectors such as communications, energy, transportation systems, and water and wastewater systems, but also includes manufacturing, maritime, government, information technology, and education. Beyond the US, Volt Typhoon has shown interest in critical infrastructure in Australia and the broader Asia-Pacific region, including a notable breach in Singapore. Their operations are characterized by an emphasis on stealth and long-term persistence, often maintaining covert access to victim networks for extended periods, sometimes for years. The Chinese government has publicly denied any involvement with Volt Typhoon, dismissing it as a misinformation campaign.

Tactics & Techniques

Volt Typhoon employs sophisticated tactics designed to evade detection and blend into normal network activity. Initial access is often achieved by exploiting vulnerabilities in internet-facing edge devices, including small office/home office (SOHO) routers, and appliances from vendors such as Fortinet, Ivanti, NETGEAR, Citrix, and Cisco. They also leverage weak administrator passwords and factory default logins for initial compromise.

A hallmark of Volt Typhoon’s operational methodology is its heavy reliance on “living-off-the-land” (LOTL) techniques. Instead of deploying custom malware, the group extensively uses legitimate, built-in system tools like wmic, ntdsutil, netsh, PowerShell, and ping to conduct reconnaissance, move laterally, and maintain persistence. This approach makes their activities extremely difficult to detect by traditional endpoint detection and response (EDR) solutions, as malicious actions are masked as routine administrative tasks. Commands are sometimes encoded in Base64 to further obscure their intent in logs.

For defense evasion and command and control (C2), Volt Typhoon frequently utilizes compromised SOHO routers and network devices, collectively known as the KV botnet (or JDYFJ botnet), to proxy their traffic. This tactic obscures the true origin of their operations and complicates attribution. The group also employs custom versions of open-source tools like Impacket and Fast Reverse Proxy (FRP) to establish C2 channels. Application layer protocols such as HTTP, HTTPS, and DNS are also leveraged for C2 communications, exploiting their ubiquity to blend into legitimate network traffic.

Credential access is a key objective, often involving techniques such as credential dumping from the Local Security Authority Subsystem Service (LSASS) using tools like Mimikatz. They also harvest credentials from network administrator browser data, OpenSSH, realvnc, and PuTTY profiles, which can grant access to critical systems including those for water treatment plants and electrical substations.

Volt Typhoon conducts extensive discovery and reconnaissance post-compromise, mapping networks, gathering system information, identifying running processes, and discovering domain controllers. Lateral movement often occurs using stolen administrator credentials via Remote Desktop Protocol (RDP) or by creating internal proxies with netsh portproxy.

Recent reporting indicates that a separate initial access cluster, known as SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon (also tracked as VOLTZITE) for follow-on operations. [MITRE summary, 24, 27, 31] SYLVANITE has weaponized vulnerabilities in products from F5, Ivanti, and SAP to gain initial access, particularly within operational technology (OT) environments.

Notable Campaigns

Volt Typhoon’s activity gained significant public attention in May 2023 when Microsoft and a coalition of “Five Eyes Alliance” cybersecurity agencies issued joint advisories detailing the group’s malicious activities targeting US critical infrastructure since mid-2021. These advisories highlighted the strategic shift towards pre-positioning for disruptive attacks.

In January 2024, the FBI announced a court-authorized disruption of the KV botnet, successfully removing malware from hundreds of compromised US-based SOHO routers. However, the botnet has since been revived and continues to be leveraged by the group.

February 2024 saw the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) release a joint Cybersecurity Advisory (AA24-038A), further confirming widespread Volt Typhoon compromises in communications, energy, transportation systems, and water and wastewater systems across the continental and non-continental United States and its territories, including Guam.

Other notable incidents include the targeting of military strategic locations in Hawaii, Guam, the West Coast, and Texas in December 2023, and a breach of a Singapore-based telecommunications company, Singtel, in June 2024, which was considered a potential test run for attacks on US telecom providers. Between June and August 2024, Volt Typhoon also conducted the “Versa Director Zero Day Exploitation,” leveraging a vulnerability (CVE-2024-39717) in Versa Director servers for initial access and code execution. As late as November 2025, Australian intelligence identified Volt Typhoon attempts to access critical infrastructure within Australia.

Associated Malware & Tools

While heavily relying on LOTL techniques, Volt Typhoon does utilize specific tools and infrastructure:

  • KV Botnet (and JDYFJ Botnet): A crucial component of their infrastructure, this botnet consists of compromised SOHO routers and network devices (e.g., from ASUS, Cisco, D-Link, NETGEAR, Zyxel, DrayTek) used to proxy command and control traffic and obfuscate the group’s origin.
  • Web Shells: Employed for persistence and remote access within compromised networks. [MITRE summary, 6]
  • Custom Open-Source Tools: The group has been observed using customized versions of open-source tools such as Impacket and Fast Reverse Proxy (FRP) to establish C2 channels.
  • Mimikatz: A popular open-source tool leveraged for credential dumping, specifically to extract plaintext passwords, hashed credentials, and Kerberos tickets from the Local Security Authority Subsystem Service (LSASS) process in memory.
  • Living-Off-The-Land (LOTL) Binaries: While not “malware” in the traditional sense, Volt Typhoon’s extensive use of native Windows utilities like wmic, ntdsutil, netsh, PowerShell, and ping constitutes their primary “toolset” for post-exploitation activities.
  • VPNs: Used to connect to victim environments and facilitate post-exploitation actions, often creating direct communication channels between the attackers and the victim’s network.

Current Status

Volt Typhoon remains an active and persistent threat as of mid-2026. Despite the FBI’s disruption of the KV botnet in early 2024, the botnet was quickly revived, indicating the group’s resilience and determination. Reports from 2025 and 2026 continue to highlight Volt Typhoon’s ongoing intrusions into critical infrastructure, including cellular gateways and routers impacting US electric, oil, and gas companies.

The emergence of the SYLVANITE cluster as an initial access broker for Volt Typhoon demonstrates an evolution in their operational model, further enhancing their capabilities to compromise operational technology (OT) environments. Security agencies and experts continue to assess Volt Typhoon as a sustained, high-risk threat with a long-term strategy for maintaining covert access to vital lifeline sectors, positioning itself to disrupt these critical services during a future crisis. Their advanced tactics, emphasizing stealth, persistence, and an ability to operate across both IT and OT environments, reflect a high level of operational maturity and a persistent danger to national security and public services.

Worried this actor targets your sector?

Let's map your exposure before they find it themselves.

Book an advisory call