Volt Typhoon is a China-linked, state-sponsored advanced persistent threat group focused primarily on cyber espionage and long-term pre-positioning in critical infrastructure. The actor is also tracked as Bronze Silhouette, DEV-0391, Insidious Taurus, Storm-0391, UNC3236, Vanguard Panda, Voltzite, and Volt Typhoon (G1017). Reporting places the group’s activity from at least 2021 onward, with operations centered on stealthy access, operational security, and persistence in environments that could support future disruptive action. The group is best known for targeting critical infrastructure and network edge environments, especially in the United States and Guam, with victims spanning communications, utilities, energy, water, transportation, manufacturing, construction, maritime, government, information technology, education, and defense-related organizations. Additional reporting links the actor to activity affecting telecommunications in Singapore and to targeting of U.S. energy and defense sectors. Its targeting pattern is consistent with strategic intelligence collection and contingency preparation rather than overtly destructive operations. Volt Typhoon has repeatedly abused vulnerable internet-facing appliances and small-office/home-office equipment, including routers, firewalls, VPN appliances, and other embedded edge devices. Public reporting associates the actor with compromised-device proxy and botnet infrastructure, notably the KV Botnet and the JDY cluster, used to conceal operator traffic, support covert data transfer, and conduct scanning and reconnaissance. The actor has been linked to exploitation or probing involving edge technologies such as Cisco RV320/325 devices, Citrix NetScaler ADC, and Ivanti Connect Secure, although successful compromise is not always directly observed in every reported cluster. A defining characteristic of Volt Typhoon is extensive living-off-the-land tradecraft. The actor has been described as relying heavily on legitimate administrative tools already present in victim environments instead of deploying conventional malware, particularly in energy, water, and communications networks. At the same time, reporting also links Volt Typhoon-associated operations to tunneling and proxy tooling seen in broader PRC intrusion ecosystems, including use of compromised relay infrastructure and commodity tunneling techniques to hinder attribution and disruption. Observed behaviors include reconnaissance, scanning, theft of browser-stored data from network administrators, credential theft, exfiltration, persistence, lateral movement, post-exploitation, and defense evasion. The actor has targeted browser data such as browsing history and stored credentials, and has used compromised devices as operational relay nodes to mask follow-on intrusion activity. Reporting on associated clusters also indicates interest in maintaining covert access to critical infrastructure over extended periods, including through non-persistent malware on edge devices that can be rapidly re-established after disruption. Volt Typhoon is widely assessed as a PRC-origin espionage actor whose operations align with Chinese state interests. Its campaigns emphasize stealth, infrastructure obfuscation, and access into sectors whose disruption could have strategic effects during a geopolitical crisis, particularly involving U.S. military logistics and regional contingencies in the Indo-Pacific.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
55 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
33 malware families attributed to this actor across reporting.
28 additional families tracked in Mallory.
33 CVEs this actor has used in observed campaigns. 33 of them exploited in the wild.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
Fortinet disclosed in February that the Chinese Volt Typhoon hacking group exploited two FortiOS SSL VPN flaws (CVE-2022-42475 and CVE-2023-27997) to backdoor a Dutch Ministry of Defence military network using custom Coathanger remote access trojan (RAT) malware.
In another Secureworks IR engagement in September 2021, the activity was slightly briefer. This time the attackers exploited a public-facing application to obtain initial access. Secureworks surmised that it was likely to have been an exploitation of CVE-2021-40539 against a ManageEngine ADSelfService Plus server.
"Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection." | Lumen Technologies reported Chinese APT Volt Typhoon exploiting Versa Director servers (CVE-2024-39717), enabling credential interception and malicious code injection.
CVE-2024-21762 (CVSS skóre 9,6) Kritická zraniteľnosť CVE-2024-21762 sa nachádza v komponente sslvpnd a umožňuje zapisovať mimo povolené hodnoty vyrovnávacej pamäte. Úspešné zneužitie umožňuje neautentifikovanému útočníkovi ľubovoľné vykonávanie kódu alebo príkazov prostredníctvom špeciálne vytvorených HTTP požiadaviek. Pre zraniteľnosť nie je vydaná dočasná mitigácia... Zraniteľnosť CVE-2024-21762 môže byť aktívne zneužívaná.
28 more CVEs tied to this actor tracked in Mallory.
177 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a state-linked group associated with long-term prepositioning in electric power and telecommunications networks, illustrating OT/critical infrastructure intrusion risk.
PRC state-sponsored actor referenced comparatively as using living-off-the-land techniques in critical infrastructure environments for pre-positioning rather than disruption.
Referenced as an example of a group known for pre-positioning and quiet persistence against U.S. critical infrastructure; not described as operating ENDLESSDOORS in this report.
Chinese threat actor described as pre-positioning in US critical infrastructure and utility sectors to enable disruption during a future crisis, especially one related to Taiwan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.