SYLVANITE is an initial-access threat group tracked by Dragos since 2025 that compromises industrial organizations and transfers access to other operators, including VOLTZITE, a cluster highly correlated with Volt Typhoon. SYLVANITE operates as a distinct access-enablement group rather than the team responsible for long-term operational technology access or disruptive effects. Its targets include electric power generation, transmission and distribution, water and sewage utilities, oil and gas organizations, and manufacturing companies. Its targeting spans North America, Europe, Asia and the Middle East, with identified activity affecting the United States, United Kingdom, South Korea, Guam, the Philippines and Saudi Arabia. SYLVANITE specializes in rapidly weaponizing disclosed vulnerabilities in internet-facing systems, including products from Ivanti, F5, SAP and ConnectWise, and has targeted vulnerable devices within 48 hours of disclosure. It uses Cobalt Strike, Sliver and web shells to establish access that can support subsequent intrusions toward OT environments. A May 2025 intrusion at a U.S. utility exploited Ivanti Endpoint Manager Mobile vulnerabilities CVE-2025-4427 and CVE-2025-4428, extracted backend database information including LDAP user details and Office 365 tokens, and reused stolen credentials for internal lateral movement. Movement into OT systems was not confirmed in that incident.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Used as a contextual example explaining the need to monitor systems at the IT/OT boundary. Compromises electric utilities through their IT environments and uses that access as a pathway toward operational technology environments.
An access-enablement cluster that gains initial access to operational technology and utility environments and then hands that access off to Volt Typhoon for follow-on activity.
OT-focused activity cluster described as an initial access broker supporting Volt Typhoon/Voltzite by exploiting (weaponizing) vulnerabilities in F5, Ivanti, and SAP products to enable downstream intrusions.
Threat group described as obtaining and weaponizing edge device vulnerabilities before patches are applied, then handing off access for deeper OT intrusions.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.