SYLVANITE is an OT-focused initial access group tracked as part of the broader China-linked Volt Typhoon ecosystem and assessed to operate in support of VOLTZITE. Its role is to rapidly weaponize newly disclosed vulnerabilities in internet-facing edge and enterprise products, establish footholds in industrial organizations, and hand that access to follow-on operators for deeper operational technology intrusion. Reported exploitation has included products from F5, Ivanti, SAP, and ConnectWise, with activity sometimes occurring within 48 hours of vulnerability disclosure. SYLVANITE has targeted industrial and critical-infrastructure organizations across North America, Europe, the United Kingdom, Asia, the Middle East, South Korea, Guam, the Philippines, and Saudi Arabia. Victim sectors include electric power generation, transmission and distribution, water and sewage, oil and gas, and manufacturing. The group has been described as a large-scale access-enablement operation focused on internet-facing systems rather than long-term occupation or direct disruptive effects. Observed tradecraft includes rapid vulnerability exploitation for initial access, use of web shells and post-compromise tooling such as Cobalt Strike and Sliver, credential theft including directory-service user details and cloud-service tokens in at least one utility intrusion, and replay of stolen credentials for internal movement. SYLVANITE’s activity illustrates a specialized division of labor in which one team develops and brokers access while another conducts deeper OT operations. The dominant motivation is espionage-oriented strategic access enablement in support of potential future disruptive operations against critical infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An access-enablement cluster that gains initial access to operational technology and utility environments and then hands that access off to Volt Typhoon for follow-on activity.
OT-focused activity cluster described as an initial access broker supporting Volt Typhoon/Voltzite by exploiting (weaponizing) vulnerabilities in F5, Ivanti, and SAP products to enable downstream intrusions.
Threat group described as obtaining and weaponizing edge device vulnerabilities before patches are applied, then handing off access for deeper OT intrusions.
Dragos-tracked activity cluster newly observed targeting ICS/OT environments (no further details provided in the content).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.