81
Techniques
17
Toolsets
2
CVEs Referenced
1
KEV Entries
CISA Known Exploited
About Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

View MITRE record ↗

Techniques by Tactic (81)
Toolsets (17)
🐛
VersaMem S1154
Malware · Network Devices
🔧
FRP S1144
Tool · Linux, macOS, Windows
🔧
Impacket S0357
Tool · Linux, macOS, Windows
🔧
Mimikatz S0002
Tool · Windows
🔧
Net S0039
Tool · Windows
🔧
Nltest S0359
Tool · Windows
🔧
Ping S0097
Tool
🔧
PsExec S0029
Tool · Windows
🔧
Reg S0075
Tool · Windows
🔧
Tool
🔧
Tasklist S0057
Tool
🔧
Wevtutil S0645
Tool · Windows
🔧
certutil S0160
Tool · Windows
🔧
cmd S0106
Tool · Windows
🔧
ipconfig S0100
Tool
🔧
netsh S0108
Tool · Windows
🔧
netstat S0104
Tool
CVEs Referenced (2 · 1 CISA KEV)
CVE-2014-7169View full details on NVDKEV
CVE-2016-6662View full details on NVD
↑