Threat actor · all actors
Volt TyphoonG1017 state
🇨🇳 CN · PLA
aka Volt Typhoon, BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad, Storm-0391
Last updated: 2026-08-22
About this actor
[Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. [Volt Typhoon](https://attack.mitre.org/groups/G1017)'s targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. [Volt Typhoon](https://attack.mitre.org/groups/G1017) has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)(Citation: Microsoft Volt Typhoon May 2023)(Citation: Joint Cybersecurity Advisory Volt Typhoon June 2023)(Citation: Secureworks BRONZE SILHOUETTE May 2023). The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.(Citation: DOJ KVBotnet 2024). Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to [Volt Typhoon](https://attack.mitre.org/groups/G1017), also tracked as VOLTZITE, for follow-on operations. (Citation: Dragos 2025 Year in Review)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
MandiantUNC uncategorised cluster
Secureworkscolour-metal names
DragosICS mineral names
Palo Alto Unit 42constellation names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 98 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 2 CVE published
- 2025 — 2 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2025-0283 | 7.3 | 7.0 | 0.4955 | 2025-01-08 | see CVE |
CVE-2025-64119 | 7.0 | 9.3 | 0.0042 | 2026-01-02 | see CVE |
CVE-2026-22813 | 4.8 | 6.1 | 0.0093 | 2026-01-12 | see CVE |
CVE-2025-7746 | 3.5 | 5.3 | 0.0043 | 2025-09-09 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1003.003NTDS ↗T1005Data from Local System ↗T1006Direct Volume Access ↗T1007System Service Discovery ↗T1010Application Window Discovery ↗T1012Query Registry ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1018Remote System Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1027Obfuscated Files or Information ↗T1027.002Software Packing ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.005Match Legitimate Resource Name or Location ↗T1036.008Masquerade File Type ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1056Input Capture ↗T1056.001Keylogging ↗T1057Process Discovery ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.004Unix Shell ↗T1068Exploitation for Privilege Escalation ↗T1069Permission Groups Discovery ↗T1069.001Local Groups ↗T1069.002Domain Groups ↗T1070Indicator Removal ↗T1070.004File Deletion ↗T1070.007Clear Network Connection History and Configurations ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.001Local Account ↗T1087.002Domain Account ↗T1090Proxy ↗T1090.001Internal Proxy ↗T1090.003Multi-hop Proxy ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1113Screen Capture ↗T1120Peripheral Device Discovery ↗T1124System Time Discovery ↗T1133External Remote Services ↗T1140Deobfuscate/Decode Files or Information ↗T1190Exploit Public-Facing Application ↗T1217Browser Information Discovery ↗T1218System Binary Proxy Execution ↗T1497Virtualization/Sandbox Evasion ↗T1497.001System Checks ↗T1505Server Software Component ↗T1505.003Web Shell ↗T1518Software Discovery ↗T1552Unsecured Credentials ↗T1552.004Private Keys ↗T1555Credentials from Password Stores ↗T1555.003Credentials from Web Browsers ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1570Lateral Tool Transfer ↗T1573Encrypted Channel ↗T1573.001Symmetric Cryptography ↗T1584Compromise Infrastructure ↗T1584.003Virtual Private Server ↗T1584.004Server ↗T1584.005Botnet ↗T1584.008Network Devices ↗T1587Develop Capabilities ↗T1587.004Exploits ↗T1588Obtain Capabilities ↗T1588.002Tool ↗T1588.006Vulnerabilities ↗T1589Gather Victim Identity Information ↗T1589.002Email Addresses ↗T1590Gather Victim Network Information ↗T1590.004Network Topology ↗T1590.006Network Security Appliances ↗T1591Gather Victim Org Information ↗T1591.004Identify Roles ↗T1592Gather Victim Host Information ↗T1593Search Open Websites/Domains ↗T1594Search Victim-Owned Websites ↗T1596Search Open Technical Databases ↗T1596.005Scan Databases ↗T1614System Location Discovery ↗T1654Log Enumeration ↗T1680Local Storage Discovery ↗T1685Disable or Modify Tools ↗T1685.005Clear Windows Event Logs ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 43 / 98 | 44% |
CM-6 | 38 / 98 | 39% |
CM-2 | 33 / 98 | 34% |
AC-3 | 31 / 98 | 32% |
SI-3 | 30 / 98 | 31% |
AC-6 | 29 / 98 | 30% |
CM-7 | 29 / 98 | 30% |
AC-2 | 28 / 98 | 29% |
CA-7 | 25 / 98 | 26% |
SI-7 | 23 / 98 | 23% |
AC-5 | 19 / 98 | 19% |
SC-7 | 19 / 98 | 19% |
AC-4 | 17 / 98 | 17% |
IA-2 | 17 / 98 | 17% |
RA-5 | 17 / 98 | 17% |
Co-occurring actors
- Kimsuky 1 shared CVEs
- Mustang Panda 1 shared CVEs
- MuddyWater 1 shared CVEs
- Gamaredon Group 1 shared CVEs
Similar actors
Similar TTPs
- Operation Wocao 0.44
- OilRig 0.33
- Chimera 0.32
- FIN13 0.32
- Sandworm Team 0.30
Overlapping CVEs
- Gamaredon Group 0.25
- MuddyWater 0.20
- Mustang Panda 0.20
- Kimsuky 0.17
Active in same years
- SharePoint ToolShell Exploitation 2.00
- Kimsuky 2.00
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00