VOLT TYPHOON
VOLTZITE
BRONZE SILHOUETTE
VANGUARD PANDA
Threat IntelligenceAPTMarch 10, 202620 min read

Volt Typhoon: Threat Intelligence Profile

PRC state-sponsored (PLA) advanced persistent threat group pre-positioning within US critical infrastructure networks using living-off-the-land techniques, assessed as preparation for potential disruptive operations during geopolitical crisis.

Scroll

Volt Typhoon / VOLTZITE / Bronze Silhouette (also known as VOLTZITE, Bronze Silhouette, Vanguard Panda, DEV-0391, Insidious Taurus, UTA0178) is a state-sponsored advanced persistent threat group attributed to People's Republic of China (PLA), active since 2021. The group primarily targets critical infrastructure, energy, water, transportation, communications, maritime sectors. It is tracked by MITRE ATT&CK as G1017.

Overview & Attribution

Volt Typhoon represents an unprecedented strategic threat to US national security. Unlike traditional espionage-focused APT groups, Volt Typhoon has been assessed by CISA, NSA, FBI, and Five Eyes intelligence partners as pre-positioning within critical infrastructure networks for potential disruptive or destructive operations during a future geopolitical crisis -- particularly a conflict over Taiwan. The group's exclusive use of living-off-the-land techniques makes detection exceptionally difficult.

Threat Assessment

Volt Typhoon has been active since 2021, attributed to People's Republic of China (PLA). The group exclusively uses living-off-the-land binaries and legitimate administrator tools, making detection exceptionally challenging. Their presence in US water, energy, transportation, and communications infrastructure has been confirmed by multiple government agencies.

Arsenal & Tools

Volt Typhoon employs a distinctive approach of using only native operating system tools and legitimate software:

Targeting & Operations

The group focuses on critical infrastructure, energy, water, transportation, communications, maritime sectors across the United States and its territories. Their operations are assessed as pre-positioning for disruption rather than traditional intelligence collection, representing a fundamental shift in PRC cyber strategy.

Operational Pattern

Volt Typhoon is distinguished by its exclusive reliance on living-off-the-land techniques. The group uses only native OS tools (ntdsutil, netsh, PowerShell, wmic) and legitimate administrator credentials, deploying no custom malware. This approach allows them to maintain persistent access for years while blending with normal system administration activity.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1190 Exploit Public-Facing ApplicationExploitation of Fortinet FortiGuard, Zoho ManageEngine, and other internet-facing appliances
ExecutionT1059.001 PowerShellNative PowerShell for reconnaissance, lateral movement, and data staging
PersistenceT1078 Valid AccountsCredential theft and reuse of legitimate administrator accounts for persistent access
PersistenceT1136 Create AccountCreation of local accounts on compromised systems for backup access
Defense EvasionT1218 System Binary Proxy ExecutionExclusive use of LOLBins to blend with legitimate system administration activity
Lateral MovementT1021.002 SMB/Windows Admin SharesLateral movement via administrative shares using stolen credentials

Notable Campaigns

Volt Typhoon has been linked to multiple significant campaigns targeting US critical infrastructure. The group continuously evolves its techniques to evade detection while maintaining persistent access.

Known Indicators
  • Known to use compromised SOHO routers as C2 proxies (no static IOCs)
  • Behavioral detection is primary approach due to LOLBin-only operations

Detection & Defense

Defend Against Volt Typhoon

Mjolnir Security provides specialized capabilities to detect and respond to Volt Typhoon operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for Volt Typhoon TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of Volt Typhoon campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: March 10, 2026