G1017 · 80 ATT&CK techniques · 1 correlated reports

Volt Typhoon

Aliases: BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021 primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.

Open interactive actor investigation

ATT&CK techniques

T1046
Network Service Discovery
T1083
File and Directory Discovery
T1591.004
Identify Roles
T1057
Process Discovery
T1021.001
Remote Desktop Protocol
T1584.004
Server
T1090
Proxy
T1518
Software Discovery
T1078
Valid Accounts
T1584.008
Network Devices
T1056.001
Keylogging
T1036.005
Match Legitimate Name or Location
T1036.008
Masquerade File Type
T1059.003
Windows Command Shell
T1190
Exploit Public-Facing Application
T1555
Credentials from Password Stores
T1074
Data Staged
T1070.001
Clear Windows Event Logs
T1590
Gather Victim Network Information
T1560.001
Archive via Utility
T1124
System Time Discovery
T1069.002
Domain Groups
T1016
System Network Configuration Discovery
T1018
Remote System Discovery
T1047
Windows Management Instrumentation
T1133
External Remote Services
T1570
Lateral Tool Transfer
T1593
Search Open Websites/Domains
T1082
System Information Discovery
T1589.002
Email Addresses
T1497.001
System Checks
T1003.003
NTDS
T1027.002
Software Packing
T1573.001
Symmetric Cryptography
T1003.001
LSASS Memory
T1584.005
Botnet
T1592
Gather Victim Host Information
T1049
System Network Connections Discovery
T1087.001
Local Account
T1217
Browser Information Discovery
T1059.001
PowerShell
T1654
Log Enumeration
T1068
Exploitation for Privilege Escalation
T1113
Screen Capture
T1090.001
Internal Proxy
T1587.004
Exploits
T1090.003
Multi-hop Proxy
T1594
Search Victim-Owned Websites
T1033
System Owner/User Discovery
T1112
Modify Registry
T1505.003
Web Shell
T1218
System Binary Proxy Execution
T1059.004
Unix Shell
T1007
System Service Discovery
T1069
Permission Groups Discovery
T1584.003
Virtual Private Server
T1555.003
Credentials from Web Browsers
T1591
Gather Victim Org Information
T1590.004
Network Topology
T1010
Application Window Discovery
T1069.001
Local Groups
T1120
Peripheral Device Discovery
T1070.004
File Deletion
T1588.006
Vulnerabilities
T1105
Ingress Tool Transfer
T1552
Unsecured Credentials
T1078.002
Domain Accounts
T1005
Data from Local System
T1006
Direct Volume Access
T1012
Query Registry
T1589
Gather Victim Identity Information
T1588.002
Tool
T1596.005
Scan Databases
T1087.002
Domain Account
T1614
System Location Discovery
T1070.007
Clear Network Connection History and Configurations
T1016.001
Internet Connection Discovery
T1552.004
Private Keys
T1074.001
Local Data Staging
T1590.006
Network Security Appliances

Correlated CTI and IR reports

Continue the investigation