Volt Typhoon has attempted to access hashed credentials from the LSASS process memory space.78
group
Volt Typhoon G1017
- Created
- 27 July 2023
- Last modified
- 31 July 2026
- Aliases
- Volt Typhoon · BRONZE SILHOUETTE · Vanguard Panda · DEV-0391 · UNC3236 · Voltzite · Insidious Taurus · DazedToad
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].
Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1017
Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.9101112
Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.131415
Volt Typhoon has executed the Windows-native vssadmin command to create volume shadow copies.16
Volt Typhoon has used net start to list running services.17
Volt Typhoon has collected window title information from compromised systems.18
Standing G1017
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
97th percentile · 97% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
85th percentile · 85% of 176 ATT&CK groups have this many tactics spanned or fewer.
92nd percentile · 92% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 176 ATT&CK groups have more detection rules per technique.
Detection coverage G1017
2045 distinct rules cover the 81 techniques recorded for this group. The 2383 technique-to-rule mappings resolve to 2045 distinct rules, because one rule can cover several techniques. 1353 Sigma · 692 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org