← Back to all threat actors

Volt Typhoon

Also known as BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad
Tracked as G1017

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

How we source and review actor profiles
Motivation
nation-state
Attributed nexus
CN
Sectors
critical-infrastructure, energy, transportation, telecom, government
Status
Active

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
IdentityTracking identifier: G1017

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: BRONZE SILHOUETTE

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Vanguard Panda

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: DEV-0391

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: UNC3236

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Voltzite

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Insidious Taurus

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: DazedToad

Reviewed identity mapping approved on this date.

Cataloged
CVECVE-2023-27997 linked to this actor
Cataloged
CVECVE-2023-3519 linked to this actor
Cataloged
CVECVE-2024-1709 linked to this actor
Cataloged
CVECVE-2024-1708 linked to this actor
Last observed
CampaignVersa Director Zero Day Exploitation

Versa Director Zero Day Exploitation was conducted by Volt Typhoon from early June through August 2024 as zero-day exploitation of Versa Director servers controlling software-defined wide area n…

First observed
CVECVE-2024-39717 linked to this actor
Last observed
CampaignKV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity wa…

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Volt TyphoonCanonical Name
BRONZE SILHOUETTEAlias
DEV-0391Alias
DazedToadAlias
Insidious TaurusAlias
UNC3236Alias
Vanguard PandaAlias
VoltziteAlias
G1017Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...