ChinaFormally attributedActiveMITRE G1017

Volt Typhoon

Coverage omission — Eastern

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
4.3
Moderate signal strength
Mentions5
Sources1
High conf.5
Last seenMay 2026
First observed
2023-07-27
Last active
Active
Origin
China — attributed by US, UK, Australian, Canadian, and New Zealand governments
Aliases
9
Techniques
81
Campaigns
7
China — attributed by US, UK, Australian, Canadian, and New Zealand governmentsconsensus confidence
TargetsCritical InfrastructureEnergyWaterTelecommunicationsTransportation
RegionsUsGuApac

Attribution signals

5 mentions · 1 source
#1confirmedhigh
InfrastructureTTP match
cisa
May 2026

"The U.S. authoring agencies have confirmed that Volt Typhoon has compromised the IT environments of multiple critical infrastructure organizations"

#2assess with high confidencehigh
TTP matchVictimologyGeopolitical
cisa
May 2026

"the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT assets to disrupt functions"

#3state-sponsored cyber actorhigh
Unspecified
cisa
May 2026

"a People's Republic of China (PRC) state-sponsored cyber actor, also known as Volt Typhoon"

#4have been usedhigh
Unspecified
ncsc-uk-all
May 2026

"They have been used by Chinese state-sponsored actors Volt Typhoon to pre-position offensive cyber capabilities on critical national infrastructure."

#5used byhigh
InfrastructureMalware
ncsc-uk-all
May 2026

"The KV Botnet used by Volt Typhoon was mainly made up of vulnerable Cisco and NetGear routers."

Campaign: KV Botnet

Hedge terms observed

assess with high confidenceconfirmedhave been usedstate-sponsored cyber actorused by