Volt Typhoon
Alias-Namen: BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, DazedToad
6
5
21.04.2026
26.08.2026
Profil laut MITRE ATT&CK
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet..
Vollständiges MITRE-ProfilBeschreibung und Alias-Namen stammen aus MITRE ATT&CK®.
Nennungen im Zeitverlauf
Meldungen je Monat, letzte 12 Monate.
Beobachtete Techniken
ATT&CK-Techniken, die in denselben Meldungen benannt sind — nicht das vollständige MITRE-Repertoire.
T1587.001 Malware
Resource Development
T1588.001 Malware
Resource Development
T1592.002 Software
Reconnaissance
T1588.006 Vulnerabilities
Resource Development
T1583.005 Botnet
Resource Development
T1584.005 Botnet
Resource Development
T1090 Proxy
Command & Control
T1566 Phishing
Initial Access
T1583.003 Virtual Private Server
Resource Development
T1583.004 Server
Resource Development
T1584.003 Virtual Private Server
Resource Development
T1584.004 Server
Resource Development
Schwachstellen im selben Kontext
CVEs, die in denselben Meldungen auftauchen. Ko-Okkurrenz, kein Nachweis einer Ausnutzung.
Gemeinsam genannt
Betroffene Branchen
Meldungen
DOJ, FBI seize China-linked QScan and QTRouter platforms used to target US critical infrastructure
ARI urges Trump to designate AI as ‘critical infrastructure’ amid growing cyber risks across critical sectors
CYFIRMA reports telecom sector faces high cyber risk as China, Russia-linked APT campaigns intensify
Cyber Attack Trends 2026: What Security Teams Face
China-linked JDY botnet expands targeting of U.S. military networks
Defending Against China-Nexus Covert Networks of Compromised Devices
Quellen: Industrial Cyber (3), IOActive (1), BleepingComputer (1), CISA Alerts (1)
Alle Angaben auf dieser Seite stammen aus dem Alias-Abgleich der Meldungstexte gegen den MITRE-ATT&CK-Katalog. Beziehungen entstehen rein statistisch: Zwei Einträge gelten als verbunden, wenn sie in derselben Meldung benannt sind. Das ist keine eigenständige Attribution durch SecBoard, und eine Nennung ist kein Nachweis einer Täterschaft.