Threat intelligence
- Suspected origin
- China
- Targeted countries
- China
- TLP
- WHITE
(Microsoft) Microsoft has uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States. The attack is carried out by Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.
Volt Typhoon has been active since mid-2021 and has targeted critical infrastructure organizations in Guam and elsewhere in the United States. In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. Observed behavior suggests that the threat actor intends to perform espionage and maintain access without being detected for as long as possible. Microsoft is choosing to highlight this Volt Typhoon activity at this time because of our significant concern around the potential for further impact to our customers. Although our visibility into these threats has given us the ability to deploy detections to our customers, the lack of visibility into other parts of the actor’s activity compelled us to drive broader community awareness and further investigations and protections across the security ecosystem.
Also known as
Bronze SilhouetteDazedToadDev-0391Insidious TaurusRedflyStorm-0391UAT-5918UAT-7237UNC3236Vanguard PandaVolt TyphoonVOLTZITE
Vulnerabilities exploited
Tooling and malware
VersaMemcertutilcmdFRPImpacketipconfigMimikatzNetnetshnetstatNltestPingPsExecRegSysteminfoTasklistWevtutil
MITRE ATT&CK techniques
T1005 Data from Local SystemT1074 Data StagedT1113 Screen CaptureT1090 ProxyT1105 Ingress Tool TransferT1552 Unsecured CredentialsT1555 Credentials from Password StoresT1112 Modify RegistryT1007 System Service DiscoveryT1010 Application Window DiscoveryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1069 Permission Groups DiscoveryT1083 File and Directory DiscoveryT1120 Peripheral Device DiscoveryT1124 System Time DiscoveryT1217 Browser Information DiscoveryT1518 Software DiscoveryT1614 System Location DiscoveryT1654 Log EnumerationT1680 Local Storage DiscoveryT1047 Windows Management InstrumentationT1190 Exploit Public-Facing ApplicationT1570 Lateral Tool TransferT1133 External Remote ServicesT1068 Exploitation for Privilege EscalationT1589 Gather Victim Identity InformationT1590 Gather Victim Network InformationT1591 Gather Victim Org InformationT1592 Gather Victim Host InformationT1593 Search Open Websites/DomainsT1594 Search Victim-Owned WebsitesT1006 Direct Volume AccessT1078 Valid AccountsT1140 Deobfuscate/Decode Files or Information
Coverage 4
threat-intel
A DomainTools report details ongoing nation-state targeting of water systems by Iran, Russia, and China, primarily through exploiting weak passwords, exposed PLCs, and HMI vulnerabilities. The motivations behind these at…

threat-intel
Canadian spy agency, CSIS, utilized a novel court-ordered warrant to neutralize two foreign-run botnets operating within Canada. The operation targeted infected servers, SOHO routers, and IoT devices like Ring doorbells…

threat-intel
A China-linked botnet, dubbed JDY, has significantly expanded its operations, now comprising over 1,500 compromised SOHO and IoT devices. Initially a component of the KV-botnet, the JDY botnet is being used for large-sca…

threat-intel
A Chinese-linked botnet, JDY, has significantly expanded its targeting of U.S. military networks and associated infrastructure. The botnet, previously associated with Volt Typhoon, utilizes reconnaissance techniques like…