Threat Actor ProfileVolt Typhoon

State-sponsored cyber operations increasingly form part of long-term strategic competition, particularly through espionage activities targeting sectors essential to national security and economic stability. These operations are typically conducted by advanced persistent threat (APT) groups that prioritize intelligence collection and sustained access over immediate or visible impact. One such actor is Volt Typhoon, a China-linked threat group that has been active since at least 2021 – though large-scale attribution did not occur until 2023 – and is primarily associated with espionage and intelligence collection through strategic pre-positioning within critical infrastructure environments. The group is commonly tracked under several aliases, most notably Vanguard Panda, BRONZE SILHOUETTE, and Insidious Taurus.

Volt Typhoon is distinguished by its operational focus on stealth and persistence rather than the deployment of custom malware or overtly disruptive techniques. Reported activity indicates that the group frequently relies on valid credentials and native system tools – a technique commonly referred to as “living off the land” (LOTL) – to access and operate within target environments, allowing it to blend into legitimate network activity. This approach complicates detection and attribution, particularly in large enterprise and infrastructure environments where similar administrative behavior is common. In some confirmed cases, Volt Typhoon maintained undetected access to victim networks for up to five years before discovery.

Activity attributed to Volt Typhoon has primarily been observed across a range of countries, with targeting concentrated on sectors connected to critical infrastructure and industrial operations. The group's focus on Guam (a U.S. Pacific territory hosting major American military installations) has been specifically highlighted by U.S. authorities as indicative of the group's broader strategic intent, given the island's significance to U.S. military operations in the Indo-Pacific.

In order to assess the threat posed by Volt Typhoon, this profile examines the group’s origins, motivations, campaigns, tools, and techniques, as well as broader trends, sectoral implications, and defensive considerations relevant to affected industries.

  • Aliases: BRONZE SILHOUETTE, VANGUARD PANDA, UNC3236, Insidious Taurus, Redfly, VOLTZITE, DEV-0391, Storm-0391
  • Strategic motives: Espionage, information theft, and long-term pre-positioning in critical infrastructure environments
  • Affiliation: People’s Republic of China (PRC)
  • Cyber capabilities: ★★★★☆
  • Target sectors: Communications, manufacturing, energy, transportation, construction, maritime, information technology, education, and government-related infrastructure
  • Observed countries: United States, United Kingdom, Australia, India, Italy, Germany, France, Belgium, Slovenia, Romania, Czech Republic, Canada, New Zealand, Taiwan

Request a free membership to access our full research insights

Already a member? Login here

Origins, Motivations & Targets

Origins

Volt Typhoon is an advanced persistent threat group with publicly documented activity dating to at least 2021, with large-scale public attribution first occurring in early 2023.[1] Early reporting describes the group's initial discovery as the result of investigations into covert intrusions characterised by long dwell times and minimal use of distinctive malware, rather than the identification of unique malware families.[2] The group was first publicly named and attributed by Microsoft on May 24, 2023, followed immediately by a joint advisory from the cybersecurity agencies of the Five Eyes intelligence alliance (comprising the United States, United Kingdom, Australia, Canada, and New Zealand) marking one of the most significant coordinated public attribution events in recent memory.[3] These early intrusions were marked by an emphasis on maintaining access while avoiding indicators likely to trigger traditional security controls.[4]

From the outset, Volt Typhoon demonstrated extensive use of living-off-the-land (LOTL) techniques and legitimate administrative tooling following initial compromise, indicating a deliberate focus on operational security and persistence.[5] Rather than deploying custom malware (which carries a higher risk of detection and attribution) the group made use of tools native to the Windows operating system, including wmic, ntdsutil, netsh, and PowerShell, to conduct reconnaissance, harvest credentials, and move laterally through victim environments.[6] The group also made early use of compromised small office and home office (SOHO) network devices as intermediate relay infrastructure, later identified by researchers as the KV-Botnet, suggesting early investment in methods designed to obscure the origin of malicious activity and complicate detection and attribution.[7] This combination of stealth, access maintenance, and internal reconnaissance points to an operational model designed for prolonged presence rather than short, high-impact campaigns.

Multiple assessments from government agencies and independent cybersecurity researchers attribute Volt Typhoon to state-sponsored activity linked to the People's Republic of China (PRC), assessed with high confidence.[8] The PRC has publicly denied these attributions.[9] Early operational focus included critical infrastructure environments in the United States and U.S. territories such as Guam (home to Andersen Air Force Base and Naval Base Guam, two installations critical to U.S. military posture in the Indo-Pacific) aligning with strategic considerations related to communications, logistics, and military readiness.[10] Independent industrial threat reporting by Dragos, who are tracking the group under the designation VOLTZITE, has identified activity clusters associated with Volt Typhoon operations emerging from 2021 onward, with a particular concentration on electric utilities, telecommunications providers, and emergency services in the United States and allied nations, reinforcing the assessment that the group operates as part of a broader, sustained effort targeting strategically relevant systems.[11]

 

Motivations & Targets

Volt Typhoon's observed activity is primarily motivated by strategic espionage and long-term intelligence collection, clearly distinguishing the group from cybercriminal threat actors operating in overlapping sectors. The group's behaviour reflects an emphasis on covert, sustained access to networks supporting critical services, consistent with objectives centred on strategic situational awareness and operational pre-positioning.[12; 13] This is reinforced by U.S. official assessments characterising the group's activity as preparation for potential future disruptive action during periods of geopolitical crisis, rather than an end in itself.[14] Notably, Dragos has assessed that the group's interest in operational technology (OT) environments and geographic information system (GIS) data (mapping the physical layout of infrastructure) points toward pre-positioning for potential sabotage rather than passive intelligence collection alone.[15]

Targeting has been concentrated on organisations within critical infrastructure and closely related industries. Publicly reported victim sectors include communications, energy, transportation, maritime, manufacturing, construction, information technology, emergency services, and education.[16; 17; 18] Private-sector operators of essential services represent the largest portion of confirmed targets, alongside a smaller number of government-affiliated entities.[19; 20] Financial motivations have not been observed in any publicly attributed Volt Typhoon activity. This absence is itself analytically significant: it confirms that access to victim environments serves strategic rather than economic objectives, and that the group's targeting decisions are driven by geopolitical relevance rather than the monetisation potential of compromised data.

Geographically, confirmed activity has primarily focused on the United States and U.S. territories, most notably Guam, assessed as a strategic target due to its role in Indo-Pacific military logistics and communications.[21; 22] The Five Eyes nations (the United States, United Kingdom, Australia, Canada, and New Zealand) represent the most authoritatively confirmed geographic scope, as reflected in the joint May 2023 advisory.[23] Activity in additional countries including India and several European nations has been referenced in vendor reporting, though attribution strength varies and these assessments carry lower levels of official confirmation than the Five Eyes cases.[24; 25]

Taken together, these motivations and targeting patterns reflect a calculated, long-term approach aimed at embedding persistent access within strategically significant environments.

SWOT analysis

Strengths, weaknesses, opportunities & threats

Strengths

  • Access to significant state resources and long-term strategic tasking
  • Stealthy tradecraft based on credential abuse and living-off-the-land techniques
  • Established covert relay infrastructure
  • Broad sectoral access across critical infrastructure

Weaknesses

  • Strong dependence on valid credentials and existing access paths
  • Limited use of bespoke tooling reduces operational flexibility
  • Dependence on third-party infrastructure introduces operational risk

Opportunities

  • Ability to pre-position within globally interconnected infrastructure
  • Expanding digital dependency across critical infrastructure environments
  • Persistent underdetection due to LOTL tradecraft

Threats

  • Increased international focus on Chinese state-sponsored cyber activity
  • Growing effectiveness of identity-centric and behavior-based detection
  • Active law enforcement and government disruption operations

Campaigns Overview

The campaigns discussed below represent a selection of Volt Typhoon's most publicly documented and strategically significant operations. They were selected on the basis of their impact, the volume of corroborating public reporting, and their ability to illustrate the group's evolving tactics and long-term strategic objectives. They do not constitute an exhaustive account of all activity, primarily due to the inherent challenges of attribution in operations characterised by the use of legitimate credentials and native system tooling.

January 1, 2022
16:00 PM

U.S. Critical Infrastructure Intrusion Campaign

2021–2023

From at least 2021, Volt Typhoon conducted a sustained intrusion campaign against U.S. critical infrastructure, targeting organisations across the communications, utilities, manufacturing, transportation, maritime, construction, and information technology sectors.[26] This campaign was notable for the depth and duration of access achieved: in some cases, the group maintained undetected presence within victim environments for up to five years, a finding that reflects both the group's operational discipline and the detection gaps present in large enterprise and infrastructure environments.[27; 28]

Confirmed intrusions during this period included organisations operating in Guam, the U.S. Pacific territory home to strategically significant American military installations including Andersen Air Force Base and Naval Base Guam.[29] The targeting of Guam-based communications and logistics infrastructure was assessed as particularly significant given the island's role in supporting U.S. military operations in the Indo-Pacific region. Palo Alto Networks Unit 42, tracking the group as Insidious Taurus, corroborated this assessment, noting that the geographic focus on Guam and surrounding Pacific infrastructure aligned with broader PRC strategic priorities in the region.[30]

Beyond Guam, Dragos (referring to Volt Typhoon as VOLTZITE) identified confirmed intrusions against U.S. electric utilities, emergency services, and telecommunications providers, with activity observed across multiple U.S. states. Dragos assessed VOLTZITE as one of the most significant threats to electric utility operational technology (OT) environments identified in 2023, noting that the group's activity extended beyond IT networks into OT-adjacent systems, where access could have direct consequences for physical infrastructure operations.[31]

The intrusions relied heavily on valid, stolen credentials and built-in administrative tools, including wmic, ntdsutil, and netsh, rather than custom malware, allowing the attackers to blend into normal network activity and avoid triggering conventional security controls.[32; 33]

January 1, 2022
16:00 PM

Telecommunications and Communications Provider Intrusions

2021–2024

Volt Typhoon has been consistently linked to targeted intrusions against telecommunications and communications service providers in the United States and allied nations[34], reflecting a sustained strategic interest in connectivity infrastructure. It is important to note that telecommunications sector intrusions have also been attributed to the separately tracked Chinese APT group Salt Typhoon. These are distinct operations conducted by a different threat actor, and claims specific to Salt Typhoon have been excluded from this profile.[35]

Within activity directly attributed to Volt Typhoon, communications providers were targeted primarily as enablers of broader operational access. Compromising a communications provider offered insight into network dependencies and the operational resilience of downstream organisations, including government and military entities.[36] Dragos confirmed that satellite communications providers were among the organisations targeted by VOLTZITE, consistent with the group's interest in understanding and potentially disrupting strategic communications capabilities.[37]

Intrusions into communications providers were characterised by low operational tempo. The group moved slowly and infrequently within victim environments to avoid triggering anomaly-based detection systems. The focus of activity was internal discovery: mapping network topology, identifying dependencies between systems, and locating high-value assets such as OT interfaces and network management systems.[38] No disruptive activity has been publicly attributed to Volt Typhoon in this sector to date, reinforcing the assessment that current operations remain in a pre-positioning phase.[39; 40]

January 1, 2022
16:00 PM

KV-Botnet: SOHO Router Infrastructure Compromise

2022–2024

Between 2022 and 2024, Volt Typhoon systematically compromised a large network of end-of-life small office and home office (SOHO) routers and network edge devices, repurposing them as a covert operational relay network. This infrastructure, later named the "KV-Botnet" by researchers at Lumen Black Lotus Labs, was used to proxy malicious traffic through legitimate-looking IP addresses, obscuring the group's origin and significantly complicating attribution efforts.[41]

The botnet primarily consisted of compromised Cisco RV320/RV325, Netgear ProSAFE, and ASUS routers — devices that had reached end-of-life status and no longer received security patches, making them particularly susceptible to exploitation without generating alerts in the environments through which they relayed traffic.[42]

At its peak, the KV-Botnet comprised hundreds of compromised devices, effectively creating a domestic relay network that caused Volt Typhoon's traffic to appear to originate from within the United States.[43] This approach served a dual purpose: it reduced the likelihood that outbound connections from victim environments would be flagged as anomalous, and it made attribution to a foreign state actor significantly more difficult for both victim organisations and government investigators. The use of compromised third-party infrastructure as operational relay nodes is a documented and consistent element of Volt Typhoon's tradecraft, reflecting the group's broader emphasis on minimising forensic footprint and complicating attribution.

In January 2024, the U.S. Department of Justice and FBI announced a court-authorised operation to disrupt the botnet. FBI agents remotely accessed hundreds of the compromised routers and deleted the malicious payloads, effectively severing the devices from Volt Typhoon's command-and-control infrastructure.[44] FBI Director Christopher Wray described the operation as targeting "a key [Chinese government] hacking operation" and noted that the routers' owners (ordinary American households and small businesses) had no knowledge their devices were being used as relay points for state-sponsored espionage. [45] Despite the disruption, analysts noted that the underlying capability was not permanently dismantled, as Volt Typhoon retained the ability to rebuild similar infrastructure using other vulnerable devices.[46; 47]

January 1, 2022
16:00 PM

Electric Utility and Operational Technology Targeting

2023–2024

Dragos reporting published in 2024 elevated Volt Typhoon — tracked as VOLTZITE — to one of the highest-priority threats facing the electric utility sector, distinguishing this cluster of activity from the group's broader critical infrastructure campaign by virtue of its demonstrated and specific interest in operational technology (OT) environments.[48]

The significance of this campaign lies in the depth of access sought. Unlike IT-focused intrusions, where the primary risk is data theft or credential harvesting, OT-adjacent access introduces the possibility of physical consequences, such as disruption to power generation or distribution systems. Dragos confirmed that VOLTZITE activity extended into OT-adjacent systems within victim environments, including network management systems and historian servers that bridge IT and OT networks.[49] Access to such systems does not require specialised OT malware; the same credential-based, living-off-the-land techniques observed in Volt Typhoon's IT intrusions are sufficient to navigate into OT-adjacent environments where network segmentation is incomplete or inconsistently enforced.

A particularly significant finding concerns the collection of Geographic Information System (GIS) data within compromised utility environments. In an energy infrastructure context, GIS data encompasses detailed spatial records of physical asset locations: the precise placement of substations, transmission lines, generation facilities, and switching equipment. The collection of this data is not consistent with passive intelligence gathering, but rather reflects a targeting methodology oriented toward understanding the physical architecture of infrastructure in sufficient detail to identify chokepoints whose disruption would have the greatest cascading effect on grid stability.[50] This assessment is consistent with the broader characterisation of Volt Typhoon's objective by U.S. officials: the establishment of capability to disrupt or destroy critical infrastructure at a moment of geopolitical crisis, rather than the collection of intelligence as an end in itself.[51] Within OT-adjacent environments, the group maintained its characteristic low operational tempo, conducting systematic enumeration of network topology and asset inventories while avoiding active interaction with control systems.[52; 53] This behaviour is consistent with a preference for maintaining access over achieving immediate operational effects. No disruptive activity targeting OT systems has been publicly attributed to Volt Typhoon to date.

January 1, 2022
16:00 PM

Re-entry and Persistence Operations Following Public Exposure

2023–2024

Following the public disclosure of Volt Typhoon's activity in May 2023, cybersecurity agencies anticipated that the group would attempt to re-establish access to environments from which it had been evicted. Subsequent reporting confirmed this concern.[54]

This re-entry pattern reflects a structural characteristic of Volt Typhoon's operational model. Remediation efforts in APT intrusions typically focus on closing known access vectors and removing identified malware and the attacker from confirmed compromise locations. They frequently fail to account for the full scope of credentials harvested during the intrusion, particularly credentials collected from systems outside the primary investigation scope, or belonging to accounts not directly linked to identified indicators of compromise. Volt Typhoon's systematic credential harvesting across extended dwell times produces an authentication capability that survives the eviction of tooling and the disruption of relay infrastructure. When credential rotation is incomplete, previously harvested credentials remain valid entry points requiring no new exploitation.[55; 56] This dynamic also illustrates the limits of infrastructure-focused disruption: the January 2024 KV-Botnet takedown degraded Volt Typhoon's relay capability but did not affect the credential stockpile or environmental knowledge the group had accumulated over years of access.[57; 58]

Targeting during this phase largely overlapped with earlier campaigns, particularly organisations in the utilities and transportation sectors, indicating that the group prioritised the recovery of specific, strategically valuable footholds over expansion into new environments.[59] During congressional testimony in January 2024, FBI Director Christopher Wray characterised the campaigns of Chinese hackers as preparation for potential future conflict, warning that they are pre-positioning themselves to "wreak havoc [onto critical infrastructure] and cause real-world harm".[60]

More detailed information about this actor?

Already a member? Login here

Volt Typhoon in the Netherlands

At the time of writing, there are no publicly confirmed or formally attributed intrusions by Volt Typhoon against Dutch organisations.[120] The absence of public attribution should not be interpreted as evidence that Dutch entities fall outside the group's operational scope. Public reporting links Volt Typhoon to long-term espionage operations targeting critical infrastructure and strategically significant industries in the United States and allied countries, including the United Kingdom and Australia.[121] These operations emphasise access maintenance and internal reconnaissance, suggesting objectives related to strategic positioning rather than immediate operational impact. This targeting logic is not geographically bound but instead prioritises organisations that play a role in interconnected international systems such as logistics, communications, energy distribution, and industrial supply chains.

The Netherlands occupies a central position within these systems due to its role as a hub for European logistics, maritime transport, digital connectivity, and industrial production. The Port of Rotterdam (the largest port in Europe) and Amsterdam Internet Exchange (AMS-IX) (one of the world's largest internet exchange points) represent exactly the kind of strategically significant infrastructure that Volt Typhoon has demonstrably targeted elsewhere. National threat assessments have explicitly warned of sustained interest by state-linked actors, including those affiliated with China, in Dutch economic, technological, and infrastructure assets, particularly where access could have broader international consequences.[122; 123] The AIVD's 2025 threat assessment specifically identified Chinese state-sponsored cyber actors as among the most significant and persistent threats facing the Netherlands, noting a pattern of targeting that aligns closely with Volt Typhoon's observed operational focus. [124] While these assessments do not attribute specific incidents to Volt Typhoon by name, they describe a threat landscape that closely aligns with the group's observed targeting patterns in other countries.

Attribution challenges further complicate detection in this context. Volt Typhoon's reliance on valid accounts and trusted network paths means that intrusions may be detected as anomalous behaviour without being conclusively linked to a specific threat actor. In practice, organisations may identify credential misuse or suspicious internal activity without being able to determine whether it is associated with Volt Typhoon or another APT.

From a defensive perspective, this uncertainty should be viewed as a call to action. Volt Typhoon's operations demonstrate that malicious activity can often be detected at the behavioural level even when attribution remains unclear. Given the broader strategic context, the Netherlands' position as a critical node in European and global infrastructure, and the documented involvement of Chinese state-sponsored actors in operations targeting comparable environments, Volt Typhoon remains a relevant and credible threat to the Dutch threat landscape despite the lack of publicly confirmed cases.

Trends & Connections

Volt Typhoon's activity reflects a broader evolution in state-sponsored cyber operations, in which long-term access and strategic positioning take precedence over short-term disruption or demonstrative attacks. Rather than pursuing immediate operational effects, the group's campaigns emphasise persistence, internal reconnaissance, and the maintenance of covert access to environments of strategic relevance. The group demonstrates sustained interest in civilian and commercial infrastructure with broader systemic importance. This targeting approach mirrors warnings from Western intelligence services regarding cyber-enabled pre-positioning by state-backed actors intended to provide strategic leverage during periods of heightened geopolitical tension.[125; 126] This approach aligns with a growing trend among advanced state-backed actors to treat cyber operations as a preparatory capability integrated into wider geopolitical and national security planning.[127]

A defining characteristic of this trend is the deliberate minimisation of unique tooling. Volt Typhoon's reliance on valid accounts, native system utilities, and living-off-the-land techniques mirrors tradecraft increasingly observed across multiple Chinese state-linked cyber operations. By avoiding custom malware and overt command-and-control infrastructure, the group reduces attribution confidence and extends dwell time in complex enterprise environments. This approach is not unique to Volt Typhoon but reflects a broader doctrinal shift across PRC-affiliated threat actors toward operationally disciplined, low-noise intrusion tradecraft.[128]

Within this context, Volt Typhoon is best understood as part of a broader ecosystem of Chinese state-sponsored cyber capability. While the group exhibits its own operational patterns, significant overlap exists with other PRC-aligned intrusion clusters at the level of access methods, infrastructure abuse, and targeting logic.[129] Analysts have noted similarities between Volt Typhoon and other China-linked threat groups that emphasise credential abuse and stealthy persistence, suggesting coordination at a doctrinal or organisational level rather than coincidental tactical overlap.[130]

This ecosystem-based view is further illustrated by reporting on the exploitation of multiple zero-day vulnerabilities in Ivanti Connect Secure appliances in late 2023 and early 2024. During this activity, several Chinese espionage clusters were observed exploiting the same vulnerabilities — specifically CVE-2023-46805 and CVE-2024-21887 — for initial access while displaying distinct post-compromise behaviour, suggesting parallel operations by related but separately managed threat clusters. One such cluster, UNC5135, has been assessed with moderate confidence to be linked to UNC3236, which is in turn suspected to align with publicly reported Volt Typhoon activity.[131] This assessment should be treated as tentative rather than confirmed, given the moderate confidence level of the underlying attribution.

Conclusions & Future Implications

Volt Typhoon exemplifies a form of state-sponsored cyber activity that prioritises persistence and strategic positioning over immediate operational impact. As demonstrated throughout this profile, the group relies on legitimate credentials and native system functionality to maintain covert access to environments of long-term strategic relevance, allowing malicious activity to blend into routine administrative behaviour and complicating both detection and attribution. The scale of this challenge is reflected in official assessments: CISA has acknowledged that the number of known Volt Typhoon victims is likely an underestimate, and confirmed intrusions have in some cases involved undetected access spanning up to five years.[132]

Volt Typhoon appears aligned with broader strategic objectives that favour access maintenance and internal reconnaissance over short-term gains. The absence of overt disruption should be interpreted as a deliberate operational choice in support of long-term positioning. In this context, the most significant risk is the quiet accumulation of access that may remain undiscovered for extended periods, with consequences that may only materialise under conditions of heightened geopolitical tension.

Looking ahead, geopolitical tensions surrounding the Indo-Pacific region and the continued digital integration of critical infrastructure suggest that operations of this nature are likely to persist and potentially intensify. Public warnings by Western governments and intelligence agencies, including the Five Eyes joint advisories and national assessments from the AIVD and NCTV, highlight growing concern over cyber-enabled pre-positioning by state-backed actors within internationally interconnected infrastructure environments.[133; 134; 135] As a result, organisations should expect continued emphasis on stealthy, credential-based intrusion techniques that exploit the gap between technical controls and operational reality.

Defending against threats such as Volt Typhoon therefore requires a shift away from static security assumptions toward continuous validation and behavioural detection. The challenge is not solely technical, but organisational: sustaining long-term awareness of subtle misuse of legitimate access requires ongoing investment in adversary-specific insight and the continuous adaptation of detection capabilities to evolving threat behaviour. As Volt Typhoon's operations illustrate, the effectiveness of modern cyber espionage increasingly depends on the defender's ability to recognise when "normal" behaviour is no longer benign.

Sources

[1] CISA et al., AA24-038A, February 2024

[2] Microsoft Threat Intelligence, May 24, 2023

[3] CISA et al., AA23-144A, May 2023

[4] Microsoft Threat Intelligence, May 24, 2023

[5] CISA et al., AA23-144A, May 2023

[6] Microsoft Threat Intelligence, May 24, 2023

[7] Lumen Black Lotus Labs, December 13, 2023

[8] CISA et al., AA23-144A, May 2023

[9] Reuters, January 29, 2024

[10] Microsoft Threat Intelligence, May 24, 2023

[11] Dragos, 2024

[12] Microsoft Threat Intelligence, May 24, 2023

[13] CISA et al., AA24-038A, February 2024

[14] Testimony of FBI Director Christopher Wray, U.S. House Select Committee on the Chinese Communist Party, January 31, 2024

[15] Dragos, 2024

[16] CISA et al., AA23-144A, May 2023

[17] Dragos, 2024

[18] MITRE ATT&CK, Volt Typhoon G1017

[19] CISA et al., AA23-144A, May 2023

[20] Palo Alto Networks Unit 42, 2023

[21] Microsoft Threat Intelligence, May 24, 2023

[22] CISA et al., AA23-144A, May 2023 

[23] CISA et al., AA23-144A, May 2023

[24] MITRE ATT&CK, Volt Typhoon G1017

[25] Dragos, 2024

[26] CISA et al., AA23-144A, May 2023

[27] CISA et al., AA24-038A, February 2024 

[28] Bloomberg, February 7, 2024

[29] Microsoft Threat Intelligence, May 24, 2023

[30] Palo Alto Networks Unit 42, 2023

[31] Dragos, 2024

[32] CISA et al., AA23-144A, May 2023

[33] Microsoft Threat Intelligence, May 24, 2023

[34] CISA et al., AA24-038A, February 2024

[35] MITRE ATT&CK, Volt Typhoon G1017

[36] CISA et al., AA23-144A, May 2023

[37] Dragos, 2024

[38] CISA et al., AA23-144A, May 2023

[39] CISA et al., AA24-038A, February 2024

[40] Palo Alto Networks Unit 42, 2023

[41] Lumen Black Lotus Labs, December 13, 2023

[42] Lumen Black Lotus Labs, December 13, 2023

[43] U.S. Department of Justice, January 31, 2024

[44] U.S. Department of Justice, January 31, 2024

[45] Testimony of FBI Director Christopher Wray, U.S. House Select Committee on the Chinese Communist Party, January 31, 2024

[46] Lumen Black Lotus Labs, December 13, 2023

[47] CISA et al., AA24-038A, February 2024

[48] Dragos, 2024

[49] Dragos, 2024

[50] Dragos, 2024

[51] Testimony of FBI Director Christopher Wray, U.S. House Select Committee on the Chinese Communist Party, January 31, 2024

[52] Dragos, 2024

[53] CISA et al., AA24-038A, February 2024

[54] CISA et al., AA24-038A, February 2024

[55] CISA et al., AA24-038A, February 2024

[56] Hunt & Hackett Threat Diagnostic System 

[57] Lumen Black Lotus Labs, December 13, 2023

[58] CISA et al., AA24-038A, February 2024

[59] CISA et al., AA24-038A, February 2024

[60] Testimony of FBI Director Christopher Wray, U.S. House Select Committee on the Chinese Communist Party, January 31, 2024

[61] Microsoft Threat Intelligence, May 24, 2023

[62] CISA et al., AA24-038A, February 2024

[63] CISA et al., AA23-144A, May 2023

[64] Microsoft Threat Intelligence, May 24, 2023

[65] CISA et al., AA23-144A, May 2023

[66] MITRE ATT&CK, Volt Typhoon G1017

[67] Palo Alto Networks Unit 42, 2023

[68] CISA et al., AA23-144A, May 2023

[69] Microsoft Threat Intelligence, May 24, 2023

[70] CISA et al., AA24-038A, February 2024

[71] MITRE ATT&CK, Volt Typhoon G1017

[72] CISA et al., AA23-144A, May 2023

[73] Hunt & Hackett Threat Diagnostic System

[74] MITRE ATT&CK, Volt Typhoon G1017

[75] CISA et al., AA23-144A, May 2023

[76] Microsoft Threat Intelligence, May 24, 2023

[77] Hunt & Hackett Threat Diagnostic System

[78] CISA et al., AA23-144A, May 2023

[79] CISA et al., AA24-038A, February 2024

[80] CISA et al., AA24-038A, February 2024

[81] CISA et al., AA23-144A, May 2023

[82] MITRE ATT&CK, Volt Typhoon G1017

[83] CISA et al., AA23-144A, May 2023

[84] Microsoft Threat Intelligence, May 24, 2023

[85] CISA et al., AA23-144A, May 2023

[86] MITRE ATT&CK, Volt Typhoon G1017 

[87] CISA et al., AA23-144A, May 2023

[88] MITRE ATT&CK, Volt Typhoon G1017

[89] MITRE ATT&CK, Volt Typhoon G1017

[90] CISA et al., AA23-144A, May 2023

[91] CISA et al., AA24-038A, February 2024

[92] MITRE ATT&CK, Volt Typhoon G1017

[93] CISA et al., AA23-144A, May 2023

[94] MITRE ATT&CK, Volt Typhoon G1017

[95] Microsoft Threat Intelligence, May 24, 2023 

[96] CISA et al., AA23-144A, May 2023

[97] CISA et al., AA23-144A, May 2023

[98] CISA et al., AA23-144A, May 2023

[99] Lumen Black Lotus Labs, December 13, 2023

[100] U.S. Department of Justice, January 31, 2024

[101] CISA et al., AA23-144A, May 2023

[102] MITRE ATT&CK, Volt Typhoon G1017

[103] CISA et al., AA24-038A, February 2024

[104] CISA et al., AA23-144A, May 2023

[105] Microsoft Threat Intelligence, May 24, 2023

[106] MITRE ATT&CK, Volt Typhoon G1017

[107] Palo Alto Networks Unit 42, 2023

[108] MITRE ATT&CK, Volt Typhoon G1017

[109] CISA et al., AA23-144A, May 2023

[110] MITRE ATT&CK, Volt Typhoon G1017

[111] Microsoft Threat Intelligence, May 24, 2023

[112] Hunt & Hackett Threat Diagnostic System

[113] CISA et al., AA24-038A, February 2024

[114] Hunt & Hackett Threat Diagnostic System 

[115] CISA et al., AA24-038A, February 2024

[116] Hunt & Hackett Threat Diagnostic System 

[117] CISA et al., AA23-144A, May 2023

[118] Hunt & Hackett Threat Diagnostic System

[119] CISA et al., AA24-038A, February 2024

[120] AIVD, Threat Assessment of State Actors 2025

[121] CISA et al., AA23-144A, May 2023

[122] AIVD, Threat Assessment of State Actors 2025

[123] NCTV, Cybersecurity Assessment Netherlands 2025

[124] AIVD, Threat Assessment of State Actors 2025

[125] AIVD, Threat Assessment of State Actors 2025

[126] NCTV, Cybersecurity Assessment Netherlands 2025

[127] CISA et al., AA24-038A, February 2024

[128] Palo Alto Networks Unit 42, 2023

[129] MITRE ATT&CK, Volt Typhoon G1017

[130] Palo Alto Networks Unit 42, 2023

[131] Mandiant, M-Trends 2025

[132] CISA et al., AA24-038A, February 2024

[133] CISA et al., AA23-144A, May 2023

[134] AIVD, Threat Assessment of State Actors 2025

[135] NCTV, Cybersecurity Assessment Netherlands 2025

Learn more about our threat research?

Get in touch