CARDS
CARDS
Volt Typhoon is a state-sponsored cyber threat actor affiliated with the People's Republic of China, first observed active in mid-2021. This group distinguishes itself by primarily focusing on pre-positioning capabilities within critical infrastructure networks, particularly in the United States, to enable disruptive or destructive cyberattacks during potential future geopolitical crises rather than traditional espionage or intelligence gathering. Their operational approach heavily relies on stealth through extensive use of living-off-the-land techniques and the leveraging of compromised small office/home office (SOHO) network devices, allowing them to maintain long-term, undetected persistence within target environments for years. Volt Typhoon is also tracked under various aliases including VANGUARD PANDA, BRONZE SILHOUETTE, Dev-0391, UNC3236, Voltzite, Insidious Taurus, and Storm-0391.
This profile is generated from the same canonical actor-card record used by the Threat Actor Cards directory, so aliases, targeting fields, activity notes, and source links stay aligned as the database is enriched.
Actor Card Detail
Victim Count1
Not available
Identity
Source Boundary
SOCRadar is the retained baseline for this profile. IntelliOS preserves source labels as discovery and comparison signals until a cited source explicitly supports a merge, split, or actor-boundary change.
Targeting
Target Countries / Exposure1
Target Sectors1
Campaign Context
Indicators
SOCRadar reports 44 IOCs for this profile. IntelliOS currently retains 54 cited public observable/context rows; this is not the full possible public-source IOC corpus.
Source coverage: 5 source groups tracked; 4 currently contribute retained observable or context rows.
Retained Observables
Showing 55 of 55
| Type | Value | Source |
|---|---|---|
| SHA-256 Hash | 17506c2246551d401c43726bdaec800f8d41595d01311cf38a19140ad32da2f44 | Microsoft |
| SHA-256 Hash | 389a497f27e1dd7484325e8e02bbdf656d53d5cf2601514e9b8d8974befddf614 | Microsoft |
| SHA-256 Hash | 3a9d8bb85fbcfe92bae79d5ab18e4bca9eaf36cea70086e8d1ab85336c83945f5 | CISA |
| SHA-256 Hash | 3c2fe308c0a563e06263bbacf793bbe9b2259d795fcc36b953793a7e499e7f715 | CISA |
| SHA-256 Hash | 3e9fc13fab3f8d8120bd01604ee50ff65a40121955a4150a6d2c007d348076424 | Microsoft |
| SHA-256 Hash | 41e5181b9553bbe33d91ee204fe1d2ca321ac123f9147bb475c0ed32f94885975 | CISA |
| SHA-256 Hash | 450437d49a7e5530c6fb04df2e56c3ab1553ada3712fab02bd1eeb1f1adbc2674 | Microsoft |
| SHA-256 Hash | 472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d4 | Microsoft |
| SHA-256 Hash | 472ccfb865c81704562ea95870f60c08ef00bcd2ca1d7f09352398c05be5d05d5 | CISA |
| SHA-256 Hash | 4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a3103494 | Microsoft |
| SHA-256 Hash | 6036390a2c81301a23c9452288e39cb34e577483d121711b6ba6230b29a3c9ff4 | Microsoft |
| SHA-256 Hash | 66a19f7d2547a8a85cee7a62d0b6114fd31afdee090bd43f36b89470238393d75 | CISA |
| SHA-256 Hash | 7939f67375e6b14dfa45ec70356e91823d12f28bbd84278992b99e0d2c12ace54 | Microsoft |
| SHA-256 Hash | 8fa3e8fdbaa6ab5a9c44720de4514f19182adc0c9c6001c19cf159b79c0ae9c24 | Microsoft |
| SHA-256 Hash | 93ce3b6d2a18829c0212542751b309dacbdc8c1d950611efe2319aa715f3a0664 | Microsoft |
| SHA-256 Hash | 99b80c5ac352081a64129772ed5e1543d94cad708ba2adc46dc4ab7a0bd563f16 | CISA |
| SHA-256 Hash | 9dd101caee49c692e5df193b236f8d52a07a2030eed9bd858ed3aaccb406401a4 | Microsoft |
| SHA-256 Hash | b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc744 | Microsoft |
| SHA-256 Hash | baeffeb5fdef2f42a752c65c2d2a52e84fb57efc906d981f89dd518c314e231c4 | Microsoft |
| SHA-256 Hash | c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d4 | Microsoft |
| SHA-256 Hash | c4b185dbca490a7f93bc96eefb9a597684fdf532d5a04aa4d9b4d4b1552c283b4 | Microsoft |
| SHA-256 Hash | c7fee7a3ffaf0732f42d89c4399cbff219459ae04a81fc6eff7050d53bd69b995 | CISA |
| SHA-256 Hash | cd69e8a25a07318b153e01bba74a1ae60f8fc28eb3d56078f448461400baa9844 | Microsoft |
| SHA-256 Hash | d17317e1d5716b09cee904b8463a203dc6900d78ee2053276cc948e4f41c82954 | Microsoft |
| SHA-256 Hash | d6ab36cb58c6c8c3527e788fc9239d8dcc97468b6999cf9ccd8a815c8b4a80af4 | Microsoft |
| SHA-256 Hash | d6ebde42457fe4b2a927ce53fc36f465f0000da931cfab9b79a36083e914ceca5 | CISA |
| SHA-256 Hash | e453e6efc5a002709057d8648dbe9998a49b9a12291dee390bb61c98a58b6e954 | Microsoft |
| SHA-256 Hash | edc0c63065e88ec96197c8d7a40662a15a812a9583dc6c82b18ecd7e43b13b706 | CISA |
| SHA-256 Hash | ee8df354503a56c62719656fae71b3502acf9f87951c55ffd955feec90a114845 | CISA |
| SHA-256 Hash | ef09b8ff86c276e9b475a6ae6b54f08ed77e09e169f7fc0872eb1d427ee27d315 | CISA |
| SHA-256 Hash | f4dd44bc19c19056794d29151a5b1bb76afd502388622e24c863a8494af147dd5 | CISA |
| SHA-256 Hash | fe95a382b4f879830e2666473d662a24b34fccf34b6b3505ee1b62b32adafa155 | CISA |
| Tool / Process | custom Fast Reverse Proxy (FRP)4 | Microsoft |
| Tool / Process | EarthWorm4 | Microsoft |
| Tool / Process | Impacket4 | Microsoft |
| Tool / Process | living-off-the-land techniques6 | CISA |
| Tool / Process | LOLBins6 | CISA |
| Tool / Process | netsh4 | Microsoft |
| Tool / Process | network appliance compromise6 | CISA |
| Tool / Process | Ntdsutil4 | Microsoft |
| Tool / Process | ping4 | Microsoft |
| Tool / Process | PowerShell4 | Microsoft |
| Tool / Process | router and firewall footholds6 | CISA |
| Tool / Process | systeminfo4 | Microsoft |
| Tool / Process | valid accounts6 | CISA |
| Tool / Process | wevtutil4 | Microsoft |
| Tool / Process | wmic4 | Microsoft |
| CVE | CVE-2021-278605 | CISA |
| CVE | CVE-2021-405395 | CISA |
| CVE | CVE-2022-424756 | CISA |
| CVE | CVE-2024-397172 | MITRE |
| Campaign Context | CISA and partner agencies warned that PRC state-sponsored actors living off the land can evade endpoint detection and blend into normal Windows and network-administration activity.5 | CISA |
| Campaign Context | CISA's 2024 joint advisory assessed that PRC state-sponsored actors compromised and maintained persistent access to U.S. critical infrastructure, with emphasis on long-term disruptive potential and identity/network telemetry review.6 | CISA |
| Campaign Context | Microsoft reported Volt Typhoon targeting U.S. critical infrastructure using living-off-the-land techniques and custom Fast Reverse Proxy variants to evade detection.4 | Microsoft |
| Campaign Context | MITRE ATT&CK tracks Volt Typhoon / G1017 with aliases including BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236, Voltzite, Insidious Taurus, and DazedToad.2 | MITRE |
| Source | Reported | Retained | Coverage Status |
|---|---|---|---|
| SOCRadar1 | 44 | 0 | Reported IOC count retained; underlying SOCRadar feed values are not republished unless stored as cited public observables. |
| Microsoft Threat Intelligence4 | N/A | 30 | Public observables or source-context rows retained and displayed. |
| CISA5 | N/A | 14 | Public observables or source-context rows retained and displayed. |
| CISA6 | N/A | 9 | Public observables or source-context rows retained and displayed. |
| MITRE ATT&CK2 | N/A | 2 | Public observables or source-context rows retained and displayed. |
IntelliOS Intel Products
PANDA Flash Threat Intel Brief
Source-backed brief for MITRE C0039, CVE-2024-39717, CISA KEV context, VersaMem, and provider trust-path scoping.
CARDS Campaign
Canonical campaign record for Volt Typhoon's Versa Director exploitation activity.
Source Reconciliation
| Source | Primary Name | Treatment | Boundary |
|---|---|---|---|
| SOCRadar | Volt Typhoon | Baseline actor-card record retained for the current profile view. | Fields reflect the retained database record. Additional source consensus, collisions, and canonical identity mappings can be layered into this profile without automatically merging actors. |
| IntelliOS | Volt Typhoon | Normalizes this record for directory search, card display, profile lookup, and future product linking. | Normalization is a presentation and workflow aid; it is not an independent attribution claim. |
Citations
| # | Source | Use In Card |
|---|---|---|
| 1 | SOCRadar Threat Actor Database https://socradar.io/free-tools/threat-actor | Baseline actor-card corpus source for retained profile fields. |
| 2 | MITRE ATT&CK https://attack.mitre.org/groups/G1017 | Canonical ATT&CK group, campaign, software, aliases, and technique mapping source where matched. |
| 3 | MITRE CTI https://raw.githubusercontent.com/mitre/cti/master/enterprise-attack/enterprise-attack.json | Open MITRE CTI source used for ATT&CK enrichment. |
| 4 | Microsoft: Volt Typhoon Targets US Critical Infrastructure https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/ | Vendor Research |
| 5 | CISA: PRC State-Sponsored Cyber Actor Living off the Land https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a | Government Advisory |
| 6 | CISA: PRC Actors Maintain Persistent Access to U.S. Critical Infrastructure https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a | Government Advisory |
Source Collision Notes
IntelliOS starts this detail page from the retained source record for Volt Typhoon.
No possible same-actor, alias reuse, sub-cluster, duplicate-boundary, or external-source collision is currently retained for this actor.
| Collision Source | Candidate Records | Shared Evidence | Treatment |
|---|---|---|---|
| None retained | No candidate records | No shared evidence recorded | No collision action needed. |
| External sources | Mandiant, CrowdStrike, other non-SOCRadar sources | None retained | External collisions are shown separately when retained. |