Volt Typhoon

Description

(Microsoft) Microsoft has uncovered stealthy and targeted malicious activity focused on post-compromise credential access and network system discovery aimed at critical infrastructure organizations in the United States. The attack is carried out by Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.

Volt Typhoon has been active since mid-2021 and has targeted critical infrastructure organizations in Guam and elsewhere in the United States. In this campaign, the affected organizations span the communications, manufacturing, utility, transportation, construction, maritime, government, information technology, and education sectors. Observed behavior suggests that the threat actor intends to perform espionage and maintain access without being detected for as long as possible. Microsoft is choosing to highlight this Volt Typhoon activity at this time because of our significant concern around the potential for further impact to our customers. Although our visibility into these threats has given us the ability to deploy detections to our customers, the lack of visibility into other parts of the actor’s activity compelled us to drive broader community awareness and further investigations and protections across the security ecosystem.

Names

NameName-Giver
Volt TyphoonMicrosoft
Vanguard PandaCrowdStrike
Bronze SilhouetteSecureWorks
RedflySymantec
Insidious TaurusPalo Alto
VOLTZITEDragos
Dev-0391Microsoft
Storm-0391Microsoft
UNC3236Mandiant
UAT-5918Talos

Country

State-sponsored

Motivation

  • Information theft and espionage

First Seen

2020

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Other Information

Uuid

a8b73194-0ca4-41b0-85ff-3793b83e47c0

Last Card Change

2025-04-21