Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ Volt Typhoon

🇨🇳Volt Typhoon

🇨🇳 Volt Typhoon is a tracked threat actor in the Clankerusecase corpus. Attributed to CN. Primary motivation: State. We map 18 detection use cases to this actor across 86 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-07-28 to 2026-07-28.

high 1
View full actor card → All threat actors MITRE ATT&CK group spec (G1017) ↗
18Use cases
1Articles
86Techniques
0IOCs

Known aliases

Volt TyphoonVanguard PandaBronze SilhouetteVOLTZITEBRONZE SILHOUETTEDEV-0391UNC3236VoltziteInsidious TaurusDazedToad

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1003.003 · NTDST1005 · Data from Local SystemT1006 · Direct Volume AccessT1007 · System Service DiscoveryT1010 · Application Window DiscoveryT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1016.001 · Internet Connection DiscoveryT1018 · Remote System DiscoveryT1021.001 · Remote Desktop ProtocolT1027.002 · Software PackingT1033 · System Owner/User DiscoveryT1036.005 · Match Legitimate Resource Name or LocationT1036.008 · Masquerade File TypeT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1056.001 · KeyloggingT1057 · Process DiscoveryT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.004 · Unix ShellT1068 · Exploitation for Privilege EscalationT1069 · Permission Groups DiscoveryT1069.001 · Local GroupsT1069.002 · Domain GroupsT1070.004 · File DeletionT1070.007 · Clear Network Connection History and ConfigurationsT1074 · Data StagedT1074.001 · Local Data StagingT1078 · Valid AccountsT1078.002 · Domain AccountsT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1090 · ProxyT1090.001 · Internal ProxyT1090.003 · Multi-hop ProxyT1105 · Ingress Tool TransferT1112 · Modify RegistryT1113 · Screen CaptureT1120 · Peripheral Device DiscoveryT1124 · System Time DiscoveryT1133 · External Remote ServicesT1140 · Deobfuscate/Decode Files or InformationT1217 · Browser Information DiscoveryT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1497.001 · System ChecksT1505.003 · Web ShellT1518 · Software DiscoveryT1552 · Unsecured CredentialsT1552.004 · Private KeysT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1560.001 · Archive via UtilityT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1573.001 · Symmetric CryptographyT1584.003 · Virtual Private ServerT1584.004 · ServerT1584.005 · BotnetT1584.008 · Network DevicesT1587.004 · ExploitsT1588.002 · ToolT1588.006 · VulnerabilitiesT1589 · Gather Victim Identity InformationT1589.002 · Email AddressesT1590 · Gather Victim Network InformationT1590.004 · Network TopologyT1590.006 · Network Security AppliancesT1591 · Gather Victim Org InformationT1591.004 · Identify RolesT1592 · Gather Victim Host InformationT1593 · Search Open Websites/DomainsT1594 · Search Victim-Owned WebsitesT1596.005 · Scan DatabasesT1614 · System Location DiscoveryT1654 · Log EnumerationT1680 · Local Storage DiscoveryT1685.005 · Clear Windows Event Logs

Detection use cases (18)

Volt Typhoon NTDS.dit domain-credential theft via ntdsutil IFM / VSS AI · profile SΣDD Volt Typhoon netsh portproxy pivot for covert traffic relay AI · profile SΣDD Remote service execution — PsExec / SMB lateral movement Internal Ransomware-style mass file rename / extension change Internal LSASS process access / dump (credential theft) Internal RMM tool installed by non-IT user — remote-access utility for hands-on-keyboard Internal 1Password activity from Tor exit node MITRE match 1Password impossible-travel sign-in MITRE match 1Password item exfiltration attempt MITRE match 1Password vault export attempted MITRE match AI-Agent Server (PraisonAI/MCP) Spawns OS Shell or Recon LOLBin — Unauthenticated RCE Exploitation MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request MITRE match Internet-Exposed AI Agent/LLM Service Spawns Shell or LOLBin After Inbound Connection MITRE match

Threat-intel articles (1)