Volt Typhoon
View MITRE Group Page ↗Key Facts
- Attributed Country: People's Republic of China.
- ATT&CK Group Reference: G1017 (Volt Typhoon).
- Linked to 1 primary court prosecution records.
- Identified 0 individually charged operatives.
Primary ATT&CK Techniques Employed
| Technique | Frequency |
|---|---|
| T1078 Valid Accounts | 1 incidents |
| T1190 Exploit Public-Facing Application | 1 incidents |
| T1584 Compromise Infrastructure | 1 incidents |
| T1059.003 Windows Command Shell | 1 incidents |
| T1016 System Network Configuration Discovery | 1 incidents |
| T1018 Remote System Discovery | 1 incidents |
| T1033 System Owner/User Discovery | 1 incidents |
| T1057 Process Discovery | 1 incidents |
Prosecution Cases Attributed to This Actor
Volt Typhoon Critical Infrastructure Pre-Positioning
State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.
Targeted Defensive Hardening for Volt Typhoon
Primary Initial Access Defense
Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.
Lateral Movement Interception
Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.