Threat Actor ๐Ÿ‡จ๐Ÿ‡ณ China

Volt Typhoon

Also known as: BRONZE SILHOUETTE ยท VANGUARD PANDA ยท UNC3236 ยท Insidious Taurus ยท VOLTZITE ยท Dev-0391 ยท Storm-0391

[Microsoft] Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises. [Secureworks] BRONZE SILHOUETTE likely operates on behalf the PRC. The targeting of U.S. government and defense organizations for intelligence gain aligns with PRC requirements, and the tradecraft observed in these engagements overlap with other state-sponsored Chinese threat groups.

MITRE ATT&CK TTPs 5

Source Articles

CISA shares advice on isolating vital systems during cyberattacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), the FBI, and international partners have released guidance titled 'CI Fortify โ€“ Advice for isolating vital systems' to help critical infrastructure organizations prepare for cyberattacks. The guidance emphasizes the need to isolate operational technology (OT) systems from corporate and Internet-facing networks to maintain essential services during attacks. State-sponsored actors like Volt Typhoon and Salt Typhoon have targeted critical infrastructure sectors, including communications, energy, water, and transportation, with long-term access aimed at potential disruption during crises.
bleeping-computer ยท1mo ago
New InfraTrust report reveals infrastructure flaws admins should patch first
The July 2026 InfraTrust Pulse report by Eclypsium highlights critical infrastructure vulnerabilities that administrators should prioritize, focusing on those that are actively exploited, remotely accessible, or unauthenticated. Key vendors affected include SonicWall, Fortinet, Dell, F5, Juniper, and NVIDIA, with flaws impacting network edge devices, data center infrastructure, and firmware components. Russian and Chinese state-sponsored actors are increasingly targeting such infrastructure, as seen in campaigns linked to Volt Typhoon and Salt Typhoon. The report emphasizes risk-based prioritization over CVSS scores alone, noting that internet-exposed flaws pose significant real-world threats even if their severity scores are lower.
bleeping-computer ยท1mo ago
Closing the Identity Gaps in Critical Infrastructure Security
The article discusses the persistent threat to critical infrastructure from state-backed actors like Volt Typhoon, who exploit weak identity controls and compromised credentials to gain access and maintain long-term persistence. It highlights the Colonial Pipeline attack as an example of how a single unsecured VPN account can lead to widespread disruption. The focus is on the need for zero trust principles, particularly stronger identity and device verification, to defend against credential theft, living-off-the-land techniques, and unauthorized access through unmanaged devices.
bleeping-computer ยท1mo ago