← All Threat Actors
Nation-State critical China (PRC)

Volt Typhoon

Chinese state-sponsored · Pre-positioning / espionage

Reports 3
Active Since 2021
Last Reported 21 May 2026
Sectors Targeted government, critical-infrastructure, ot-ics, communications, transport

Tactics, Techniques & Procedures (TTPs)

  • Living off the land (LOTL) — avoids custom malware
  • SOHO/edge device compromise (routers, firewalls)
  • Operational Relay Box (ORB) networks for traffic obfuscation
  • Credential harvesting via built-in OS tools
  • OT/ICS network access via IT pivot
  • Long-duration, stealthy persistence (months to years)

Known Targets

US and UK critical national infrastructureWater and energy utilitiesTelecommunicationsTransportationDefence industrial base

Analyst Notes

Assessed by CISA, NSA, NCSC, and Five Eyes partners as focused on pre-positioning for potential disruptive attacks on CNI rather than immediate intelligence collection.

Also Known As

Bronze SilhouetteVanguard PandaDev-0391