Volt Typhoon: Hunting the Ghost Already Living in Your Network

Volt Typhoon, living off the land, KV botnet.

If those three terms do not snap together into one coherent threat picture in your head, then your security operations center (SOC) probably has a detection gap, and something might be quietly exploiting it right now. 

This is the actor your security information and event management (SIEM) platform almost certainly misses, because Volt Typhoon does not bring malware to the fight. They use your tools, your systems, your credentials, and they have been doing that for over five years. 

Most coverage of this group fixates on geopolitics. This guide does not. We are going to walk through it tool by tool, technique by technique, and indicator by indicator, so you can actually hunt it. Let’s get started.


Who Is Volt Typhoon?

Let me get the naming chaos out of the way first, because it trips everyone up.

You will see this actor called Vanguard Panda, BRONZE SILHOUETTE, UNC3236, Insidious Taurus, VOLTZITE, Dev-0391, and G1017, depending on which vendor’s report you are reading. 

Microsoft assigned the label Volt Typhoon, and that is the tag the Five Eyes agencies use in their joint advisories, so it is the one we will stick with here.

One actor, six aliases, and that is before you reach the Microsoft label.

The fragmentation is itself an intelligence signal. When a single group carries half a dozen designations, it usually means it was tracked in silos for years, by separate teams who could not see the full campaign. That alone tells you how patient and quiet this actor has been. 

Our primer on threat actors covers how groups get categorized by motive and capability, the lens we are about to apply.

Attribution here is unusually firm. The joint advisory from CISA and its Five Eyes partners attributes the activity to the People’s Republic of China state-sponsored actors. Separate analysis widely assesses Volt Typhoon as a People’s Liberation Army (PLA) operation. Either way, this is not a criminal crew monetizing access.

Do not confuse Volt Typhoon with Salt Typhoon. They share a national sponsor and a weather-themed name, but little else. Volt Typhoon is assessed as a PLA effort focused on pre-positioning for disruption. Salt Typhoon is the espionage-focused group widely linked to the Ministry of State Security (MSS).

The motive is not money. It is pre-positioning.

Volt Typhoon embeds persistent footholds inside US water systems, power grids, and telecommunications providers, then sits on them, waiting. The confirmed victim base is overwhelmingly American, including its Pacific territories, though the Five Eyes co-authors treat allied infrastructure as the same target set. The plan is to have those footholds ready to activate together if geopolitical tensions escalate into conflict.

The targeting profile confirms the intent. They are not hitting defense contractors or government networks for espionage value. They are targeting municipal water supplies, electrical substations that supply hospitals, regional internet service providers (ISPs), and port utility systems in Guam. None of it is about stealing secrets. All of it is about being able to turn off the lights.

Pre-positioning is the whole game. Volt Typhoon is not trying to act today. It is trying to be everywhere it needs to be, undetected, so that it can act everywhere at once on a day of its choosing. Treat a quiet intrusion in critical infrastructure as a loaded weapon, not a low-priority alert.

Now we know the current situation, the question is… how did we get here?

A Five-Year Timeline of Quiet Pre-Positioning

Mid 2021: KV Botent

In mid-2021, Volt Typhoon began constructing what would become the KV botnet, a network of compromised small office and home office (SOHO) routers used to mask command-and-control (C2) traffic. This was foundational work. They were building the highway before they started driving on it.

August 2022: Attack on Guam

Guam sits at the strategic heart of the campaign. CISA documented at least one confirmed intrusion where Volt Typhoon gained entry through an unpatched FortiGate firewall, exploiting the Common Vulnerabilities and Exposures (CVE) entry CVE-2022-42475, and the actor’s focus on utility infrastructure near Andersen Air Force Base and nearby naval installations was no accident. Those installations would be central to any US response in a Pacific conflict.

May 2023: Microsoft Reporting

In May 2023, Microsoft publicly disclosed the campaign, and the wider security community finally woke up to what had been running quietly in the background for years. The lesson there is brutal but worth internalizing: by the time a nation-state actor is publicly named, you should assume your sector’s peers are already compromised, and possibly that you are too.

December 2023: DoJ Takedown

In December 2023, the Department of Justice (DOJ) and the FBI conducted a court-authorized operation to remotely delete the KV botnet malware from hundreds of infected routers across the US. It caused real disruption. It also did not last. Within a concentrated three-day window that same month, Lumen’s Black Lotus Labs observed the operators attempting to re-exploit roughly 2,100 NetGear ProSAFE devices that were still exposed online, in an attempt to rebuild the network.

This is not a hacktivist collective or a ransomware gang working off laptops. It is an industrialized, well-resourced operation that treats its botnet as a critical capability worth rebuilding the moment it is touched.

January 2024: Congressional Testimony

FBI Director Christopher Wray, testifying before the House Select Committee on January 31, 2024, said China’s hackers were positioning to “wreak havoc and cause real-world harm to American citizens.” At the same hearing, then-CISA Director Jen Easterly described the scenario as “Everything Everywhere, All at Once,” with simultaneous failures across telecom, water, transport, and power. The threat moves from classified briefings to public record.

Mid 2024: Remergence

In mid-2024, Volt Typhoon was tied (with moderate confidence) to the exploitation of CVE-2024-39717, a zero-day in Versa Director SD-WAN software, used to reach internet service providers (ISPs) and managed service providers (MSPs). They wanted a bigger blast radius.

February 2026: Current Situation

Then, in February 2026, Dragos released its annual OT/ICS Cybersecurity Year in Review and confirmed the actor is still active, still embedded, and still unresolved inside US utilities.

Five years of documented activity, live right now. That is the landscape your SOC is operating in. But, how are they doing it?


Living Off the Land: The Toolkit That Breaks Your Stack

Here is the single fact that breaks most detection programs: Volt Typhoon almost never deploys custom malware.

Every capability your SOC has built around signature matching, file hash reputation, and sandboxing is partially blind to this actor. There is no malicious binary to flag. There is no payload to detonate. The technique is called living off the land (LOTL), which means using legitimate tools already present on the victim’s systems.

Think of it this way:

  • A traditional intruder is a burglar carrying a bag of specialized tools. Your security guard spots the crowbar and the lock picks and stops them at the door, because those tools do not belong there. 
  • Volt Typhoon is the janitor. They walk through the front entrance, use the building’s own mops, keys, and maintenance corridors. To anyone watching the cameras, it looks like a normal Tuesday morning.

The toolkit is entirely native Windows binaries. Every one of these ships with Windows has a legitimate administrative use, which is exactly why they slip past your endpoint detection and response (EDR) tooling.

Native toolWhat Volt Typhoon uses it forWhy it slips past detection
WMICRecon of OS version, patch level, and hardwareRuns in memory, with nothing written to disk
NetSHPort forwarding to tunnel trafficLooks like a routine local network change
Net User / Net GroupMapping admin accounts and domain structureStandard commands that an admin runs every day
schtasks.exePersistence through scheduled tasksNo persistent binary, mimics routine maintenance
NTDSUtilSnapshotting Active Directory to dump every password hashA signed, built-in tool, not malware

MITRE ATT&CK mappings to anchor your detections:

Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The Windows command prompt can be used to control almost any aspect of a system, with various permission levels required for different subsets of commands. The command prompt can be invoked remotely via Remote Services such as SSH.

Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members, such as devices, users, and access rights. By default, the NTDS file (NTDS.dit) is located in %SystemRoot%\NTDS\Ntds.dit of a domain controller.

T1090 Proxy (use of internal and external proxies)

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure. Many tools exist that enable traffic redirection through proxies or port redirection, including HTRAN, ZXProxy, and ZXPortMap.

Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The schtasks utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.

Building detections around those technique IDs, not file signatures, is how you start to see this actor. Our MITRE ATT&CK framework guide covers mapping behavior to technique IDs, and our intro to detection engineering covers turning those into working rules.

That said, living off the land is not the only way Volt Typhoon is able to evade your detections. There is also the genius of the KV botnet.


The KV Botnet: Hiding in Plain Sight

Once Volt Typhoon is inside, how do they operationalize that access without lighting up your geofencing controls?

They do not connect your network back to a server in Beijing. That would trip IP reputation checks instantly, and your stack is well-positioned to catch it. Instead, they route their C2 through the KV botnet.

That network of compromised SOHO routers makes traffic from Beijing appear to be from an ordinary home broadband customer rather than a state actor on the other side of the world. 

The hardware is end-of-life, unpatched, and forgotten, sitting in small businesses, back offices, and home networks, still plugged into the internet. Custom, MIPS-based malware turns those boxes into operational relay boxes (ORBs), transparent proxies that blend into your network’s traffic baseline and pass for ordinary residential activity.

If you run perimeter equipment that is past end of life and still exposed to the internet, that hardware is a recruitment candidate for the next iteration of their botnet. It will get targeted.

Hacking techniques aside, let’s move up the chain of command and explore how Volt Typhoon operates on a tactical level.


SYLVANITE: The Two-Phase Operation

Before Volt Typhoon settles in for the long dwell, someone else usually opens the door. There is a distinct initial access cluster that Dragos tracks as SYLVANITE, and it handles the perimeter breach.

SYLVANITE exploits public-facing edge devices: FortiGate SSL VPNs, Ivanti Connect Secure, Zoho ManageEngine, and similar appliances. These are your network’s front doors, and the exploits are often publicly documented CVEs. The real problem is that the vulnerabilities remain unpatched long enough for the group to walk through them.

SYLVANITE’s job is entry and internal mapping. Once the environment is charted and access is stable, it hands the keys to Volt Typhoon for the long-term dwelling and pre-positioning. This two-phase model explains a pattern that confuses many incident responders.

You may find clear evidence of initial exploitation with no obvious follow-on activity. That is not necessarily a failed attack. The follow-on can be very quiet and may arrive months or even years after the initial breach.

Next question: how do you find a ghost that operates inside your own wires?


How to Hunt Volt Typhoon in Your Environment

File-based detection fails against this actor. If your detection posture is signature-dependent, you are operating blind. The shift you need is from “what files exist on this host?” to “what are these processes doing that they should not be doing?” The question stops being is this file malicious and becomes does this behavior look abnormal for my environment?

This is the move our Pyramid of Pain guide describes: away from cheap, disposable indicators and toward the tactics, techniques, and procedures (TTPs) an actor cannot easily change. That is the core of threat hunting, and it is where this group gets caught.

Here are five hunts to prioritize.

Hunt 1: Process creation anomalies

Hunt for NTDSUtil.exe running with install-from-media arguments that write to publicly accessible folders. No legitimate administrator backs up the Active Directory database to a location like that. If it fires on a domain controller, treat it as a confirmed compromise until you prove otherwise. Here is a Sigma rule you can adapt to your SIEM:

YAML
title: NTDSUtil Install-From-Media to a Public Path
id: 6f8e2a1c-3b7d-4e9a-8c2f-1a5d9b4e7c30
status: experimental
description: Detects use of ntdsutil IFM 'create' to copy the AD database (ntds.dit), a common credential-theft technique on domain controllers.
Description: 
references:
  - https://attack.mitre.org/techniques/T1003/003/
tags:
  - attack.credential-access
  - attack.t1003.003
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    Image|endswith: '\ntdsutil.exe'
    CommandLine|contains|all:
      - 'create'
      - 'ifm'
    CommandLine|contains:
      - 'C:\Users\Public'
      - 'C:\Windows\Temp'
      - 'C:\PerfLogs'
  condition: selection
level: high

Hunt 1: Suspicious Port Forwarding

Hunt for NetSH commands to configure a port proxy, then trace where the traffic goes. The giveaway is a process named netsh.exe with a command line containing interface portproxy add v4tov4, which legitimate endpoint administration almost never uses.

Hunt 3: Logon Baselining With Event ID 4624

This is the Windows logon success event. A successful logon to a privileged account from a residential ISP outside business hours is exactly what an ORB relay connection looks like.

Hunt 4: Staging Directories

Watch file creation in locations like C:\Users\Public, C:\Windows\Temp, and PerfLogs. The CISA advisory on Volt Typhoon confirms these as staging spots for extracted ntds.dit and SYSTEM registry hives, so any unexpected database or hive copies parked there deserve immediate attention.

Hunt 5: Renamed tools

Hunt for Impacket secretsdump.py behavior on hosts that have no business running it, and flag oddly named processes like cisco.exe or vmd_service.exe, which have appeared as renamed fast reverse proxy (FRP) clients. Attackers love to rename their tooling to blend in with legitimate services, so common misspellings of trusted application names are worth a closer look.

NTDSUtil writing an install-from-media snapshot to a public folder is about as close to a smoking gun as living-off-the-land tradecraft gets. If you build only one Volt Typhoon detection, build that one. 


Strategic Defenses That Actually Move the Needle

Hunting is the operational layer. Above it sits a strategic layer, and two priorities matter more than the rest.

First, segment your IT and OT networks. Volt Typhoon’s entire lateral movement chain depends on pivoting from your information technology network into your operational technology environment, where control of physical systems such as water, gas, and telecommunications is actually exercised. An air gap, or robust segmentation with monitoring on every cross-point, breaks the kill chain at its most critical juncture.

Second, deploy phishing-resistant multi-factor authentication (MFA) on every privileged account. Volt Typhoon lives on valid credentials because that is how they blend in. Take away easy credential movement, and you force them into noisier techniques that your EDR and SIEM can catch.

Strong IT/OT segmentation and phishing-resistant MFA give you:

  • A broken kill chain, since the pivot from IT into OT is where pre-positioning becomes physical risk.
  • Forced noise, because credential theft stops being a quiet win and starts generating detectable behavior.
  • Faster triage, as anomalies that survive these controls are far more likely to be real.
  • A defensible posture you can demonstrate to regulators and leadership, rather than one you simply hope holds. 

This Is Bigger Than One Country

You will often see the cyber threat intelligence community frame Volt Typhoon as a “China problem.” Tactically, that is correct, but strategically, it is a dangerous oversimplification.

Every major nation-state, including the US and its allies, is building the same pre-positioning capabilities, and the doctrine of dwell without action and degrade without attribution is spreading. So if your threat model only accounts for the PRC targeting your OT, it is already out of date. Assume more than one party may be inside, and hunt for the anomalies that stand out.


Where Volt Typhoon Stands in 2026

Current status: active.

The Dragos 2026 report confirms that Volt Typhoon remains embedded in US utilities, with the SYLVANITE initial access cluster still targeting edge devices. Priority targets include Fortinet and Ivanti appliances, as well as other SOHO-grade edge gear. If you run edge devices in the critical infrastructure space, you are inside a targeting window.

The trajectory tracks geopolitics. Expect activity to rise against the Pacific region, and watch MSP- and ISP-run supply chains. One MSP compromise can hand an attacker dozens of downstream infrastructure clients, so if you outsource network management, that provider’s posture is now your attack surface.

CISA has been blunt that what has been found is only the tip of the iceberg. Many small municipal utilities lack the tooling, budget, or expertise to realize they have been compromised, and Dragos says some breaches may never be found, given how thin OT resources are.

This guide has shown you what most coverage skips: the tradecraft.

Volt Typhoon is a patient, state-sponsored actor that pre-positions inside critical infrastructure, lives off the land using native Windows tools, hides its C2 behind a botnet of forgotten home routers, and relies on the SYLVANITE cluster to get in the door. Your signature-based stack will not see it. A behavioral hunting program, anchored to MITRE ATT&CK technique IDs and backed by IT/OT segmentation and phishing-resistant MFA, will.

Stay sharp, and happy hunting.

Frequently Asked Questions

What is Volt Typhoon?

Volt Typhoon is a People’s Republic of China state-sponsored threat actor, also tracked as Vanguard Panda, BRONZE SILHOUETTE, UNC3236, VOLTZITE, and Insidious Taurus. Active since at least mid-2021, it specializes in pre-positioning inside the US and allied critical infrastructure rather than stealing data for profit.

What Does “Living off the Land” Mean?

Living off the land (LOTL) is the use of legitimate, native tools already present on a target system instead of custom malware. Volt Typhoon uses built-in Windows utilities such as WMIC, NetSH, Net User, schtasks.exe, and NTDSUtil, which let its activity blend in with normal administration and slip past signature-based defenses.

What is the KV botnet?

The KV botnet is a network of compromised small office and home office routers that Volt Typhoon uses to relay its command-and-control traffic. By routing through end-of-life residential devices, the group disguises its activity as ordinary broadband traffic and avoids IP reputation and geofencing checks.

How Do You Detect Volt Typhoon?

You detect Volt Typhoon through behavioral threat hunting rather than file signatures. Prioritize hunts for NTDSUtil writing snapshots to public folders, suspicious NetSH port forwarding, privileged logons from residential ISPs outside business hours, and staging directories holding ntds.dit copies, and renamed proxy tools like FRP clients.

Is Volt Typhoon Still Active in 2026?

Yes. The Dragos 2026 OT/ICS Cybersecurity Year in Review confirms that Volt Typhoon remains embedded in US utilities, with the SYLVANITE initial access cluster still exploiting edge devices from vendors such as Fortinet and Ivanti.