DEFCON 3 · ELEVATED OBSERVATORY STATUS
04:24:00 UTC
EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30
groupactive

Volt Typhoon (Bronze Silhouette / Vanguard Panda)

KNOWN ALIASES: Bronze Silhouette · Vanguard Panda · UNC3236 · Dev-0391 · Voltzite
EXECUTIVE INTELLIGENCE SUMMARY

State-sponsored threat actor focused on stealth pre-positioning within critical infrastructure networks to enable disruptive kinetic or cyber sabotage.

Volt Typhoon emphasizes stealth and evasion, almost exclusively utilizing living-off-the-land binaries (LotLBs) and compromised SOHO routers (KV-Botnet) to avoid detection while establishing deep persistence across telecommunications, power grids, water utilities, and maritime transit hubs.

MAJOR ATTRIBUTED OPERATIONS
2026 · Pacific Telecommunications Fiber Tap ReconnaissanceTARGET: Subsea Cable Landing Stations & Carrier Routers

Long-term credential extraction and router configuration modifications across trans-Pacific gateway switches.

2023 · Guam Military & Critical Infrastructure InfiltrationTARGET: Communications & Energy Infrastructure on Guam

Compromise of Fortinet and Cisco edge appliances to maintain persistent access during geopolitical crisis scenarios.

SOURCE CITATIONS & ATTESTATIONS (1)
CISA Joint Cybersecurity Advisory: PRC State-Sponsored Actors Compromise US Critical InfrastructureCISA / NSA / FBI / Five Eyes

Volt Typhoon Living-off-the-Land Advisory

TELEMETRY CARDID: group-volt-typhoon
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
People’s Republic of China (PRC)
INDEXED TAGS
#apt#pre_positioning#critical_infrastructure#lotl#edge_compromise#router_botnet