EXPLORE DIRECTORY
LAST SYNCHRONIZED: 2026-08-30TLP:CLEAR
groupactive
Volt Typhoon (Bronze Silhouette / Vanguard Panda)
KNOWN ALIASES: Bronze Silhouette · Vanguard Panda · UNC3236 · Dev-0391 · Voltzite
EXECUTIVE INTELLIGENCE SUMMARY
State-sponsored threat actor focused on stealth pre-positioning within critical infrastructure networks to enable disruptive kinetic or cyber sabotage.
Volt Typhoon emphasizes stealth and evasion, almost exclusively utilizing living-off-the-land binaries (LotLBs) and compromised SOHO routers (KV-Botnet) to avoid detection while establishing deep persistence across telecommunications, power grids, water utilities, and maritime transit hubs.
MAJOR ATTRIBUTED OPERATIONS
2026 · Pacific Telecommunications Fiber Tap ReconnaissanceTARGET: Subsea Cable Landing Stations & Carrier Routers
Long-term credential extraction and router configuration modifications across trans-Pacific gateway switches.
2023 · Guam Military & Critical Infrastructure InfiltrationTARGET: Communications & Energy Infrastructure on Guam
Compromise of Fortinet and Cisco edge appliances to maintain persistent access during geopolitical crisis scenarios.
SOURCE CITATIONS & ATTESTATIONS (1)
CISA Joint Cybersecurity Advisory: PRC State-Sponsored Actors Compromise US Critical InfrastructureCISA / NSA / FBI / Five Eyes
Volt Typhoon Living-off-the-Land Advisory
TELEMETRY CARDID: group-volt-typhoon
ENTITY TYPE
group
STATE JURISDICTION / ORIGIN
People’s Republic of China (PRC)
INDEXED TAGS
#apt#pre_positioning#critical_infrastructure#lotl#edge_compromise#router_botnet
CONNECTED ENTITIES (2)VIEW IN GRAPH →