TL;DR: Volt Typhoon is a People's Republic of China (PRC) state-sponsored advanced persistent threat (APT). Microsoft, which first described it publicly in May 2023, says it has been active since mid-2021 [5]. The joint advisory AA24-038A from CISA, NSA, FBI, DOE, EPA, TSA and the cyber agencies of Australia, Canada, the UK and New Zealand, released February 7, 2024, says the US agencies observed indications of Volt Typhoon keeping footholds in some victim IT environments for at least five years, primarily in the Communications, Energy, Transportation Systems, and Water and Wastewater Systems sectors, in the continental and non-continental United States and its territories, including Guam [1]. The advisory names sectors, not companies. Outside the US, Bloomberg reported in November 2024 that Volt Typhoon breached Singtel in Singapore; Singtel confirmed it found and removed malware in June 2024 but said it could not confirm a link to Volt Typhoon [2][7]. A court-authorized US operation in December 2023, announced on January 31, 2024, deleted the "KV Botnet" malware from hundreds of hijacked small-office/home-office (SOHO) routers, most of them end-of-life Cisco and NetGear models, that the group used to hide its traffic [3]. The playbook is living-off-the-land: Volt Typhoon rarely uses malware after initial access, relies on built-in tools such as ntdsutil, wmic, netsh and PowerShell, and commonly exploits networking appliances from vendors including Fortinet, Ivanti, NETGEAR, Citrix and Cisco [1][5]. The most recent dated item on this page is from November 2025.

What Volt Typhoon Actually Is

Volt Typhoon is a label for a PRC state-sponsored cyber group, not a single hacker. CISA, NSA, FBI and partner agencies attribute the activity to PRC state-sponsored cyber actors and list the group's other industry names as Vanguard Panda, BRONZE SILHOUETTE, Dev-0391, UNC3236, Voltzite and Insidious Taurus [1]. The first public descriptions came on May 24, 2023, when Microsoft published its analysis and the US, Australian, Canadian, New Zealand and UK cyber agencies issued joint advisory AA23-144A on the same actor's living-off-the-land techniques [5][6].

Two things distinguish Volt Typhoon from more familiar espionage crews. First, the US agencies say its choice of targets and behaviour "is not consistent with traditional cyber espionage or intelligence gathering operations." They assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to operational technology (OT) assets to disrupt functions [1]. AA24-038A says PRC state-sponsored actors are seeking to pre-position "for disruptive or destructive cyberattacks against U.S. critical infrastructure in the event of a major crisis or conflict with the United States" [1]. Microsoft's 2023 assessment, made with moderate confidence, was that the campaign was developing capabilities that could disrupt critical communications infrastructure between the United States and the Asia region during future crises [5]. Second, Volt Typhoon hides its traffic inside compromised SOHO devices. According to the Justice Department, the vast majority of routers in the KV Botnet were Cisco and NetGear routers that were no longer supported through their manufacturer's security patches or other software updates [3].

Publicly Reported Victims

The public victim list is short. Volt Typhoon's tradecraft is built to avoid detection, and government advisories describe victims by sector rather than by name. Each entry below states who reported it and how firmly.

US Critical Infrastructure (Communications, Energy, Transportation, Water)

The most authoritative statement of victim scope comes from AA24-038A: the US authoring agencies "have confirmed that Volt Typhoon has compromised the IT environments of multiple critical infrastructure organizations," primarily in the Communications, Energy, Transportation Systems, and Water and Wastewater Systems sectors, "in the continental and non-continental United States and its territories, including Guam" [1]. The advisory adds that "some victims are smaller organizations with limited cybersecurity capabilities that provide critical services to larger organizations or key geographic locations" [1]. AA24-038A does not name specific US companies.

Organizations on Guam

Microsoft's May 2023 report said Volt Typhoon had targeted critical infrastructure organizations in Guam and elsewhere in the United States, and that affected organizations spanned the communications, manufacturing, utility, transportation, construction, maritime, government, information technology and education sectors [5]. AA24-038A explicitly includes Guam in its geographic scope [1]. Specific network owners on Guam have not been named publicly.

Singtel, Singapore (reported November 2024)

On November 5, 2024, Bloomberg, citing two people familiar with the matter, reported that Volt Typhoon had breached Singtel, that the intrusion was discovered in June, and that it was "a test run by China for further hacks against US telecommunications companies" [2][7]. Singtel, Singapore's largest telecom operator, told CNA: "Our protective and detective measures picked up the malware and eradicated it, and this was reported to the relevant authorities" [7]. In an email to The Register, Singtel confirmed it detected malware in June but said it could not confirm a link to Volt Typhoon, and said no data was stolen and no services were impacted [2]. Singapore's Cyber Security Agency and IMDA said they understood from Singtel that no service was affected and no data loss was reported [7]. The Register, citing Bloomberg, reported that a web shell was used in the breach [2]. The attribution of the Singtel intrusion to Volt Typhoon therefore rests on anonymous sourcing; Singtel has not confirmed it.

US Internet Providers via Versa Director (reported August 2024)

In August 2024, researchers at Lumen Technologies' Black Lotus Labs attributed, "with moderate confidence," the exploitation of a Versa Director zero-day (CVE-2024-39717) to Volt Typhoon [2][8]. According to The Record's account of the research, the group used the flaw to upload a custom web shell named VersaMem that intercepted and harvested credentials, and the targets reportedly included four US victims and one non-US victim in the internet service provider, managed service provider and IT sectors [8]. The victims were not named.

Australia (warning, November 2025)

In a November 2025 speech, ASIO director-general Mike Burgess said Salt Typhoon and Volt Typhoon were "working for the Chinese government and their military," described Volt Typhoon's intent in the US as to "pre-position for potential sabotage," and said: "we have seen Chinese hackers probing our critical infrastructure as well" [10]. According to The Guardian, Burgess did not say which Chinese units had targeted Australian infrastructure or whether they had gained access [10]. That speech does not establish a Volt Typhoon victim in Australia.

The Playbook: How Volt Typhoon Gets In And Stays In

The joint advisory AA24-038A lists the techniques in detail [1]. The core entry vectors and tradecraft:

  • Exploiting internet-facing appliances. AA24-038A says Volt Typhoon actors commonly exploit vulnerabilities in networking appliances such as those from Fortinet, Ivanti Connect Secure (formerly Pulse Secure), NETGEAR, Citrix and Cisco, often with publicly available exploit code, and are also adept at discovering and exploiting zero-days [1]. In one confirmed compromise, the actors likely gained initial access by exploiting CVE-2022-42475 in an unpatched FortiGate 300D perimeter firewall, with evidence of a buffer overflow attack in the SSL-VPN crash logs [1]. Separately, Black Lotus Labs linked Volt Typhoon, with moderate confidence, to exploitation of the Versa Director flaw CVE-2024-39717 using the VersaMem web shell [8].
  • Living off the land. Microsoft reported in 2023 that Volt Typhoon rarely uses malware in its post-compromise activity [5]. AA24-038A lists the LOTL tools and commands the group uses for discovery: cmd, certutil, dnscmd, ldifde, makecab, net user/group/use, netsh, nltest, netstat, ntdsutil, ping, PowerShell, quser, reg query/reg save, systeminfo, tasklist, wevtutil, whoami, wmic and xcopy [1].
  • Credential dumping from the domain controller. AA24-038A documents Volt Typhoon using Mimikatz (and, per industry partners, Impacket), Magnet RAM Capture (MRC) version 1.20 on domain controllers, and, in one compromise, an outdated copy of the legitimate comsvcs.dll placed in a non-standard folder to dump LSASS memory [1]. In one compromise, Volt Typhoon likely extracted the Active Directory database NTDS.dit from three domain controllers in a four-year period; in another, it extracted NTDS.dit two times from a victim in a nine-month period [1]. Cracking the stolen hashes "allows Volt Typhoon actors to obtain elevated access and further infiltrate and manipulate the network" [1].
  • Hiding behind proxies and SOHO routers. AA24-038A says Volt Typhoon historically uses multi-hop proxies for command and control (T1090.003), typically built from virtual private servers (T1583.003) or SOHO routers, and recently used end-of-life Cisco and NETGEAR SOHO routers implanted with KV Botnet malware (T1584.005) [1]. The December 2023 court-authorized operation deleted the KV Botnet malware from the routers and took steps to sever their connection to the botnet, such as blocking communications with devices used to control it [3].
  • Lateral movement to OT. AA24-038A describes Volt Typhoon using valid administrator credentials and Remote Desktop Protocol to move laterally, says the group may be capable of Pass the Hash or Pass the Ticket (T1550), and describes access to PuTTY profiles for water treatment plants, water wells, an electrical substation and OT systems [1]. The advisory says this access enables potential disruptions such as manipulating HVAC systems in server rooms or disrupting critical energy and water controls, and that in some cases the actors had the capability to access camera surveillance systems at critical infrastructure facilities [1].
  • Defense evasion. AA24-038A documents Volt Typhoon packing tools with UPX (T1027.002), selectively clearing Windows event logs (T1070.001), removing other evidence of intrusion (T1070.009) and masquerading file names (T1036.005) [1]. Two Windows event IDs stand out in its detection table. For Event ID 1102 (audit log cleared), the advisory says: "All Event ID 1102 entries should be investigated as logs are generally not cleared and this is a known Volt Typhoon tactic to cover their tracks" [1]. Event ID 1017 in the System log is "Handle scavenged"; the advisory's example involves a History.zip file in a user's downloads folder [1].

The defensive lesson from AA24-038A is unglamorous. Its "actions to take today" are, in order: apply patches for internet-facing systems, implement phishing-resistant MFA, ensure logging is turned on and stored centrally, and plan "end of life" for technology beyond the manufacturer's supported lifecycle [1].

Who Runs Volt Typhoon

CISA, NSA, FBI, DOE, EPA, TSA and the Australian, Canadian, UK and New Zealand cyber agencies attribute Volt Typhoon to PRC state-sponsored cyber actors [1]. US government officials have said the goal is to slow down any potential military mobilization that may follow a Chinese invasion of Taiwan, according to The Record [8]. China disputes the attribution: in July 2024, China's National Computer Virus Emergency Response Center (CVERC) published a report arguing that Volt Typhoon was an invention of Western intelligence agencies and that any real attacks were the work of a ransomware gang, and ThreatMon, one of the companies the report cited, said the CVERC had completely mischaracterized its work [9].

When the Justice Department announced the KV Botnet operation on January 31, 2024, FBI Director Christopher Wray said: "China's hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict" [3]. He continued: "Volt Typhoon malware enabled China to hide as they targeted our communications, energy, transportation, and water sectors. Their pre-positioning constitutes a potential real-world threat to our physical safety that the FBI is not going to tolerate. We are going to continue to work with our partners to hit the PRC hard and early whenever we see them threaten Americans" [3][4]. John Riggi, the American Hospital Association's national advisor for cybersecurity and risk, said the removal of the malware was "proof positive that Chinese government cyber efforts are no longer solely focused on espionage and data theft" and that the actors "clearly intend to be in a position to inflict physical harm to our critical infrastructure, impacting the safety of hospitals and all Americans" [4].

What You Can Do If Volt Typhoon Touches Your Network

For critical-infrastructure organizations that find Volt Typhoon activity, AA24-038A lists specific incident-response steps [1]:

  • Sever the enterprise network from the internet. The advisory notes this requires understanding internal and external connections to avoid disrupting critical functions; if severing is not possible, shut down all non-essential traffic between the affected network and the internet [1].
  • Reset credentials, including krbtgt twice. The krbtgt account handles Kerberos ticket requests and signs them. AA24-038A says it should be reset twice "because the account has a two-password history," letting the first reset replicate before the second [1].
  • Audit network appliance and edge device configurations. Check running and boot-time configurations for unauthorized changes; if changes are found, change all credentials and keys used to manage those devices and update firmware [1].
  • Hunt for the host artifacts the advisory describes. These include C:\Users\Public\Documents\user.dat, C:\Users\Public\Documents\systeminfo.dat, C:\Windows\System32\rult3uil.log, the staging folders C:\Users\Public\pro and C:\Windows\Temp\tmp\Active Directory, and the file names BrightmetricAgent.exe, SMSvcService.exe, ronf.exe, rdpservice.exe and comsvcs.dll outside System32 [1].
  • Report to an authoring agency. In the US, CISA's 24/7 Operations Center at Report@cisa.gov or 1-844-Say-CISA (1-844-729-2472), or a local FBI field office. Water sector: watercyberta@epa.gov. Energy sector inquiries: EnergySRMA@hq.doe.gov. NSA: Cybersecurity_Requests@nsa.gov [1].
  • Apply cloud identity best practices. AA24-038A points to CISA's SCuBAGear tool and the SCuBA baselines for Microsoft cloud tenants [1].
  • Reconnect to the internet, then minimize remote access tools. The advisory says the decision to reconnect depends on senior leadership's confidence in the actions taken, and recommends minimizing and controlling the use of remote access tools and protocols [1].
  • Share technical information. The advisory suggests sharing with an authoring agency or a sector information sharing and analysis center, and publishes a STIX indicator file (MAR-10448362.c1.v2.CLEAR_stix2.json, 51.99 KB) and a malware analysis report (MAR-10448362-1.v1) [1].

For any organization running SOHO routers at the network edge, the practical step follows from the KV Botnet case: end-of-life Cisco and NetGear routers that no longer received security patches made up the vast majority of that botnet [3], and AA24-038A tells organizations to plan "end of life" for technology beyond the manufacturer's supported lifecycle [1].

The Honest Takeaway

Volt Typhoon is one of the clearest documented examples of state-sponsored pre-positioning. The tradecraft is built to hide inside an organization's own tools and perimeter, with little malware to detect. AA24-038A's detection table points defenders to specific event IDs: ESENT 216, 325, 326, 327 and 637 in the Application log, 1102 in the Security log, 1017 in the System log, and 21 through 25 in the Terminal Services Local Session Manager Operational log [1]. The advisory also names CISA's SCuBAGear and gait, a Zeek extension developed by Sandia National Labs for spotting network proxy activity [1].

The public record has limits. The government advisories name sectors, not victims; the Singtel and Versa attributions rest on anonymous sourcing or moderate-confidence private research; and nothing on this page documents new Volt Typhoon activity in 2026. This tracker will be updated if new victims are confirmed or new official actions are announced.

Sources

  1. CISA, NSA, FBI and partners, PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A, February 7, 2024)
  2. The Register, China's Volt Typhoon reportedly breached Singtel in 'test-run' for US telecom attacks (November 6, 2024)
  3. US Department of Justice, U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure (January 31, 2024)
  4. American Hospital Association, FBI and DOJ disrupt campaign targeting critical infrastructure through small/home office routers (February 5, 2024)
  5. Microsoft Threat Intelligence, Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (May 24, 2023)
  6. NSA, CISA, FBI, ACSC, CCCS, NCSC-NZ and NCSC-UK, People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection (AA23-144A, May 24, 2023)
  7. CNA, Singtel detected and 'eradicated' malware said to be from Chinese hacking group (November 5, 2024)
  8. The Record, China's Volt Typhoon reportedly targets US internet providers using Versa zero-day (August 27, 2024)
  9. The Record, Chinese cyber agency accused of 'false and baseless' claims about US interfering in Volt Typhoon research (July 11, 2024)
  10. The Guardian, Asio accuses Chinese hackers of seeking access to Australia's critical infrastructure (November 11, 2025)