Volt Typhoon
Also reported as BRONZE SILHOUETTE, UNC3236, Insidious Taurus, Redfly, VOLTZITE and 11 other names. Linked to China by four sources.
Reports per quarter
Techniques seen in the last two years
- T1003.003 2 reports in ATT&CK
- T1003 1 report reports only
- T1003.001 1 report in ATT&CK
- T1003.002 1 report reports only
- T1003.004 1 report reports only
- T1003.005 1 report reports only
- T1003.006 1 report reports only
- T1003.007 1 report reports only
- T1003.008 1 report reports only
- T1021 1 report reports only
Show all 29 techniques Show fewer
- T1036 1 report reports only
- T1047 1 report in ATT&CK
- T1053.005 1 report reports only
- T1055.001 1 report reports only
- T1059.001 1 report in ATT&CK
- T1059.003 1 report in ATT&CK
- T1068 1 report in ATT&CK
- T1078 1 report in ATT&CK
- T1078.002 1 report in ATT&CK
- T1082 1 report reports only
- T1087 1 report reports only
- T1134 1 report reports only
- T1190 1 report in ATT&CK
- T1203 1 report reports only
- T1207 1 report reports only
- T1482 1 report reports only
- T1547 1 report reports only
- T1555.003 1 report in ATT&CK
- T1574 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
Show all 71 techniques Show fewer
- T1036.008
- T1046
- T1049
- T1056.001
- T1057
- T1059.004
- T1069
- T1069.001
- T1069.002
- T1070.004
- T1070.007
- T1074
- T1074.001
- T1083
- T1087.001
- T1087.002
- T1090
- T1090.001
- T1090.003
- T1105
- T1112
- T1113
- T1120
- T1124
- T1133
- T1140
- T1217
- T1218
- T1497.001
- T1505.003
- T1518
- T1552
- T1552.004
- T1555
- T1560.001
- T1570
- T1573.001
- T1584.003
- T1584.004
- T1584.005
- T1584.008
- T1587.004
- T1588.002
- T1588.006
- T1589
- T1589.002
- T1590
- T1590.004
- T1590.006
- T1591
- T1591.004
- T1592
- T1593
- T1594
- T1596.005
- T1614
- T1654
- T1680
- T1685.005
CVEs named in reports
- CVE-2008-5353
- CVE-2009-0556 KEV
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2009-3867
- CVE-2009-4324 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2011-0611 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2013-3900 KEV
Show all 89 CVEs Show fewer
- CVE-2015-1548
- CVE-2017-11882 KEV ransomware
- CVE-2017-17663
- CVE-2017-3506 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-13379 KEV ransomware
- CVE-2019-0604 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-11539 KEV ransomware
- CVE-2019-1653 KEV
- CVE-2020-12641 KEV
- CVE-2020-22653
- CVE-2020-22658
- CVE-2020-35730 KEV
- CVE-2020-8218 KEV
- CVE-2021-20021 KEV ransomware
- CVE-2021-20022 KEV ransomware
- CVE-2021-20023 KEV ransomware
- CVE-2021-21974
- CVE-2021-22893 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-27860 KEV
- CVE-2021-40539 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2022-1040 KEV
- CVE-2022-27518 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-27997
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-37042 KEV ransomware
- CVE-2022-40684 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-41328 KEV
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-49475
- CVE-2023-20867 KEV
- CVE-2023-23397 KEV
- CVE-2023-25717 KEV
- CVE-2023-26360 KEV
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-28771 KEV
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46747 KEV ransomware
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2023-7101 KEV
- CVE-2023-7102
- CVE-2024-1709 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-39717 KEV
- CVE-2025-21590 KEV
- CVE-2025-2492
- CVE-2025-31324 KEV ransomware
- CVE-2025-4427 KEV
- CVE-2025-4428 KEV
- CVE-2026-22813
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
Show all 69 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Meterpreter (Malware Family)
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor LaZagne (Malware Family)
-
Volt Typhoon - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Volt Typhoon - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor MimiKatz (Malware Family)
-
Dragos_Littleton_Electric_Water_CaseStudy.pdf
The original link failed its last check. Original publisher Detailsfor Dragos_Littleton_Electric_Water_CaseStudy.pdf
-
Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Volt Typhoon targets US critical infrastructure with living-off-the-land techniques _ Microsoft Security Blog
-
Volt Typhoon targets US critical infrastructure with living-off-the-land techniques
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Volt Typhoon targets US critical infrastructure with living-off-the-land techniques
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor AA23-144a- People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection
Newest first. Details opens the report in Explore.