Volt Typhoon

APT / EstatalG1017 ↗
Origen🇨🇳 China
Técnicas (MITRE ATT&CK)81
FuenteMITRE ATT&CK
0
También conocido como:BRONZE SILHOUETTEDEV-0391DazedToadDev-0391Insidious TaurusStorm-0391UNC3236VANGUARD PANDAVOLTZITEVanguard PandaVoltzite

Sobre el grupo

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.. Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations.

Cadena de ataque

Escenario plausible montado a partir de las técnicas reales del grupo, ordenadas por las fases de un ataque. Cada etapa muestra cómo suele actuar el grupo.

Severidad del arsenal77
Impacto: Alto
T1190T1047T1133T1068T1007T1021.001ENTRYAcceso inicialExploitPublic-Facing App…EXECEjecuciónWindows ManagementInstrumentationPERSPersistenciaExternal RemoteServicesPRIVEscalada de privilegiosExploitation forPrivilege Escalat…DISCDescubrimientoSystem ServiceDiscoveryLATMovimiento lateralRemote DesktopProtocolCOLLRecolecciónData from LocalSystem

Cadena ilustrativa derivada de las técnicas documentadas en MITRE ATT&CK — no representa un ataque específico ya ocurrido. La severidad resume el arsenal conocido (cobertura de la cadena, CVEs en explotación activa, técnicas).

Técnicas (MITRE ATT&CK) 81

Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.

Vulnerabilidades explotadas 2

CVEs que este grupo es conocido por explotar, según MITRE ATT&CK. Ordenadas por gravedad real.

El grupo Volt Typhoon usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.

Conocer el Pentest Autónomo con IA →