TL;DR: Volt Typhoon is a People's Republic of China state-sponsored advanced persistent threat (APT) that has been burrowing into US critical infrastructure since at least mid-2021 [1][6]. The joint advisory AA24-038A from CISA, NSA, FBI, DOE, EPA, TSA, and the Five Eyes cyber agencies, released February 7, 2024, says Volt Typhoon has maintained access in some victim environments for at least five years, primarily inside the communications, energy, transportation, and water/wastewater sectors, including US territories such as Guam [1]. The confirmed victim list as of this tracker: US critical-infrastructure organizations in those four sectors (named collectively in the advisory), Singtel in Singapore (June 2024), and systems on Guam tied to US military communications [2][6]. The FBI's court-authorized takedown in early 2024 wiped the "KV Botnet" malware from hundreds of compromised Cisco and NetGear small-office/home-office routers that Volt Typhoon used to hide its traffic [3][4]. The playbook is living-off-the-land: Volt Typhoon rarely drops malware after initial access, leans on built-in Windows tools like ntdsutil, wmic, netsh, and PowerShell, and exploits internet-facing appliances from Fortinet, Ivanti, NETGEAR, Citrix, and Cisco by name [1][5]. This tracker is the running list of confirmed victims, named CVEs, the specific TTPs, and what defenders are told to do. Updated as cases develop.
What Volt Typhoon Actually Is
Volt Typhoon is a People's Republic of China state-sponsored advanced persistent threat, not a single hacker. CISA, NSA, FBI, and partner agencies attribute the activity to PRC state-sponsored cyber actors using the Volt Typhoon label [1]. The group tracks under several names across the security industry: Vanguard Panda, BRONZE SILHOUETTE, Redfly, Insidious Taurus, Dev-0391, Storm-0391, UNC3236, Voltzite [1][6]. Microsoft tags it Dev-0391 or Storm-0391; Secureworks (now owned by Dell) calls it BRONZE SILHOUETTE; Palo Alto Networks' Unit 42 uses Insidious Taurus; Mandiant (Google) calls it UNC3236; CrowdStrike uses Vanguard Panda; Dragos uses Voltzite [6]. The first public identification came in May 2023, when Microsoft and the Five Eyes published joint guidance on Volt Typhoon's tactics, techniques, and procedures [6].
Two things distinguish Volt Typhoon from the more familiar Chinese corporate-espionage crews. First, the goal is not bulk data theft. CISA, NSA, and FBI assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to operational technology (OT) assets to disrupt functions [1]. AA24-038A frames the activity as "preparing to launch disruptive or destructive cyberattacks against US critical infrastructure" during a future geopolitical crisis, not stealing intellectual property [1]. Second, Volt Typhoon hides its traffic inside compromised SOHO routers. The KV Botnet that powered the operation ran on Cisco and NetGear small-office/home-office routers that were no longer supported through the manufacturer's security patches or other software updates [3][4]. Wiping that botnet, in February 2024, was the most concrete disruption action the US government has taken against the group.
Confirmed Victims (So Far)
The victim list is short by design. Volt Typhoon's tradecraft is built to avoid detection, and many victims never name the group publicly. The entries below are confirmed by a government advisory, a court filing, or a victim disclosure.
US Critical Infrastructure (Communications, Energy, Transportation, Water)
The most authoritative single statement of victim scope comes from the joint advisory AA24-038A: Volt Typhoon has compromised and maintains persistent access to networks in the US Communications, Energy, Transportation Systems, and Water and Wastewater Systems sectors [1]. The advisory covers "the continental and non-continental United States and its territories, including Guam" and notes that "some victims are smaller organizations with limited cybersecurity capabilities that provide critical services to larger organizations or key geographic locations" [1]. AA24-038A does not name specific US companies by name; it names sectors. Some of the named organizations are protected as critical infrastructure under CISA's own designation rules and are not publicly identified.
Systems on Guam
Public reporting places Volt Typhoon activity inside systems on Guam, the US territory that hosts major communications infrastructure [6]. The reporting frames Guam as the staging ground for activity designed to enable sabotage of critical communications infrastructure between the US and Asia during potential future crises [6]. AA24-038A explicitly extends its geographic scope to Guam [1]. Specific network owners on Guam have not been named publicly.
Singtel, Singapore (June 2024)
Singtel, Singapore's largest telecommunications carrier, detected malware in June 2024 and dealt with it, a spokesperson told The Register [2]. Bloomberg, citing two people familiar with the matter, reported the intrusion was discovered in June 2024 and described it as "a test run by China for further hacks against US telecommunications companies" [2]. Singtel's spokesperson told The Register the operator "can't confirm that it's linked to Volt Typhoon" and said "no data was stolen in the attack, and no services were impacted" [2]. The Register reports, citing Bloomberg, that Volt Typhoon used a web shell in the Singtel breach, consistent with Lumen Technologies Black Lotus Labs' research on the VersaMem web shell linked to Volt Typhoon's exploitation of Versa SD-WAN vulnerability CVE-2024-39717 [2]. Singtel told the Singapore Coordinating Minister for National Security in subsequent reporting that the malware had been eradicated [6]. Public attribution was first reported by Bloomberg in November 2024 [6].
Australian Critical Infrastructure (Probing, 2024-2025)
Mike Burgess of the Australian Security Intelligence Organisation (ASIO) warned publicly in 2025 that Volt Typhoon, alongside Salt Typhoon, was targeting Australian telecommunications and critical infrastructure [6]. Specific Australian victim organizations are not named in the public statements.
The Playbook: How Volt Typhoon Gets In And Stays In
The joint advisory AA24-038A lists the techniques in detail [1]. The core entry vectors and tradecraft:
- Exploiting internet-facing appliances. Volt Typhoon affiliates target known-exploited CVEs against edge devices. AA24-038A names CVE-2022-42475 (a Fortinet FortiGate 300D firewall buffer overflow in SSL-VPN) and lists exploitation of Fortinet, Ivanti Connect Secure (formerly Pulse Secure), NETGEAR, Citrix, and Cisco as the recurring pattern [1]. CISA and partners separately tied Volt Typhoon to exploitation of the Versa SD-WAN vulnerability CVE-2024-39717 via a custom credential-harvesting web shell dubbed VersaMem [2]. The recurring theme: appliances that sit on the perimeter, often end-of-life, often unpatched.
- Living off the land. Once inside, Volt Typhoon rarely drops malware. AA24-038A documents use of cmd, certutil, dnscmd, ldifde, makecab, net user/group/use, netsh, nltest, netstat, ntdsutil, ping, PowerShell, quser, reg query/reg save, systeminfo, tasklist, wevtutil, whoami, wmic, xcopy [1]. Secureworks' research on BRONZE SILHOUETTE (the same actor) noted an interest in operational security that "likely stemmed from embarrassment over the drumbeat of US indictments" [6]. Public researchers including Secureworks' Ryan Sherstobitoff have said of the group: "Unlike attackers who vanish when discovered, this adversary digs in even deeper when exposed" [6].
- Credential dumping from the domain controller. AA24-038A documents Volt Typhoon using Mimikatz, Impacket, Magnet RAM Capture (MRC) version 1.20, and the legitimate comsvcs.dll sideloaded for LSASS dumping [1]. In one compromise, Volt Typhoon pulled the Active Directory database ntds.dit from three domain controllers over a four-year period [1]. In another, the group extracted ntds.dit twice in a nine-month period from the same victim [1]. Successful decryption of stolen password hashes "allows Volt Typhoon actors to obtain elevated access and further infiltrate and manipulate the network" [1].
- Hiding inside SOHO routers. Volt Typhoon has implanted KV Botnet malware on end-of-life Cisco and NETGEAR SOHO routers and used those routers as proxies for command-and-control traffic [1][3]. T1573 (encrypted channel) and T1090 (proxy) are the MITRE ATT&CK labels, with T1583.003/T1584.005 covering the acquisition and compromise of the botnet itself [1]. The February 2024 FBI court-authorized operation deleted KV Botnet from those routers and blocked communications with the botnet's controllers [3][4].
- Lateral movement to OT. Volt Typhoon uses Remote Desktop Protocol (T1021.001), Pass the Hash and Pass the Ticket (T1550), and remote service session hijacking (T1563) to move from IT to OT networks, with the explicit goal of disrupting functions during a future crisis [1]. AA24-038A names HVAC, energy, water, and camera surveillance as the OT assets Volt Typhoon has been seen targeting [1].
- Defense evasion. AA24-038A documents Volt Typhoon packing malware with UPX (T1027.002), clearing Windows event logs (T1070.001), clearing persistence indicators (T1070.009), and matching legitimate names or locations (T1036.005) [1]. Two Windows event log Event IDs are explicit detection calls. 1102 is "The audit log was cleared" and AA24-038A says "All Event ID `1102` entries should be investigated as logs are generally not cleared" [1]. 1017 is the Windows System Log "Handle scavenged" event, particularly on History.zip paths [1].
The single biggest lesson from AA24-038A is also the most boring one. Patching internet-facing appliances, retiring end-of-life SOHO routers off the perimeter, enforcing phishing-resistant MFA, and centralizing logging kill most of these initial access and persistence paths. AA24-038A's own list of "actions to take today" runs in that exact order: apply patches, implement phishing-resistant MFA, ensure logging is turned on, and plan end-of-life for technology beyond the manufacturer's supported lifecycle [1].
Who Runs Volt Typhoon
CISA, NSA, FBI, DOE, EPA, TSA, and the Five Eyes cyber agencies attribute Volt Typhoon to PRC state-sponsored cyber actors [1]. Public tracking attributes place the activity with the People's Liberation Army Cyberspace Force [6]. The PRC has called Volt Typhoon a "misinformation campaign by US intelligence agencies" and said it "firmly opposes and cracks down on all forms of cyberattacks" [6]. US officials interpreted remarks by a Chinese official during 2024 meetings as "indirect and somewhat ambiguous" but read as "a tacit admission and a warning to the US about Taiwan" [6]. The US government's stated assessment: Volt Typhoon is positioning to "slow down any potential US military mobilization" following a potential Chinese invasion of Taiwan, and to sabotage critical communications infrastructure between the US and Asia during potential future crises [6].
In early February 2024, FBI Director Christopher Wray announced the KV Botnet takedown with explicit framing of the threat: "China's hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict" [4]. Wray's full statement: "Volt Typhoon malware enabled China to hide as they targeted our communications, energy, transportation, and water sectors. Their pre-positioning constitutes a potential real-world threat to our physical safety that the FBI is not going to tolerate. We are going to continue to work with our partners to hit the PRC hard and early whenever we see them threaten Americans" [4]. John Riggi of the American Hospital Association called the takedown "proof positive that Chinese government cyber efforts are no longer solely focused on espionage and data theft" and added that the actors "clearly intend to be in a position to inflict physical harm to our critical infrastructure, impacting the safety of hospitals and all Americans" [4].
What You Can Do If Volt Typhoon Touches Your Network
If you are an IT or security lead at a US critical-infrastructure organization in communications, energy, transportation, or water, AA24-038A's incident-response steps are specific [1]:
- Sever enterprise network from internet. Pull the connection so the actor cannot keep harvesting credentials or staging tools.
- Reset all credentials, including krbtgt twice. The krbtgt account is the Kerberos ticket-granting service key; one reset invalidates tickets but leaves a one-ticket overlap, so AA24-038A's "reset twice" is to close that window [1].
- Audit network appliance and edge device configurations. Look for the file paths AA24-038A lists (C:\Users\Public\Documents\user.dat, C:\Users\Public\Documents\systeminfo.dat, C:\Windows\System32\rult3uil.log, C:\Windows\Temp\tmp\Active Directory, C:\Users\Public\pro) and for the IOC filenames (BrightmetricAgent.exe, SMSvcService.exe, ronf.exe, comsvcs.dll in non-standard folders, rdpservice.exe) [1].
- Report to authoring agency. In the US, [email protected] / 1-844-Say-CISA (1-844-729-2472). Water sector: [email protected]. Energy sector: [email protected]. NSA: [email protected] [1].
- Apply cloud identity best practices. AA24-038A links to CISA's SCuBA baselines for M365 and other cloud environments [1].
- Reconnect to internet, minimize remote access tools. Reconnect only when evidence shows the actor is out, and remove any remote-access RMM software that is not strictly necessary [1].
- Share IOCs with the authoring agency or your sector ISAC. AA24-038A ships a STIX IOC bundle (MAR-10448362.c1.v2.CLEAR_stix2.json, 51.99 KB) and a malware analysis report (MAR-10448362-1.v1) [1].
If you are a defender at any organization that runs SOHO routers on the perimeter, the immediate change is to replace end-of-life Cisco and NetGear SOHO devices on the network edge. AA24-038A's CVEs target appliances past end-of-support. KV Botnet ran on the same kind of hardware. A supported router with current firmware removes the most likely foothold.
The Honest Takeaway
Volt Typhoon is the clearest example of what state-sponsored pre-positioning looks like in 2026. The tradecraft is built to hide inside your own tools and your own perimeter. There is no obvious malware payload to detect, no noisy exfiltration to flag, and no obvious ransom note. The activity is the kind that only a sharp detection engineer with the right event-log queries will see, and the AA24-038A Event IDs (216, 325, 326, 327, 637 on ESENT; 1102 on Security; 1017 on System; 21, 22, 23, 24, 25 on Terminal Services Local Session Manager Operational) are the places to start [1]. CISA's SCuBAGear tool and Sandia National Labs' gait (a Zeek extension) are the named detection tools [1].
What does not change is the playbook. Internet-facing appliances that go unpatched. SOHO hardware past end-of-life on the perimeter. ESENT ntds.dit queries that nobody noticed. Two Windows 1102 events nobody investigated. These are the front door, every time. The fix is procedural, not technical, and it has been on the CISA list since the first edition of AA24-038A.
This tracker will be updated as new victims are confirmed, additional indictments or sanctions land, and the international cases move forward.
Sources
- CISA, NSA, FBI, DOE, EPA, TSA, ACSC, CCCS, NCSC-UK, NCSC-NZ, #StopRansomware / Volt Typhoon (AA24-038A, February 7, 2024)
- The Register, China's Volt Typhoon reportedly breached Singtel in 'test-run' for US telecom attacks (November 6, 2024)
- US Department of Justice, U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure (January 31, 2024)
- American Hospital Association, FBI and DOJ disrupt campaign targeting critical infrastructure through small/home office routers (February 5, 2024)
- Microsoft Threat Intelligence, Volt Typhoon targets US critical infrastructure with living-off-the-land techniques (May 24, 2024)
- Wikipedia, Volt Typhoon (accessed October 2026)
Published: October 3, 2026