Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1017
MITRE ATT&CK Group

Volt Typhoon (G1017)

BRONZE SILHOUETTEVanguard PandaDEV-0391UNC3236VoltziteInsidious TaurusDazedToad
ShareXLinkedInRedditHN

[Volt Typhoon](https://attack.mitre.org/groups/G1017) is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. [Volt Typhoon](https://attack.mitre.org/groups/G1017)'s targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. [Volt Typhoon](https://attack.mitre.org/groups/G1017) has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.(Citation: CISA AA24-038A PRC Critical Infrastructure February 2024)(Citation: Microsoft Volt Typhoon May 2023)(Citation: Joint Cybersecurity Advisory Volt Typhoon June 2023)(Citation: Secureworks BRONZE SILHOUETTE May 2023). The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.(Citation: DOJ KVBotnet 2024). Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to [Volt Typhoon](https://attack.mitre.org/groups/G1017), also tracked as VOLTZITE, for follow-on operations. (Citation: Dragos 2025 Year in Review)

▪Techniques used (81)

T1046Network Service DiscoveryT1083File and Directory DiscoveryT1591.004Identify RolesT1057Process DiscoveryT1021.001Remote Desktop ProtocolT1584.004ServerT1090ProxyT1518Software DiscoveryT1078Valid AccountsT1584.008Network DevicesT1056.001KeyloggingT1036.005Match Legitimate Resource Name or LocationT1036.008Masquerade File TypeT1059.003Windows Command ShellT1190Exploit Public-Facing ApplicationT1555Credentials from Password StoresT1074Data StagedT1590Gather Victim Network InformationT1560.001Archive via UtilityT1124System Time DiscoveryT1069.002Domain GroupsT1016System Network Configuration DiscoveryT1018Remote System DiscoveryT1047Windows Management InstrumentationT1133External Remote ServicesT1140Deobfuscate/Decode Files or InformationT1570Lateral Tool TransferT1593Search Open Websites/DomainsT1680Local Storage DiscoveryT1589.002Email AddressesT1497.001System ChecksT1003.003NTDST1027.002Software PackingT1573.001Symmetric CryptographyT1003.001LSASS MemoryT1685.005Clear Windows Event LogsT1584.005BotnetT1592Gather Victim Host InformationT1049System Network Connections DiscoveryT1087.001Local AccountT1217Browser Information DiscoveryT1059.001PowerShellT1654Log EnumerationT1068Exploitation for Privilege EscalationT1113Screen CaptureT1090.001Internal ProxyT1587.004ExploitsT1090.003Multi-hop ProxyT1594Search Victim-Owned WebsitesT1033System Owner/User DiscoveryT1112Modify RegistryT1505.003Web ShellT1218System Binary Proxy ExecutionT1059.004Unix ShellT1007System Service DiscoveryT1069Permission Groups DiscoveryT1584.003Virtual Private ServerT1555.003Credentials from Web BrowsersT1591Gather Victim Org InformationT1590.004Network TopologyT1010Application Window DiscoveryT1069.001Local GroupsT1120Peripheral Device DiscoveryT1070.004File DeletionT1588.006VulnerabilitiesT1105Ingress Tool TransferT1552Unsecured CredentialsT1078.002Domain AccountsT1005Data from Local SystemT1006Direct Volume AccessT1012Query RegistryT1589Gather Victim Identity InformationT1588.002ToolT1596.005Scan DatabasesT1087.002Domain AccountT1614System Location DiscoveryT1070.007Clear Network Connection History and ConfigurationsT1016.001Internet Connection DiscoveryT1552.004Private KeysT1074.001Local Data StagingT1590.006Network Security Appliances

▪Software used (17)

S0108netshtoolS0029PsExectoolS0100ipconfigtoolS0645WevtutiltoolS1154VersaMemmalwareS0057TasklisttoolS0002MimikatztoolS0097PingtoolS0357ImpackettoolS0096SysteminfotoolS0104netstattoolS0359NltesttoolS0160certutiltoolS0075RegtoolS1144FRPtoolS0106cmdtoolS0039Nettool
G1017on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.