Chinese state-sponsored espionage group targeting US critical infrastructure and defense organizations.
Analyst brief
Volt Typhoon is a Chinese state-sponsored espionage group, also tracked as BRONZE SILHOUETTE or VANGUARD PANDA. It primarily targets US government, defense, and critical infrastructure organizations. Their key TTPs include exploiting public-facing applications for initial access, using Mimikatz and Impacket for credential theft, and leveraging tools like PsExec and RDP for lateral movement. Defenders should focus on securing public-facing services, detecting lateral movement attempts, and monitoring for Chinese-linked C2 proxies.
Volt Typhoon
BRONZE SILHOUETTEVANGUARD PANDAUNC3236
unknown
[Microsoft] Volt Typhoon, a state-sponsored actor based in China that typically focuses on espionage and information gathering. Microsoft assesses with moderate confidence that this Volt Typhoon campaign is pursuing development of capabilities that could disrupt critical communications infrastructure between the United States and Asia region during future crises.
[Secureworks] BRONZE SILHOUETTE likely operates on behalf the PRC. The targeting of U.S. government and defense organizations for intelligence gain aligns with PRC requirements, and the tradecraft observed in these engagements overlap with other state-sponsored Chinese threat groups.