Threat actor
Volt Typhoon
Also known as Vanguard PandaSource [1], BRONZE SILHOUETTESource [1], Dev-0391Source [1], UNC3236Source [1], VoltziteSource [1], Insidious TaurusSource [1]
CISA, NSA and the FBI describe Volt Typhoon as a PRC state-sponsored cyber group and assess with high confidence that its actors are pre-positioning on IT networks to enable the disruption of OT functions across critical infrastructure sectors.Source [1]
What authorities and investigators report
- The agencies say Volt Typhoon compromised the IT environments of multiple critical infrastructure organizations, primarily in the Communications, Energy, Transportation Systems, and Water and Wastewater Systems sectors, in the continental and non-continental United States and its territories.Source [1]
- The advisory says the group relies on valid accounts and living-off-the-land techniques, and that the agencies observed indications of Volt Typhoon actors keeping access in some victim IT environments for at least five years.Source [1]
- It says Volt Typhoon aims to obtain administrator credentials, often by exploiting privilege escalation vulnerabilities, and in some cases obtained credentials insecurely stored on a public-facing network appliance.Source [1]
- It says Volt Typhoon achieved full domain compromise by extracting the Active Directory database (NTDS.dit) from the domain controller, and likely used offline password cracking on the hashes it contains.Source [1]
Techniques
Attack vectors
Sources
Last reviewed Oct 2, 2026