s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

AI-SEARCH-volt-typhoon medium

📛 Threat Title

AI threat search: Volt Typhoon

Category: ai-threat-search First seen: Last updated:

Description

AI-discovered findings for topic: 'Volt Typhoon'. Run at 2026-08-07T02:06:17.418803Z. DuckDuckGo returned 10 result(s); the AI Forensic Validator classified 2 IOC(s) as valid.

Indicators of Compromise (4)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

hash_sha256 c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d

IOC database

Type
hash_sha256
Value
c0fc29a52ec3202f71f6378d9f7f9a8a3a10eb19acb8765152d758aded98c76d
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AI-search: Volt Typhoon

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc74

IOC database

Type
hash_sha256
Value
b4f7c5e3f14fb57be8b5f020377b993618b6e3532a4e1eb1eae9976d4130cc74
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AI-search: Volt Typhoon

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

hash_sha256 4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a310349

IOC database

Type
hash_sha256
Value
4b0c4170601d6e922cf23b1caf096bba2fade3dfcf92f0ab895a5f0b9a310349
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AI-search: Volt Typhoon

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

domain iiss.org UrlVoid 0 / 35

IOC database

Type
domain
Value
iiss.org
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
AI-search: Volt Typhoon

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (15)

  • Volt Typhoon: U.S. Critical Infrastructure Targeted by State ... - Tenable

    For more information, read the blog Volt Typhoon : What State and Local Government Officials Should Know. Source: Microsoft Threat Intelligence Initial access Volt Typhoon typically gains initial access to targeted systems by exploiting vulnerabilities in publicly exposed systems, specifically firewalls, VPN appliances and web servers.

  • threat-intelligence-reports/reports/2026-06-volt-typhoon-lotl-critical ...

    Executive Summary I assess Volt Typhoon as a strategic critical infrastructure threat where behavioral detection matters more than atomic indicators. The actor's public profile emphasizes valid accounts, living-off-the-land tools, long dwell time, and proxying through compromised network devices.

  • Volt Typhoon: Threat Actor Intelligence Report - GitHub

    This report profiles Volt Typhoon , a state sponsored threat actor of the People's Republic of China that has been active since 2021, based on open source intelligence from CISA advisories, MITRE ATT&CK, Microsoft Threat Intelligence , and FBI and NSA joint publications.

  • Volt Typhoon: Hunting the Ghost Already Living in Your Network

    Volt Typhoon , living off the land, KV botnet. If those three terms do not snap together into one coherent threat picture in your head, then your security operations center (SOC) probably has a detection gap, and something might be quietly exploiting it right now. This is the actor your security information and event management (SIEM) platform almost certainly misses, because Volt Typhoon does ...

  • Forecasting Typhoons: Volt Typhoon Next Steps - Dataminr

    With this in mind, threat intelligence analysts and critical infrastructure asset owners need to consider Volt Typhoon as a latent, potential threat as opposed to an immediate concern. While ransomware entities and similar manifest shortly after intrusion, and espionage actors siphon off data over long periods of time, Volt Typhoon appears dedicated to information gathering for a purpose ...

  • PDF Volt Typhoon - Threat Actor Profile | Intruvent

    Background VoltTyphoon is a PRC state-sponsored threat actor that has maintained persistent access to U.S. critical infrastructure networks for over five years. Unlike traditional espionage-focused APTs, Volt Typhoon's primary objective is pre-positioning within critical systems to enable potential disruption or destruction during a future geopolitical crisis—particularly a conflict over Taiwan.

  • PDF Volt Typhoon - Comprehensive Threat Hunting Guide | Intruvent

    Why This Hunt Matters Volt Typhoon represents a strategic threat unlike typical financially-motivated or espionage-focused adversaries. Their demonstrated ability to maintain long-term access to OT/ICS environments—including exfiltrating SCADA diagrams and relay documentation—positions them to cause physical damage to infrastructure during a potential conflict scenario. Organizations in ...

  • Volt Typhoon Explained: Living Off the Land Tactics for Cyber Espionage

    Volt Typhoon is a state-sponsored threat actor known for its cyber espionage targeting critical infrastructure, primarily in the US, highlighting global cybersecurity tensions.

  • Threat Brief: Attacks on Critical Infrastructure Attributed to ...

    Volt Typhoon targets US critical infrastructure with living-off-the-land techniques - Microsoft Threat Intelligence PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure - Cybersecurity and Infrastructure Security Agency (CISA)

  • PRC State-Sponsored Actors Compromise and Maintain Persistent ... - CISA

    Volt Typhoon's choice of targets and pattern of behavior is not consistent with traditional cyber espionage or intelligence gathering operations, and the U.S. authoring agencies assess with high confidence that Volt Typhoon actors are pre-positioning themselves on IT networks to enable lateral movement to OT assets to disrupt functions.

  • Volt Typhoon, BRONZE SILHOUETTE, Vanguard Panda, DEV-0391, UNC3236 ...

    Microsoft Threat Intelligence . (2023, May 24). Volt Typhoon targets US critical infrastructure with living-off-the-land techniques. Retrieved July 27, 2023. NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023. Counter Threat Unit Research Team. (2023 ...

  • Volt Typhoon: China's Critical Infrastructure Pre-Positioning Campaign

    Volt Typhoon is one of the most important cyber campaigns in the modern threat landscape because U.S. agencies do not describe it as routine espionage. They describe it as pre-positioning inside critical infrastructure. In a joint February 2024 advisory, CISA, the FBI, and the NSA said PRC state-sponsored actors linked to Volt Typhoon had compromised U.S. critical-infrastructure networks and ...

  • Volt Typhoon - Wikipedia

    Volt Typhoon (also known as VANGUARD PANDA, BRONZE SILHOUETTE, Redfly, Insidious Taurus, Dev-0391, Storm-0391, UNC3236, or VOLTZITE) is an advanced persistent threat (APT) engaged in cyberespionage on behalf of the People's Republic of China.

  • Volt Typhoon's long shadow - iiss.org

    A reportedly China-linked threat actor, Volt Typhoon , first came to light in 2023 for infiltrating critical infrastructure networks in the United States. Though purportedly neutralised, the threat actor continues to pose serious risks to Western cyber security.

  • Volt Typhoon targets US critical infrastructure with living-off-the ...

    Volt Typhoon rarely uses malware in their post-compromise activity. Instead, they rely on living-off-the-land commands to find information on the system, discover additional devices on the network, and exfiltrate data.

Remediations (10)

  • web:attack.mitre.org

    Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon 's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential ...

  • web:dailysecurityreview.com

    The Volt Typhoon intrusion highlights the urgent need for strengthened monitoring and defense strategies within CNI organizations. Sustained investment in security expertise, technology, and risk mitigation is essential to protect the electric grid and other vital infrastructure from increasingly sophisticated threats .

  • web:github.com

    This report profiles Volt Typhoon , a state sponsored threat actor of the People's Republic of China that has been active since 2021, based on open source intelligence from CISA advisories, MITRE ATT&CK, Microsoft Threat Intelligence, and FBI and NSA joint publications.

  • web:intruvent.com

    Background VoltTyphoon is a PRC state-sponsored threat actor that has maintained persistent access to U.S. critical infrastructure networks for over five years. Unlike traditional espionage-focused APTs, Volt Typhoon's primary objective is pre-positioning within critical systems to enable potential disruption or destruction during a future geopolitical crisis—particularly a conflict over Taiwan.

  • web:intruvent.com

    Why This Hunt Matters Volt Typhoon represents a strategic threat unlike typical financially-motivated or espionage-focused adversaries. Their demonstrated ability to maintain long-term access to OT/ICS environments—including exfiltrating SCADA diagrams and relay documentation—positions them to cause physical damage to infrastructure during a potential conflict scenario. Organizations in ...

  • web:media.defense.gov

    These mitigations are primarily intended for IT and OT administrators in critical infrastructure organizations. Following the mitigations for prevention of or in response to an incident will help disrupt Volt Typhoon's accesses and reduce the threat to critical infrastructure entities.

  • web:www.cisa.gov

    These mitigations are primarily intended for IT and OT administrators in critical infrastructure organizations. Following the mitigations for prevention of or in response to an incident will help disrupt Volt Typhoon's accesses and reduce the threat to critical infrastructure entities.

  • web:www.fbi.gov

    Following the mitigations for prevention of or in response to an incident will help disrupt Volt Typhoon's accesses and reduce the threat to critical infrastructure entities.

  • web:www.linkedin.com

    The assessment indicates that Volt Typhoon is a sophisticated, state-sponsored adversary with established, documented capabilities and intent to exploit vulnerable operational technology (OT ...

  • web:www.vectra.ai

    Understand Volt Typhoon's attack method, the TTPs (Techniques Tacticts and Procedures) they use and learn how to detect Nation-State Actors with AI .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.