Volt Typhoon

  • It is a state-sponsored hacking entity originating from China, operating since at least 2021.
  • The group primarily engages in espionage and gathering sensitive information.
  • Volt Typhoon emphasizes stealth in its operations, relying heavily on living-off-the-land techniques and direct involvement in cyber activities.
  • The group often utilizes preinstalled utilities for most of its interactions with victims.
  • They employ compromised small office/home office (SOHO) devices as proxies for communication with affected networks.
  • Attack commands are issued via command-line interfaces, involving data collection, archiving for exfiltration, and maintaining persistence using stolen credentials.
  • Volt Typhoon operates covertly, routing traffic through compromised network equipment ....
