Threats · Activity group
SYLVANITE
Executive summary
SYLVANITE is reported as an access-development cluster: it specialises in compromising internet-facing edge infrastructure, rapidly weaponising newly disclosed vulnerabilities, and establishing footholds that other operations then use. Public reporting describes handoff of that access to VOLTZITE follow-on activity.
Defensively, SYLVANITE is a reminder that the edge device is the front door of most OT-supporting networks, and that patch latency on VPNs and firewalls is measured against the actor's exploitation speed.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- VOLTZITEReported linkModerate
Tracked by Dragos — Reported access handoff relationship, not equivalence.
Relevance
Why OT defenders care
Objectives
- Rapid exploitation of edge-device vulnerabilities
- Credential theft
- Durable access for follow-on operations
Reported impacts
- Access provision enabling later intrusion activity
Observed behaviours
- Exploitation within days of vulnerability disclosure
- Web shell installation on appliances
- Credential extraction from device configuration
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- Web shells
Commercial tool
Not publicly established
Open-source utility
- Tunnelling utilities
Native OS tool
Not publicly established
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- Not publicly established as named campaigns
Atlas incident case studies
Not publicly established
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Emergency patch path for internet-facing appliances, decoupled from OT change windows
- Rotate device credentials and certificates after any appliance patch
- Log and baseline outbound connections originating from appliances themselves
Hunt for this activity
- Rare external destination from an OT-supporting hostA host that supports operations is communicating with an external destination it has never contacted before.
- New remote-access sourceRemote access into the environment originated from a source that has not been seen before.
- New vendor remote-access pathA vendor is connecting through a path or tool that is not part of the approved remote-access design.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)