Skip to main content
OT Atlas

Threats · Activity group

VOLTZITE

activeOT-focused accessDragosAttribution · High
Last verified

Executive summary

VOLTZITE is the Dragos activity group tracking intrusions into US critical infrastructure that overlap heavily with the activity governments and vendors report as Volt Typhoon. The defining characteristic is patience: long-dwell access obtained through internet-facing edge devices, maintained almost entirely with living-off-the-land techniques, and used to collect information about operational technology rather than to cause an immediate effect.

Joint advisories from CISA, the NSA, the FBI and allied agencies describe pre-positioning in communications, energy, transportation and water systems, with the assessed intent of enabling disruption at a time of the actor's choosing. For OT defenders the practical signal is not malware — it is valid accounts, edge-device compromise, and unusual interest in network diagrams, engineering data and OT-supporting systems.

At a glance

Tracked byDragos
NexusReported by US and allied government agencies as state-sponsored and China-linked
First observed2021 (public reporting)
Last reported2024–2025 public advisories and vendor reporting
ICS kill chainStage 1 — Intrusion · Stage 1 — Collection of OT information

Rosetta Stone

Names across the industry

Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.

VOLTZITE
  • Volt Typhoon
    Technical overlapHigh

    Tracked by Microsoft — Microsoft's actor name for closely reported activity; Dragos describes VOLTZITE as overlapping with Volt Typhoon rather than as an identical set.

  • BRONZE SILHOUETTE
    Associated activityModerate

    Tracked by Secureworks

  • Vanguard Panda
    Associated activityModerate

    Tracked by CrowdStrike

  • DEV-0391
    AliasHigh

    Tracked by Microsoft — Pre-taxonomy Microsoft designation later renamed Volt Typhoon.

  • UNC3236
    Associated activityModerate

    Tracked by Google Threat Intelligence / Mandiant

  • Insidious Taurus
    Associated activityModerate

    Tracked by Palo Alto Unit 42

  • DazedToad
    Reported linkLow

    Tracked by Vendor reporting

Relevance

Why OT defenders care

Objectives

  • Long-term, low-noise access to critical infrastructure networks
  • Collection of OT-relevant data: network diagrams, asset inventories, engineering and SCADA documentation
  • Pre-positioning to enable future disruption rather than immediate effect

Reported impacts

  • No publicly confirmed process disruption attributed to this activity
  • Assessed pre-positioning for potential future disruptive effects

Observed behaviours

  • Exploitation of internet-facing routers, VPN concentrators and firewalls for initial access
  • Credential theft from network devices and domain infrastructure, then reuse of valid accounts
  • Proxying traffic through compromised SOHO and edge devices to blend with normal egress
  • Minimal custom malware; administration performed with built-in operating system tooling
  • Enumeration and exfiltration of OT documentation, GIS data and asset inventories

Targeting

Sectors, geography and assets

Target industries

Electric powerWater and wastewaterCommunicationsTransportation systemsOil and gas

Target geography

United StatesUS territories including GuamAllied nations reported by partner agencies

Observed assets

Remote access gatewayJump hostEngineering workstationHistorianDomain controller supporting OTNetwork edge appliance

Protocols in scope

SSHRDPSMBHTTPSVendor VPN protocols

Capability

Malware and tools

Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.

Malware

  • Web shells on edge appliancesReported on compromised internet-facing devices; families vary by campaign.

Commercial tool

Not publicly established

Open-source utility

  • Fast Reverse Proxy (frp)Reported for tunnelling and access maintenance.
  • Impacket

Native OS tool

  • netsh / wmic / ntdsutil / PowerShellCore of the living-off-the-land tradecraft.

ATT&CK

Technique mapping

History

Known campaigns and incidents

Reported campaigns

  • Reported pre-positioning campaigns against US critical infrastructure (2023–2024 advisories)

Atlas incident case studies

Not publicly established

Defence

Defensive hunting priorities

Start with the hunts below — each one is a complete procedure in the Field Playbook.

Priorities

  • Inventory and patch every internet-facing edge device that terminates access into or adjacent to OT
  • Baseline and alert on administrative protocol use crossing the IT/OT boundary
  • Monitor for valid-account use from new hosts, new geographies and outside maintenance windows
  • Treat OT documentation repositories as crown-jewel data with access logging

Hunt for this activity

Indicators

Indicator guidance

Indicators expire. Behaviour usually ages better.

This registry deliberately does not republish volatile IP and domain lists. Pull current indicators from the linked authoritative reporting, match them locally against your own telemetry, and invest your standing detections in the behaviours listed above.