Threats · Activity group
VOLTZITE
Executive summary
VOLTZITE is the Dragos activity group tracking intrusions into US critical infrastructure that overlap heavily with the activity governments and vendors report as Volt Typhoon. The defining characteristic is patience: long-dwell access obtained through internet-facing edge devices, maintained almost entirely with living-off-the-land techniques, and used to collect information about operational technology rather than to cause an immediate effect.
Joint advisories from CISA, the NSA, the FBI and allied agencies describe pre-positioning in communications, energy, transportation and water systems, with the assessed intent of enabling disruption at a time of the actor's choosing. For OT defenders the practical signal is not malware — it is valid accounts, edge-device compromise, and unusual interest in network diagrams, engineering data and OT-supporting systems.
At a glance
Rosetta Stone
Names across the industry
Every edge states the kind of relationship the public source supports — an alias is not the same as an overlap.
- Volt TyphoonTechnical overlapHigh
Tracked by Microsoft — Microsoft's actor name for closely reported activity; Dragos describes VOLTZITE as overlapping with Volt Typhoon rather than as an identical set.
- BRONZE SILHOUETTEAssociated activityModerate
Tracked by Secureworks
- Vanguard PandaAssociated activityModerate
Tracked by CrowdStrike
- DEV-0391AliasHigh
Tracked by Microsoft — Pre-taxonomy Microsoft designation later renamed Volt Typhoon.
- UNC3236Associated activityModerate
Tracked by Google Threat Intelligence / Mandiant
- Insidious TaurusAssociated activityModerate
Tracked by Palo Alto Unit 42
- DazedToadReported linkLow
Tracked by Vendor reporting
Relevance
Why OT defenders care
Objectives
- Long-term, low-noise access to critical infrastructure networks
- Collection of OT-relevant data: network diagrams, asset inventories, engineering and SCADA documentation
- Pre-positioning to enable future disruption rather than immediate effect
Reported impacts
- No publicly confirmed process disruption attributed to this activity
- Assessed pre-positioning for potential future disruptive effects
Observed behaviours
- Exploitation of internet-facing routers, VPN concentrators and firewalls for initial access
- Credential theft from network devices and domain infrastructure, then reuse of valid accounts
- Proxying traffic through compromised SOHO and edge devices to blend with normal egress
- Minimal custom malware; administration performed with built-in operating system tooling
- Enumeration and exfiltration of OT documentation, GIS data and asset inventories
Targeting
Sectors, geography and assets
Target industries
Target geography
Observed assets
Protocols in scope
Capability
Malware and tools
Malware, commercial tooling, open-source utilities and native operating-system tools are kept separate — they demand different detections.
Malware
- Web shells on edge appliancesReported on compromised internet-facing devices; families vary by campaign.
Commercial tool
Not publicly established
Open-source utility
- Fast Reverse Proxy (frp)Reported for tunnelling and access maintenance.
- Impacket
Native OS tool
- netsh / wmic / ntdsutil / PowerShellCore of the living-off-the-land tradecraft.
ATT&CK
Technique mapping
History
Known campaigns and incidents
Reported campaigns
- Reported pre-positioning campaigns against US critical infrastructure (2023–2024 advisories)
Atlas incident case studies
Not publicly established
Defence
Defensive hunting priorities
Start with the hunts below — each one is a complete procedure in the Field Playbook.
Priorities
- Inventory and patch every internet-facing edge device that terminates access into or adjacent to OT
- Baseline and alert on administrative protocol use crossing the IT/OT boundary
- Monitor for valid-account use from new hosts, new geographies and outside maintenance windows
- Treat OT documentation repositories as crown-jewel data with access logging
Hunt for this activity
- Rare external destination from an OT-supporting hostA host that supports operations is communicating with an external destination it has never contacted before.
- New IT-to-OT communication pathA corporate system has begun communicating with an OT asset over a path that is not in the approved conduit list.
- Unexpected engineering workstation peerAn engineering workstation is communicating with a system outside its normal peer set.
- Engineering workstation communicating externallyAn engineering workstation has direct or proxied internet egress.
- New remote-access sourceRemote access into the environment originated from a source that has not been seen before.
- Abnormal RDP usageRDP is being used along a path or at a time that does not match administrative practice.
- Abnormal SSH usageSSH sessions are reaching Linux-based OT infrastructure from unexpected sources or accounts.
- Living-off-the-land behaviourBuilt-in operating system tooling is being used for discovery, credential access or movement outside normal administration.
- Suspicious PowerShellPowerShell is executing encoded, downloaded or obfuscated content on an OT-supporting host.
- New scheduled taskA scheduled task was created on an OT-supporting host outside change control.
- Long-lived, low-volume connectionsA session has stayed open for an unusually long time while transferring very little data.
- Beacon-like periodic connectionsA host is contacting a destination at a regular interval consistent with automated check-in.
- Account used from a new hostA valid account authenticated from a host it has never used before.
- Account used outside the expected maintenance windowAn account with a strictly scheduled purpose was used outside its window.
- Historian communicating with an unknown internet hostA process historian is exchanging data with an external destination that is not an approved service.
- Firewall policy path unexpectedly exercisedA permissive firewall rule that normally sees no traffic has started being used.
Indicators
Indicator guidance
Indicators expire. Behaviour usually ages better.
Sources
- GovernmentCISA / NSA / FBI and international partnersPRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A) (opens in a new tab)
- GovernmentCISA / NSA / FBIIdentifying and Mitigating Living Off the Land Techniques (AA24-038B) (opens in a new tab)
- Vendor IntelligenceMicrosoft Threat IntelligenceVolt Typhoon targets US critical infrastructure with living-off-the-land techniques (opens in a new tab)
- ATT&CKMITRE ATT&CKVolt Typhoon (G1017) (opens in a new tab)
- Vendor IntelligenceDragosThreat groups — OT activity group profiles (opens in a new tab)