MITRE ATT&CK G1017
Aliases: BRONZE SILHOUETTE, Vanguard Panda, Insidious Taurus
Official Attribution Source: CISA, FBI, NSA Joint Cybersecurity Advisory

Key Facts

Jurisdiction
People's Republic of China
Geographic origin
Cases
1
Prosecution matters
Defendants
0
Indicted individuals
Sanctions
0
OFAC designations
  • Attributed Country: People's Republic of China.
  • ATT&CK Group Reference: G1017 (Volt Typhoon).
  • Linked to 1 primary court prosecution records.
  • Identified 0 individually charged operatives.

Primary ATT&CK Techniques Employed

ATT&CK Techniques Mapped to Volt Typhoon Technique frequencies extracted from verified indictments for Volt Typhoon. T1078 Valid Accounts 1 incidents T1190 Exploit Public-Facing Application 1 incidents T1584 Compromise Infrastructure 1 incidents T1059.003 Windows Command Shell 1 incidents T1016 System Network Configuration Discovery 1 incidents T1018 Remote System Discovery 1 incidents T1033 System Owner/User Discovery 1 incidents T1057 Process Discovery 1 incidents
Technique frequencies extracted from verified indictments for Volt Typhoon.
ATT&CK Techniques Mapped to Volt Typhoon
Technique Frequency
T1078 Valid Accounts 1 incidents
T1190 Exploit Public-Facing Application 1 incidents
T1584 Compromise Infrastructure 1 incidents
T1059.003 Windows Command Shell 1 incidents
T1016 System Network Configuration Discovery 1 incidents
T1018 Remote System Discovery 1 incidents
T1033 System Owner/User Discovery 1 incidents
T1057 Process Discovery 1 incidents

Prosecution Cases Attributed to This Actor

alleged 2023-05-24

Volt Typhoon Critical Infrastructure Pre-Positioning

State-sponsored cyber group sponsored by the People's Republic of China breached dozens of U.S. critical infrastructure operators in communications, energy, transportation, and water systems to establish disruptive persistent access.

9 techniques View case →
OPERATIONAL DEFENSE

Targeted Defensive Hardening for Volt Typhoon

Run Stack Audit →

Primary Initial Access Defense

Enforce hardware FIDO2 multi-factor authentication across all perimeter VPN, Citrix, and cloud data portals. Prohibit SMS or push-based MFA that can be bypassed via vishing or SIM swapping.

Lateral Movement Interception

Restrict internal SMB (port 445) and RPC traversal between workstation subnets. Implement tiered Active Directory administration so domain administrator credentials are never cached on endpoints.