logo

Volt_Typhoon__2024__Volt_Typhoon_targets_US_critical_infrastructure_with_living-off-the-land_techniques_Microsoft_Security_Blog.pdf

ID: 0dd0027d-cd15-4c6d-a803-4b7bc2ac0515

STIX ID: report--0dd0027d-cd15-4c6d-a803-4b7bc2ac0515

Threat Score

75/100

Uploaded: 2026-08-21

Published Date: 2024-02-02

Last Modified Date: 2024-02-02

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft Threat Intelligence describes Volt Typhoon, a state-sponsored actor targeting critical infrastructure in the United States since 2021. The group relies on living-off-the-land techniques and compromised edge devices to achieve credential access, discovery, persistence, and data staging, often routing traffic through SOHO devices and using proxies to conceal activity, with recommended mitigations and detections.