Volt_Typhoon__2024__Volt_Typhoon_targets_US_critical_infrastructure_with_living-off-the-land_techniques_Microsoft_Security_Blog.pdf
ID: 0dd0027d-cd15-4c6d-a803-4b7bc2ac0515
STIX ID: report--0dd0027d-cd15-4c6d-a803-4b7bc2ac0515
Threat Score
75/100
Uploaded: 2026-08-21
Published Date: 2024-02-02
Last Modified Date: 2024-02-02
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Microsoft Threat Intelligence describes Volt Typhoon, a state-sponsored actor targeting critical infrastructure in the United States since 2021. The group relies on living-off-the-land techniques and compromised edge devices to achieve credential access, discovery, persistence, and data staging, often routing traffic through SOHO devices and using proxies to conceal activity, with recommended mitigations and detections.
