THREAT-WATCH logo

THREAT‑WATCH

Threat Actors

Volt Typhoon

Bronze Silhouette, Vanguard Panda

ActiveState-sponsored (China)

A Chinese state-sponsored group focused on pre-positioning long-term access inside critical infrastructure, rather than immediate theft or disruption.

Volt Typhoon is unusual among state-sponsored actors for rarely using malware, instead relying on 'living off the land' techniques, using legitimate built-in system tools rather than custom code, which makes its activity harder to distinguish from normal administrator behavior. US and allied intelligence agencies assess the group is establishing footholds in critical infrastructure to enable potential disruptive or destructive effects during a future geopolitical crisis, rather than for immediate financial or espionage gain. CISA issued a supplementary advisory in February 2026 noting intensified activity in the water and communications sectors since mid-2025.

Target Sectors

Energy, water and wastewater, communications, and transportation critical infrastructure.

24/7 SOC Monitoring & MDR