Volt Typhoon in 2026: The Threat Actor That Stopped Being News and Never Stopped Being Present

In February 2024, Volt Typhoon was the most-discussed threat actor in American cybersecurity. CISA, the NSA, and the FBI published a joint advisory stating that People's Republic of China state-sponsored actors were pre-positioning on IT networks to enable disruptive attacks against US critical infrastructure — and that in some victim environments, those actors had held access for at least five years. The FBI announced a court-authorized takedown of the botnet the group used to hide its traffic. Congressional testimony followed. The story was everywhere.

In March 2026, the Office of the Director of National Intelligence released its Annual Threat Assessment. It named China as a persistent cyber threat and warned that adversaries can "pre-position or execute disruptive and destructive attacks" against critical infrastructure. It did not name Volt Typhoon. Analysts at CSO Online and The National Interest both flagged the omission, noting that the 2025 assessment had explicitly tracked the named campaigns.

Meanwhile, in the same window, Dragos published its ninth annual OT/ICS Year in Review and reported that the group it tracks as VOLTZITE continued attacking US utilities through 2025. Dragos CEO Robert M. Lee told reporters the group remains active, is still mapping and embedding in US and allied infrastructure, and — the part that should stop you — that there are compromised sites in the US and in NATO countries that, in his assessment, will never be found.

That gap between narrative attention and operational reality is the story worth writing about in 2026. Volt Typhoon has not been defeated. It has been filed.


What is actually confirmed

A discipline worth applying to any state-actor story: separate what has been forensically confirmed from what has been asserted, inferred, or claimed. For Volt Typhoon, the confirmed set is smaller than the coverage suggests — and still bad enough.

Confirmed by incident response. The clearest public case study is Littleton Electric Light and Water Department (LELWD), a small municipal utility in Massachusetts serving Littleton and Boxborough. Dragos, which assisted the response, documented that the intrusion began in February 2023 and was not discovered until November 2023 — more than 300 days of access. The utility learned of it the way most small operators do: assistant general manager David Ketchen took a phone call from the FBI on a Friday afternoon. LELWD was already deploying OT monitoring sensors funded through Department of Energy grants administered by the American Public Power Association; that deployment was accelerated, and the sensors enabled responders to confirm and scope the activity. Dragos reported the adversary was collecting OT-relevant data rather than attempting disruption, and that no customer-sensitive data was assessed as compromised.

This is, to date, the most detailed publicly documented confirmation of the group's presence inside a US electric utility. It is also a single small utility — which is precisely why it matters. It had no security operations center. It had visibility only because a grant program happened to be paying for sensors.

Confirmed by vendor telemetry. In August 2024, Lumen's Black Lotus Labs reported zero-day exploitation of CVE-2024-39717 in Versa Director, the management platform ISPs and MSPs use to run SD-WAN and SASE services for downstream customers. The attackers deployed a custom in-memory Java web shell — dubbed VersaMem — that hooked the Apache Tomcat filter chain to harvest plaintext credentials as they passed through. Exploitation dated back to at least 12 June 2024 and affected approximately 5 organizations across the ISP, MSP, and IT sectors. CISA added the CVE to its Known Exploited Vulnerabilities catalog.

Note the attribution language carefully: Black Lotus Labs attributed this campaign to Volt Typhoon with moderate, not high, confidence . The technical findings are solid; the actor mapping is an assessment. Versa, for its part, stated it had confirmed a single instance of APT exploitation and that the affected customer had left a high-availability management port exposed contrary to hardening guidance the vendor published in 2015 and 2017.

Confirmed by the government incident response. AA24-038A is not a threat-intel roundup; it is derived from CISA, NSA, and FBI incident-response engagements with compromised critical-infrastructure organizations across the communications, energy, transportation, and water and wastewater sectors. It describes, among other things, a victim compromised via an unpatched FortiGate 300D through CVE-2022-42475, with evidence of a buffer overflow recovered from SSL-VPN crash logs.

Confirmed by law enforcement action. The KV-botnet — a network of compromised small office/home office devices used to proxy the group's traffic and obscure its origin — was disclosed by Black Lotus Labs in December 2023 and disrupted under a court order that same month, with the operation announced publicly on 31 January 2024. The FBI mimicked the operators' command-and-control to push a remote deletion. DOJ stated that the majority of affected devices were Cisco and NetGear routers, vulnerable specifically because they had reached end-of-life status and were no longer receiving patches.

The takedown worked. It also did not last. SecurityScorecard measured the operators recompromising roughly 30% of visible Cisco RV320/325 devices — 325 of 1,116 — over a 37-day window spanning the takedown period, and reported a renewed rebuild effort from September 2024 onward, largely across devices in Asia. Infrastructure disruption without addressing the installed base of unsupported hardware buys months, not years.


What is contested

The counter-narrative. China's National Computer Virus Emergency Response Center (CVERC) has published a series of reports — beginning in April 2024 and continuing through October 2024 — arguing that Volt Typhoon is a fabrication of US and Five Eyes intelligence agencies. One iteration claimed that the underlying activity was actually the Dark Power ransomware group, which was misattributed to the Chinese state. Both ThreatMon and Trellix publicly rejected the characterization of their research; ThreatMon stated the connection CVERC drew between Volt Typhoon and Dark Power is not supported by its findings.

We flag this not because the claim is credible on the evidence presented — it rests substantially on Snowden-era disclosures and asserts capability rather than demonstrating misattribution — but because it is a durable and increasingly standard feature of Chinese attribution response. Any organization writing or briefing on this actor should expect the counter-narrative to be raised and should be able to explain precisely why the Western attribution rests on incident-response data from named victims rather than on inference alone.

The naming problem. "Volt Typhoon" is a Microsoft label. Dragos tracks an industrial-focused cluster as VOLTZITE and describes it as overlapping with, not identical to, Volt Typhoon. Secureworks called it BRONZE SILHOUETTE; Mandiant, UNC3236; CrowdStrike, VANGUARD PANDA; Palo Alto, Insidious Taurus. MITRE ATT&CK consolidates these under G1017.

This matters operationally. When Dragos attributed 2025 exploitation of the Trimble Cityworks flaw (CVE-2025-0994) to activity in the Volt Typhoon orbit, Cisco Talos had separately documented that campaign under the designation UAT-6382, assessing with high confidence only that the operator was Chinese-speaking — based on Simplified Chinese tooling, AntSword and China Chopper web shells, and a Rust loader built with the MaLoader framework. Those are two different attribution frames at two different confidence levels describing overlapping activity. Treating them as one confirmed finding is how threat intelligence quietly becomes threat marketing.

Retrospective attributions. Several incidents now routinely listed in Volt Typhoon timelines — the August 2021 Port of Houston intrusion via a Zoho ManageEngine ADSelfService Plus zero-day, for instance — were attributed after the fact, some years later, on the basis of tooling and behavioral overlap. They are plausible. They are not the same class of evidence as a Dragos-led incident response with sensor data.


The operating model has not changed. The objective has.

Volt Typhoon's tradecraft is famously unremarkable, and that is the point.

The group rarely deploys malware. It gets in through internet-facing edge infrastructure — unpatched firewalls, VPN appliances, management platforms, end-of-life SOHO routers — steals valid credentials, and then operates hands-on-keyboard using tools already present: PowerShell, WMI, netsh, ntdsutil, command-line utilities, and legitimate remote access. Where it needs a capability the environment lacks, it has been observed downloading outdated but legitimate administrative binaries — an old copy of comsvcs.dll used with MiniDump against the LSASS process to pull credentials from memory, or Magnet RAM Capture run on domain controllers to harvest credentials and in-transit data that never touches disk.

This is living off the land, and it is effective for a simple reason: it produces almost no signal that a signature-based control will catch, and the signal it does produce looks like administration. Detection requires behavioral baselining — knowing what normal lateral movement and account usage look like in your environment — which is exactly the capability that most small utilities and municipalities lack.

What has changed is what the group does once it is inside. Dragos's 2026 Year in Review reports that through 2025, VOLTZITE moved beyond collecting and exfiltrating data from IT networks toward directly interacting with OT-connected devices and stealing sensor and operational data. More specifically, Dragos describes the group manipulating engineering workstations to dump configuration files and alarm data — thereby investigating, in effect, the conditions that cause a process to stop.

That is not espionage. That is targeting research.

The same report documents a second shift: specialization. Dragos introduced a new group, SYLVANITE, that functions as an initial access broker — rapidly weaponizing vulnerabilities in Ivanti, F5, SAP, and ConnectWise products and handing established footholds to VOLTZITE for deeper OT work. Dragos says it observed this handoff firsthand while running incident response for US electric and water utilities, where SYLVANITE exploited Ivanti flaws to extract Active Directory credentials. SYLVANITE shares technical overlaps with UNC5221, UNC5174, and UNC5291.

An ecosystem where one team specializes in door-kicking and another in patient OT reconnaissance compresses the time between a published CVE and an adversary standing in a control network. It also means the intrusion you detect on your VPN appliance and the intrusion that matters may be separated by weeks and by operator.


The part nobody wants in the executive summary

Dwell time in these cases exceeds log retention in most organizations.

LELWD: 300-plus days. CISA's advisory: at least five years in some environments. Standard SIEM retention at a mid-sized organization: 30 to 90 days of hot data. If an adversary has been resident longer than your telemetry has existed, "we found no evidence of compromise" is not a finding. It is an absence of the ability to have a finding — and it should be written up that way.

Lee's assessment in February 2026 was blunter still: some compromised sites will never be found, and for large parts of the water sector, the detection maturity required simply will not arrive on the current trajectory. His framing was that a portion of US infrastructure is currently compromised and will remain compromised.

That assessment sits uncomfortably beside the periodic official line that Volt Typhoon has been largely contained and eradicated. IISS analysts noted in January 2026 that, regardless of whether the presence has been fully withdrawn, the actor continues to provide strategic benefit to Beijing. Both things can be true: specific accesses were burned, and the overall position was not.


The AI-threat detour, briefly

There is a great deal of vendor content this year about AI-enabled adversaries. Volt Typhoon is a useful corrective.

The most strategically consequential intrusion campaign against US critical infrastructure of the past five years ran on: an unpatched 2022 firewall CVE, end-of-life consumer routers, an exposed management port that violated hardening guidance published in 2015, valid stolen credentials, and built-in Windows tooling. No novel malware family. No AI. The one custom implant of note, VersaMem, was a well-built Java web shell — sophisticated engineering, entirely conventional technique.

The controls that would have mattered are the ones that have been on every baseline for a decade: asset inventory, including end-of-life edge devices; patch and replacement discipline; credential hygiene and rotation; MFA; restriction of administrative tooling; network segmentation; and enough logging to reconstruct a year.


"We're not a utility"

Three reasons this is your problem anyway.

You may be the path. The Versa Director campaign targeted ISPs, MSPs, and IT firms specifically because their management platforms hold credentials for downstream customer networks. Compromising one Director instance is a route into many environments. If you provide managed services, your administrative plane is a strategic target, not a back office.

You may be the infrastructure. The KV-botnet was built from small businesses and home routers. Those organizations were not targets; they were relay. An end-of-life router in a dentist's office is, from the operator's perspective, a piece of American infrastructure that helps traffic to a Guam military network look domestic.

You may hold the map. The Cityworks campaign went after GIS and asset-management data held by municipalities. Dragos noted that US utilities and municipalities rely on GIS data for infrastructure operations, and that the same data lets an adversary plan precise disruptive attacks. Engineering diagrams, alarm configurations, asset registers, and process documentation are targeting material. If you hold them for a client, you hold a targeting package.


What to actually do

Vendor-neutral, and aligned to AA24-038A and to CISA's CI Fortify guidance published 28 July 2026 with the Australian Signals Directorate's ACSC (which led the document), NCSC-UK, the Canadian Center for Cyber Security, and the FBI.

1. Inventory internet-facing edge devices, and flag every one that is end-of-life or approaching it. This is the single highest-yield exercise for this threat model. Firewalls, VPN concentrators, SD-WAN, management appliances, routers, and IP cameras. Unsupported hardware cannot be patched; it must be replaced or removed from exposure. Verify that management interfaces — including high-availability and pairing ports — are not reachable from the internet.

2. Treat any edge-device compromise as a credential compromise. Assume everything that was authenticated through or stored on that device is in the adversary's hands. Rotate it. VersaMem existed for no other purpose than to catch credentials in transit.

3. Detect behavior, not signatures. Baseline normal administrative activity, then alert on deviation: unusual use of PowerShell, WMI, ntdsutil and netsh; LOLBin execution from non-standard paths; RAM-capture and process-dump tooling on domain controllers; lateral movement patterns that do not match your operational norm; valid employee accounts behaving unlike the employee. Dragos's own guidance to defenders is to compare unusual lateral movement against expected traffic and validate suspicious activity originating from ordinary accounts.

4. Extend log retention to match realistic dwell time. 90 days is not a threat-model-informed number for an adversary who stays for 5 years. Prioritize authentication logs, edge-device logs, and OT network telemetry. Where extending hot retention is unaffordable, cold-store the high-value sources.

5. Segment IT from OT, and prove it. Then go further, per CI Fortify: identify your vital systems — the minimum set required to keep delivering the service — map every interconnection to them (corporate IT, vendor remote access, cloud, third parties), and build a  pre-engineered, tested capability to isolate and run without them. The core argument of CI Fortify is that isolation improvised during an incident fails, because dependencies like Active Directory and DNS have been quietly woven into OT by decades of convergence.

6. Practice manual and local operation. Recovery while isolated is a distinct capability from recovery generally, and it is only real if it has been exercised.

7. Write your uncertainty down. If a hunt covers 90 days and the threat model is five years, say so in the report. Executive teams make bad decisions on the back of unqualified all-clears.


The takeaway

The reason Volt Typhoon fell out of the headlines is not that the problem was solved. It is that pre-positioning is a story without an event. There is no outage, no ransom note, no breach notification — the entire operational goal is that nothing happens until someone decides it should.

Coverage cycles reward events. Adversaries who have read the coverage cycle build strategies that do not generate them.

The defensive implication is unglamorous: this threat is addressed through asset inventory, patch and replacement discipline, credential hygiene, behavioral detection, segmentation, and tested isolation — sustained over years, in organizations that will never see a headline about themselves. LELWD is the model outcome, and it is worth being precise about why. It was not detected by a product alone. It was detected because a grant program funded visibility, a federal agency made a phone call, and a small utility acted on both.

Most organizations in this position will get at best one of those three.


Why Organizations Choose Zaxtron

Organizations face increasingly sophisticated ransomware campaigns that exploit unpatched systems, stolen credentials, exposed remote access, and third-party weaknesses. To stay protected, they need actionable intelligence, not just alerts, to identify and reduce cyber risks before disruption occurs. Zaxtron provides Cybersecurity Risk Management, AI Risk Management, and Cyber Threat Intelligence services that deliver continuous visibility and risk-based insights. By combining attack surface intelligence, vulnerability data, threat and breach intelligence, and third-party risk analysis, Zaxtron offers a complete view of cyber exposure. This helps security leaders respond to threats, improve vendor security, and make informed decisions. Contact Zaxtron to strengthen cyber resilience today.


Sources

  • CISA/NSA/FBI, PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure (AA24-038A), 7 February 2024
  • CISA/ASD's ACSC/NCSC-UK/CCCS/FBI, CI Fortify – Advice for Isolating Vital Systems, 28 July 2026; CISA CI Fortify initiative, May 2026
  • Dragos, 2026 OT/ICS Cybersecurity Report and Year in Review (9th annual), 17 February 2026
  • Dragos, LELWD/VOLTZITE case study, March 2025
  • The Record (Recorded Future News), reporting on Dragos' findings and Robert M. Lee's remarks, 19 February 2026
  • Lumen Black Lotus Labs, Taking the Crossroads: The Versa Director Zero-Day Exploitation, 27 August 2024
  • Lumen Black Lotus Labs, KV-botnet research, December 2023; US DOJ, KV-botnet disruption announcement, 31 January 2024
  • SecurityScorecard STRIKE Team, KV-botnet / "JDYFJ" measurement and rebuild reporting, 2024
  • Microsoft Threat Intelligence, Volt Typhoon targets US critical infrastructure with living-off-the-land techniques, 24 May 2023
  • Cisco Talos, UAT-6382 / Trimble Cityworks CVE-2025-0994 research, May 2025
  • MITRE ATT&CK G1017 (Volt Typhoon) and Campaign C0039 (Versa Director Zero Day Exploitation)
  • ODNI, 2026 Annual Threat Assessment of the U.S. Intelligence Community, March 2026
  • IISS, Volt Typhoon's Long Shadow, January 2026
  • The Record, reporting on CVERC claims and Trellix/ThreatMon responses, 2024
Share: