APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Volt Typhoon (aka VOLTZITE, Dev-0391) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
Volt Typhoon
G1017
APT
CN · China
AKA
VOLTZITE · Dev-0391 · INSIDIOUSTAUR
CrowdStrike
:
VANGUARD PANDA
Mandiant
:
UNC3236
MITRE
:
G1017
Secureworks
:
BRONZE SILHOUETTE
PRC cluster targeting US critical infrastructure with living-off-the-land techniques.
Targets
1
Sectors
12
Threat types
1
GIRs covered
0/480
Active since
2021
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 3 other aliases
Open Rosetta Stone
CrowdStrike
VANGUARD PANDA
Mandiant
UNC3236
Microsoft
Volt Typhoon
MITRE
G1017
Secureworks
BRONZE SILHOUETTE
UNATTRIBUTED ALIASES
VOLTZITE
Dev-0391
INSIDIOUSTAUR
Victimology
Geographic footprint · 1 countries
Region filter
Export
origin · China
targeted countries · 1
AMERICAS ·
1
United States
Sectors targeted
12 of 40
Government
100 actors
Defense
72 actors
Aviation
22 actors
Technology
60 actors
Telecom
72 actors
Energy / Utilities
59 actors
Oil and Gas
21 actors
Education & Research
62 actors
Manufacturing (man)
50 actors
Transportation
31 actors
Logistics
22 actors
Maritime
24 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 57 techniques
Reconnaissance
· 8
T1589.002
Email Addresses
T1590
Gather Victim Network Information
T1591
Gather Victim Org Information
T1591.004
Identify Roles
T1592
Gather Victim Host Information
T1593
Search Open Websites/Domains
T1594
Search Victim-Owned Websites
T1596.005
Scan Databases
Initial Access
· 1
T1190
Exploit Public-Facing Application
Execution
· 4
T1047
Windows Management Instrumentation
Privilege Escalation
· 1
T1068
Exploitation for Privilege Escalation
Credential Access
· 6
T1003.001
LSASS Memory
Discovery
· 18
T1007
System Service Discovery
T1010
Application Window Discovery
T1012
Query Registry
Lateral Movement
· 2
T1021.001
Remote Desktop Protocol
T1570
Lateral Tool Transfer
Collection
· 4
T1005
Data from Local System
T1074
Data Staged
T1113
Screen Capture
Command And Control
· 4
T1090
Proxy
T1090.001
Internal Proxy
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 8
T1027.002
Software Packing
T1036.005
Match Legitimate Resource Name or Location
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
57 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.004
Unix Shell
T1003.003
NTDS
T1552
Unsecured Credentials
T1552.004
Private Keys
T1555
Credentials from Password Stores
T1555.003
Credentials from Web Browsers
T1016
System Network Configuration Discovery
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1046
Network Service Discovery
T1049
System Network Connections Discovery
T1057
Process Discovery
T1069.001
Local Groups
T1083
File and Directory Discovery
T1120
Peripheral Device Discovery
T1124
System Time Discovery
T1217
Browser Information Discovery
T1518
Software Discovery
T1614
System Location Discovery
T1654
Log Enumeration
T1680
Local Storage Discovery
T1560.001
Archive via Utility
T1090.003
Multi-hop Proxy
T1105
Ingress Tool Transfer
T1036.008
Masquerade File Type
T1070.004
File Deletion
T1078
Valid Accounts
T1078.002
Domain Accounts
T1140
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution