logo

Volt Typhoon: LOLBins get serious by Joshua St. Hilaire

ID: 6430e074-e46b-5554-9461-e949b6aaf776

STIX ID: report--6430e074-e46b-5554-9461-e949b6aaf776

Feed Name: Vectra AI Blog

Threat Score
88/100

Date Published: 2023-09-29

Date Updated: 2026-05-01

...
...

This report summarizes Microsoft and JCA findings on Volt Typhoon, a Chinese state-sponsored espionage campaign targeting US critical infrastructure that maintains long-term, stealthy access by abusing compromised SOHO devices as proxies and using stolen credentials and built-in Windows tools (e.g., netsh portproxy, WMIC, ping) rather than deploying obvious malware; it highlights detection challenges and recommends behavioral hunting for unusual logins, rare inbound ports, WMI activity, and other deviations from normal patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.