logo

The Hunt: Detecting VOLTZITE Threat Group Activity in Critical Infrastructure

ID: 1fdb0ba3-0959-5143-a4e1-8bf69ed906d3

STIX ID: report--1fdb0ba3-0959-5143-a4e1-8bf69ed906d3

Feed Name: Dragos Blog

Threat Score
80/100

Date Published: 2024-04-10

Date Updated: 2026-04-27

...
...

Dragos OT Watch describes detection and threat-hunting activity against the VOLTZITE (Volt Typhoon) APT targeting ICS/OT environments, reporting observed TLS 1.2 command-and-control communications, exfiltration of GIS server data, SMB traversal and discovery actions adjacent to OT systems; the blog outlines known TTPs and IOCs, hunting examples, and defensive measures including platform detections and community notification.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.