logo

Volt Typhoon Hits Multiple Electric Utilities, Expands Cyber Activity

ID: 9eefe1e0-1a7e-576c-9847-e0ec6ef8c0e4

STIX ID: report--9eefe1e0-1a7e-576c-9847-e0ec6ef8c0e4

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-02-15

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

Dragos reports that Voltzite, the OT-focused activity of the China-linked Volt Typhoon APT, has maintained long-term clandestine access to multiple US electric utilities, telecoms, and emergency services, exfiltrating OT- and SCADA-related data and using living-off-the-land techniques (e.g., csvde.exe, Volume Shadow Copy to steal NTDS.dit, web shells, FRP) to avoid detection; while no successful disruption of ICS has been observed yet, the adversary is pre-positioned to enable future disruptive operations against critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.