Volt Typhoon Hits Multiple Electric Utilities, Expands Cyber Activity
ID: 9eefe1e0-1a7e-576c-9847-e0ec6ef8c0e4
STIX ID: report--9eefe1e0-1a7e-576c-9847-e0ec6ef8c0e4
Feed Name: Dark Reading
Date Published: 2024-02-15
Date Updated: 2026-04-21
Author: Tara Seals, Managing Editor, News, Dark Reading
Dragos reports that Voltzite, the OT-focused activity of the China-linked Volt Typhoon APT, has maintained long-term clandestine access to multiple US electric utilities, telecoms, and emergency services, exfiltrating OT- and SCADA-related data and using living-off-the-land techniques (e.g., csvde.exe, Volume Shadow Copy to steal NTDS.dit, web shells, FRP) to avoid detection; while no successful disruption of ICS has been observed yet, the adversary is pre-positioned to enable future disruptive operations against critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
