Volt Typhoon in the wild
ID: b17ea679-676f-5d21-a349-4d25ec8e6844
STIX ID: report--b17ea679-676f-5d21-a349-4d25ec8e6844
Feed Name: ThreatLocker Blog
Volt Typhoon, a state-sponsored PRC cyber actor, has been observed engaging in intrusion, reconnaissance, and data exfiltration using living-off-the-land tools (e.g., tasklist.exe to enumerate processes/DLLs, mpcmdrun.exe to probe Windows Defender/CVE-2023-24934, and attempted wmic.exe execution); ThreatLocker documents the IoC timeline, notes wmic was blocked, and provides detection and mitigation recommendations including credential resets, command-line auditing, and ThreatLocker-specific controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
