logo

Volt Typhoon in the wild

ID: b17ea679-676f-5d21-a349-4d25ec8e6844

STIX ID: report--b17ea679-676f-5d21-a349-4d25ec8e6844

Feed Name: ThreatLocker Blog

Threat Score
85/100

Date Published: 2025-01-03

Date Updated: 2026-05-01

...
...

Volt Typhoon, a state-sponsored PRC cyber actor, has been observed engaging in intrusion, reconnaissance, and data exfiltration using living-off-the-land tools (e.g., tasklist.exe to enumerate processes/DLLs, mpcmdrun.exe to probe Windows Defender/CVE-2023-24934, and attempted wmic.exe execution); ThreatLocker documents the IoC timeline, notes wmic was blocked, and provides detection and mitigation recommendations including credential resets, command-line auditing, and ThreatLocker-specific controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.