logo

Calm In The Storm: Reviewing Volt Typhoon

ID: cda50c46-b0c2-589c-8089-5b85a21faea9

STIX ID: report--cda50c46-b0c2-589c-8089-5b85a21faea9

Feed Name: Huntress Blog

Threat Score
75/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

**Volt Typhoon** is a PRC-linked threat actor campaign that has conducted widespread exploitation of external-facing services (e.g., ManageEngine, PRTG, Fortinet) and small-office/home-office networking appliances to establish footholds and proxied C2 infrastructure; the actor favors living-off-the-land techniques and public tools for credential harvesting, lateral movement, and information gathering, posing a significant risk to critical infrastructure and any organization whose devices are exposed, and the report recommends patching, visibility (EDR/logging/netflow), and layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.