Adversary-emulation profile for Volt Typhoon (G1017), a PRC state-sponsored actor pre-positioning in US critical infrastructure via living-off-the-land TTPs.
Volt Typhoon is a People's Republic of China (PRC) state-sponsored cyber actor active since at least mid-2021, tracked by MITRE ATT&CK as G1017 and known by the aliases BRONZE SILHOUETTE (Secureworks), Vanguard Panda (CrowdStrike), Voltzite (Dragos), Insidious Taurus (Palo Alto Unit 42), DEV-0391 (Microsoft's pre-naming designation), and UNC3236 (Mandiant). Unlike financially motivated crews, Volt Typhoon's hallmark is patient, ultra-stealthy pre-positioning inside US critical infrastructure — communications, energy, water, and transportation — using almost exclusively living-off-the-land (LOTL) techniques and legitimate stolen credentials, with little or no custom malware on victim hosts. CISA, the NSA, and the FBI assess the group is establishing persistent access not for immediate espionage value but to enable lateral movement to operational technology (OT) for potential disruptive or destructive attacks during a future geopolitical crisis or conflict. Its operational signature is hands-on-keyboard activity, native OS binaries, web shells on edge appliances, and traffic proxied through compromised small-office/home-office (SOHO) routers to blend into normal network noise.
AuditReport.jspx, iisstart.aspx, Awen, and VersaMem on Versa Director).rd /S), and scrubs IP addresses from server logs.[kworker/0:1]), uses legitimate-looking filenames (cisco_up.exe, Win.exe), and appends .gif to exfil archives of ntds.dit.netsh PortProxy registry modification.ntdsutil to create domain controller install media containing the NTDS database; dumps ntds.dit.net user, quser, net group /dom for local and domain account discovery.net localgroup administrators, net group for local/domain groups.ipconfig, netsh interface firewall, netsh interface portproxy.netstat -ano.wevtutil.exe and PowerShell Get-EventLog.C:\Windows\Temp\.rult3uil.log on domain controllers).netsh port proxy; multi-hop proxy chains. Customized FRP, Earthworm, and Impacket..gif-renamed archives (T1560.001 / T1036.008) staged on the host. The group avoids large-volume exfil to stay quiet, consistent with its access-maintenance objective.[kworker/0:1], uses random high ports, bind-mounts to /proc/, and proxies/anonymizes operator traffic. Custom.cmd (S0106), certutil (S0160), netsh (S0108), Net (S0039), netstat (S0104), Nltest (S0359), Ping (S0097), PsExec (S0029), Reg (S0075), Systeminfo (S0096), Tasklist (S0057), Wevtutil (S0645), ipconfig (S0100), plus ntdsutil, wmic, vssadmin, wevtutil. Web shells observed: Awen, AuditReport.jspx, iisstart.aspx. Recon/post-ex: ScanLine, BrightmetricAgent (UPX-packed).Authorized use only. Execute these TTPs solely within the documented scope and rules of engagement of an explicitly authorized red-team engagement. Do not target out-of-scope systems, real critical-infrastructure OT, or third-party edge devices, and never stage destructive actions — Volt Typhoon's value to emulate is its stealth and dwell, not impact.
Map Volt Typhoon's signature to Decepticon capabilities:
wmic, powershell, cmd, netsh. Forbid yourself from uploading EXEs where a LOLBin works. This is the defining behavior to reproduce.ntdsutil/ntds.dit capture and LSASS access; stage hives in C:\Windows\Temp\, 7-Zip into password-protected multi-volume archives, and rename with a .gif extension to mirror T1560.001 / T1074.001 / T1036.008.netsh portproxy for internal pivots (T1090.001 / T1112).net user, net group /dom, net localgroup administrators, ipconfig, netstat -ano, ping) so blue can validate baseline detections.Pace operations slowly and quietly to exercise long-dwell detection rather than tripping volume-based alerts.
wmic, ntdsutil/ntdsutil.exe create, vssadmin create shadow, netsh interface portproxy add, reg save HKLM\SYSTEM|SECURITY, wevtutil cl, and net group /domain issued by non-admin or service contexts (T1059, T1003.003, T1112, T1070.001). Follow CISA AA24-038A's supplemental LOTL guidance..gif that are actually archives) in C:\Windows\Temp\.HKLM\...\PortProxy\v4tov4 registry writes and unexpected netsh portproxy listeners; baseline egress to identify SOHO/edge relays and multi-hop proxy chains..jspx/.aspx files and unusual Tomcat/IIS child processes; for Versa, hunt in-memory Java agents hooking authentication and inspect /var/versa upload paths.5e34a6d
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.