> ## Content Index
> Fetch the complete content index at: https://www.whiteroseintelligence.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Volt Typhoon
- URL: https://www.whiteroseintelligence.com/volt-typhoon/
- Published: 1999-01-03T02:48:00.000Z
- Updated: 2025-01-26T23:59:32.000Z
- Author: Liam Sturgess
- Tags: Profiles, #docs, #organization

**Volt Typhoon** is a codename for a hacking group described as being sponsored by the Chinese government.[\[1\]](#fn1)

The name “Volt Typhoon” is used by Microsoft to describe the group based on the company's internal “threat actor naming taxonomy.”[\[2\]](#fn2) Secureworks describes the same group by the codename “Bronze Silhouette”.[\[3\]](#fn3)

## History

Volt Typhoon has reportedly been in operation since mid-2021.[\[4\]](#fn4) In June 2021, Secureworks identified an intrusion into one of its clients' networks, which the company attributed to the group.[\[3:1\]](#fn3) Separate intrusions were reported by Secureworks in September 2021 and June 2022.

On May 24, 2023, Microsoft issued a warning that Volt Typhoon had “compromised 'critical' U.S. cyber infrastructure across numerous industries with a focus on gathering intelligence.”[\[1:1\]](#fn1) The [National Security Agency](https://www.whiteroseintelligence.com/National-Security-Agency) (NSA) followed up with a report of their own titled “People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection”, co-published with the Cybersecurity and Infrastructure Security Agency (CISA), the [Federal Bureau of Investigation](https://www.whiteroseintelligence.com/Federal-Bureau-of-Investigation) (FBI), the Australian Cyber Security Centre (ACSC), the Canadian Centre for Cyber Security (CCCS), the New Zealand National Cyber Security Centre (NCSC-NZ) and the United Kingdom National Cyber Security Centre (NCSC-UK).[\[5\]](#fn5)

Secureworks published their own statement concurrently, describing their own analysis of the group's activities.[\[3:2\]](#fn3)

## External links

- [Campfire Wiki](https://www.campfire.wiki/doku.php?id=volt%5Ftyphoon)

### Further reading

- May 26, 2023: "[Public-Private Cybersecurity](https://www.whiteroseintelligence.com/blog/public-private-cybersecurity/)" by [Liam Sturgess](https://www.whiteroseintelligence.com/Liam-Sturgess)

---

1. Goswami, R. (2023, May 24). *Microsoft warns that China hackers attacked U.S. infrastructure.* CNBC. <http://archive.today/2023.05.24-213247/https://www.cnbc.com/2023/05/24/microsoft-warns-that-china-hackers-attacked-us-infrastructure.html> [↩︎](#fnref1) [↩︎](#fnref1:1)
2. diannegali, chrisda, Dansimp, & Stacyrch140\. (2023, April 20). *How Microsoft names threat actors.* Microsoft. <http://archive.today/2023.05.17-020026/https://learn.microsoft.com/en-us/microsoft-365/security/intelligence/microsoft-threat-actor-naming?view=o365-worldwide> [↩︎](#fnref2)
3. Secureworks Counter Threat Unit. (2023, May 24). *Chinese Cyberespionage Group BRONZE SILHOUETTE Targets U.S. Government and Defense Organizations.* Secureworks. <http://archive.today/2023.05.25-155704/https://www.secureworks.com/blog/chinese-cyberespionage-group-bronze-silhouette-targets-us-government-and-defense-organizations> [↩︎](#fnref3) [↩︎](#fnref3:1) [↩︎](#fnref3:2)
4. Microsoft Threat Intelligence. (2023, May 24). *Volt Typhoon targets US critical infrastructure with living-off-the-land techniques.* Microsoft Security Blog. <http://archive.today/2023.05.25-103813/https://www.microsoft.com/en-us/security/blog/2023/05/24/volt-typhoon-targets-us-critical-infrastructure-with-living-off-the-land-techniques/> [↩︎](#fnref4)
5. *People’s Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection.* (2023, May 24). National Security Agency. <https://web.archive.org/web/20230525163919/https://media.defense.gov/2023/May/24/2003229517/-1/-1/0/CSA%5FLiving%5Foff%5Fthe%5FLand.PDF> [↩︎](#fnref5)