ATT&CKReferencesJoint Cybersecurity Advisory Volt Typhoon June 2023

Joint Cybersecurity Advisory Volt Typhoon June 2023

NSA et al. (2023, May 24). People's Republic of China State-Sponsored Cyber Actor Living off the Land to Evade Detection. Retrieved July 27, 2023.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1003.003
NTDS
GroupVolt Typhoon

Volt Typhoon has used ntds.util to create domain controller installation media containing usernames and password hashes.

T1005
Data from Local System
GroupVolt Typhoon

Volt Typhoon has stolen files from a sensitive file server and the Active Directory database from targeted environments, and used Wevtutil to extract event log information.

T1012
Query Registry
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems, `reg query hklm\software\`, for information on installed software including PuTTY.

T1016
System Network Configuration Discovery
GroupVolt Typhoon

Volt Typhoon has executed multiple commands to enumerate network topology and settings including `ipconfig`, `netsh interface firewall show all`, and `netsh interface portproxy show all`.

T1033
System Owner/User Discovery
GroupVolt Typhoon

Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names.

T1036.005
Match Legitimate Resource Name or Location
GroupVolt Typhoon

Volt Typhoon has used legitimate looking filenames for compressed copies of the ntds.dit database and used names including cisco_up.exe, cl64.exe, vm3dservice.exe, watchdogd.exe, Win.exe, WmiPreSV.exe, and WmiPrvSE.exe for the Earthworm and Fast Reverse Proxy tools.

T1047
Windows Management Instrumentation
GroupVolt Typhoon

Volt Typhoon has leveraged WMIC for execution, remote system discovery, and to create and use temporary directories.

T1049
System Network Connections Discovery
GroupVolt Typhoon

Volt Typhoon has used `netstat -ano` on compromised hosts to enumerate network connections.

T1059.001
PowerShell
GroupVolt Typhoon

Volt Typhoon has used PowerShell including for remote system discovery.

T1059.003
Windows Command Shell
GroupVolt Typhoon

Volt Typhoon has used the Windows command line to perform hands-on-keyboard activities in targeted environments including for discovery.

T1069.001
Local Groups
GroupVolt Typhoon

Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.

T1074.001
Local Data Staging
GroupVolt Typhoon

Volt Typhoon has saved stolen files including the `ntds.dit` database and the `SYSTEM` and `SECURITY` Registry hives locally to the `C:\Windows\Temp\` directory.

T1087.002
Domain Account
GroupVolt Typhoon

Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery.

T1090
Proxy
GroupVolt Typhoon

Volt Typhoon has used compromised devices and customized versions of open source tools such as FRP (Fast Reverse Proxy), Earthworm, and Impacket to proxy network traffic.

T1518
Software Discovery
GroupVolt Typhoon

Volt Typhoon has queried the Registry on compromised systems for information on installed software.

T1555
Credentials from Password Stores
GroupVolt Typhoon

Volt Typhoon has attempted to obtain credentials from OpenSSH, realvnc, and PuTTY.

T1584.008
Network Devices
GroupVolt Typhoon

Volt Typhoon has compromised small office and home office (SOHO) network edge devices, many of which were located in the same geographic area as the victim, to proxy network traffic.

T1654
Log Enumeration
GroupVolt Typhoon

Volt Typhoon has used `wevtutil.exe` and the PowerShell command `Get-EventLog security` to enumerate Windows logs to search for successful logons.

T1680
Local Storage Discovery
GroupVolt Typhoon

Volt Typhoon has discovered file system types, drive names, size, and free space on compromised systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.