# Volt Typhoon - G1017

> As of 2026-10-06, Volt Typhoon - G1017 is a China / Iran-nexus threat actor tracked by Threadlinqs Intelligence across 2 threats spanning ics scada, threat intel. Also known as Volt Typhoon, Cyber Av3ngers, CyberAv3ngers. ATT&CK coverage spans 57 techniques across 17 tactics in 2 of 2 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1090.003 (Multi-hop Proxy), T1190 (Exploit Public-Facing Application).

- **Nation:** China / Iran
- **Tracked threats:** 2
- **Categories:** ICS_SCADA, THREAT_INTEL
- **Also known as:** Volt Typhoon, Cyber Av3ngers, CyberAv3ngers
- **As of:** 2026-10-06

## ATT&CK techniques observed

57 techniques observed across 2 of 2 tracked threats. Tactics: Stealth (formerly Defense Evasion) (8), Execution (7), Resource Development (6), Initial Access (5), Collection (4), Credential Access (4).

- [T1078](https://intel.threadlinqs.com/technique/T1078) Valid Accounts — Persistence — observed in 2 of 2 tracked threats
- [T1090.003](https://intel.threadlinqs.com/technique/T1090.003) Multi-hop Proxy — Command and Control — observed in 2 of 2 tracked threats
- [T1190](https://intel.threadlinqs.com/technique/T1190) Exploit Public-Facing Application — Initial Access — observed in 2 of 2 tracked threats
- [T0893](https://attack.mitre.org/techniques/T0893/) Data from Local System — Collection (ICS) — observed in 1 of 2 tracked threats
- [T1003.001](https://intel.threadlinqs.com/technique/T1003.001) LSASS Memory — Credential Access — observed in 1 of 2 tracked threats
- [T1003.003](https://intel.threadlinqs.com/technique/T1003.003) NTDS — Credential Access — observed in 1 of 2 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 1 of 2 tracked threats
- [T1020](https://intel.threadlinqs.com/technique/T1020) Automated Exfiltration — Exfiltration — observed in 1 of 2 tracked threats
- [T1021.001](https://intel.threadlinqs.com/technique/T1021.001) Remote Desktop Protocol — Lateral Movement — observed in 1 of 2 tracked threats
- [T1027.002](https://intel.threadlinqs.com/technique/T1027.002) Software Packing — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1027.013](https://intel.threadlinqs.com/technique/T1027.013) Encrypted/Encoded File — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 1 of 2 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 1 of 2 tracked threats
- [T1047](https://intel.threadlinqs.com/technique/T1047) Windows Management Instrumentation — Execution — observed in 1 of 2 tracked threats
- [T1056.001](https://intel.threadlinqs.com/technique/T1056.001) Keylogging — Collection — observed in 1 of 2 tracked threats

## Tracked threats

- [OT Attacks on US Critical Infrastructure: Volt Typhoon Persistence and Iranian-Affiliated PLC Exploitation (Rockwell, Unitronics, Siemens S7)](https://intel.threadlinqs.com/threat/TL-2026-2961) — CRITICAL
- [Cyble H1 2026 Threat Actor Landscape: 261 Tracked Groups, Five Most Active Actors Profiled](https://intel.threadlinqs.com/threat/TL-2026-1721) — HIGH

## Related CVEs

5 CVEs referenced by tracked Volt Typhoon - G1017 activity.

- [CVE-2024-39717](https://intel.threadlinqs.com/cve/CVE-2024-39717)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2023-27997](https://intel.threadlinqs.com/cve/CVE-2023-27997)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2021-22681](https://intel.threadlinqs.com/cve/CVE-2021-22681)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Volt%20Typhoon%20-%20G1017
