📣 Send us your press release
Site updates every 15 minutes
Technology

Chinese Volt Typhoon Group Abuses LOLBins for Cyber Espionage

A Chinese state-sponsored group, Volt Typhoon, is employing Living Off The Land Binaries (LOLBins) to conduct cyber espionage campaigns. The group targets critical infrastructure in the US and Asia.

28 September 2026

A Chinese state-sponsored advanced persistent threat (APT) group, known as Volt Typhoon, is utilizing Living Off The Land Binaries (LOLBins) to conduct stealthy cyber espionage campaigns, according to analysis by Picus Security. The group primarily targets critical infrastructure organizations in the United States and Asia.

Volt Typhoon, also tracked as BRONZE SILHOUETTE, aims to gather and exfiltrate sensitive information while minimizing detection. Their operational tactics involve gaining initial access, conducting reconnaissance using LOLBins, moving laterally within the network, and exfiltrating data via command and control (C2) channels.

Initial access is typically achieved through compromised credentials or by exploiting vulnerabilities in public-facing applications, such as Fortinet devices and ManageEngine products. The group leverages tools like Windows Management Instrumentation (WMI) and native scripting languages like PowerShell and Command Prompt for execution and information gathering.

To maintain persistence, Volt Typhoon deploys custom web shells that can encrypt their C2 communications. They also actively remove system logs and other artifacts to evade detection and hinder threat hunting efforts.

Picus Security's report highlights the sophistication of these threats and the importance of robust defense mechanisms to detect and respond to such advanced persistent threats targeting vital sectors.

Original source: picussecurity.com