Malware · critical

How to fixVOLT_TYPHOON_APT

Volt Typhoon Living-off-the-Land APT

What this error means

VOLT_TYPHOON_APT is a critical-severity malware/security problem. Volt Typhoon is a state-sponsored cyber actor that targets critical infrastructure. They use 'Living-off-the-Land' (LotL) techniques—using legitimate built-in administrative tools like PowerShell, wmic, and netsh—to blend in with normal system activity and maintain long-term undetected persistence. Common triggers are compromised edge devices (SOHO routers, firewalls, VPN appliances) and lack of command-line logging and network telemetry monitoring. Use the steps below to track down and fix the cause.

Before you begin

Save open work and back up important files. Note any recent driver or hardware changes. If Windows cannot start, use the startup guide first.

Work through these checks

0 of 4 complete
01Enable detailed PowerShell script block logging (Event ID 4104)

Enable detailed PowerShell script block logging (Event ID 4104).

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
02Perform a full audit of built-in system accounts and active sessions

Perform a full audit of built-in system accounts and active sessions.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
03Reset all administrative credentials and domain trust settings

Reset all administrative credentials and domain trust settings.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help
04Decommission and replace compromised edge network routing hardware

Decommission and replace compromised edge network routing hardware.

Use the instructions for your exact device and operating system. Check the manufacturer’s documentation before changing firmware, hardware, or system settings.

I need help

Possible causes

  • Compromised edge devices (SOHO routers, firewalls, VPN appliances)
  • Use of stolen administrative credentials
  • Lack of command-line logging and network telemetry monitoring