Back to Error Database
VOLT-TYPHOON-APT

Volt Typhoon Living-off-the-Land APT

CRITICAL malware ID: VIR-017

What is VOLT-TYPHOON-APT?

VOLT_TYPHOON_APT is a critical-severity malware/security problem. Volt Typhoon is a state-sponsored cyber actor that targets critical infrastructure. They use 'Living-off-the-Land' (LotL) techniques—using legitimate built-in administrative tools like PowerShell, wmic, and netsh—to blend in with normal system activity and maintain long-term undetected persistence. Common triggers are compromised edge devices (SOHO routers, firewalls, VPN appliances) and lack of command-line logging and network telemetry monitoring. Use the steps below to track down and fix the cause.

Common Causes

Step-by-Step Fix Guide

Commands & Diagnostics

powershell.exe Get-WinEvent -FilterHashtable @{LogName='Microsoft-Windows-PowerShell/Operational'; Id=4104} -MaxEvents 5 -ErrorAction SilentlyContinue
wevtutil.exe qe Microsoft-Windows-PowerShell/Operational /c:5 /f:text

Frequently Asked Questions

Still Need Help?

Search our full database of 535+ documented PC errors for more solutions and step-by-step repair guides.

Search Error Database