The first Volt Typhoon advisories trained a generation of defenders to look for dumped configs and unusual device-admin sessions. That was correct, and it is now insufficient. The clusters we track in 2026 spend less time on the network devices themselves and more time on the identity systems that tell those devices who is allowed to log in.
Living-off-the-land is not a technique. It is a constraint: if you never drop a binary, most of the intel the industry still buys will never fire. The remaining signals are administrative — ticket-like change patterns, VPN posture, and the reuse of legitimate remote-access tooling.
Neighborhoods for this cluster have turned over three times since the original reporting. The behaviors have not. That is the argument for a bound operational picture: you are allowed to lose the IP. You are not allowed to lose the method.
