article · 2026-07-02 · Julian Okoye

Volt Typhoon’s living-off-the-land shift, 18 months on

The tradecraft did not disappear when the first round of advisories landed. It got quieter, closer to the identity plane, and harder to IOC.

The first Volt Typhoon advisories trained a generation of defenders to look for dumped configs and unusual device-admin sessions. That was correct, and it is now insufficient. The clusters we track in 2026 spend less time on the network devices themselves and more time on the identity systems that tell those devices who is allowed to log in.

Living-off-the-land is not a technique. It is a constraint: if you never drop a binary, most of the intel the industry still buys will never fire. The remaining signals are administrative — ticket-like change patterns, VPN posture, and the reuse of legitimate remote-access tooling.

Neighborhoods for this cluster have turned over three times since the original reporting. The behaviors have not. That is the argument for a bound operational picture: you are allowed to lose the IP. You are not allowed to lose the method.

Questions

Common questions

How has Volt Typhoon’s tradecraft changed since the first advisories?
The clusters tracked in 2026 spend less time on network devices and more on the identity systems that decide who may log in. Defenders who learned to hunt dumped configs need to widen the lens. Attack Nemesis Research finds Volt Typhoon has moved closer to the identity plane.
Why do most threat intel feeds miss living-off-the-land activity?
Living-off-the-land never drops a binary, so intel that fires on a file or a hash never fires. The remaining signals are administrative. Attack Nemesis treats living-off-the-land as a constraint on detection, not a single technique.
What should defenders watch for Volt Typhoon activity?
Change patterns that look like tickets, VPN posture, and reuse of legitimate remote-access tools. These are the signals left when there is no malware to catch. Attack Nemesis recommends watching administrative behavior, not artifacts.
What does this mean for an intelligence program?
The cluster’s infrastructure has turned over three times; its behaviors have not. A bound operational picture keeps the method even when the IP is gone. With Attack Nemesis, you are allowed to lose the IP, not the method.

Next step

See the platform against your environment.

A forty-minute briefing: your sources, your stack, and the tickets that should already exist.