Watch Vectra AI’s Attack Lab on demand to dissect Volt Typhoon and modern living-off-the-land attacks. Learn how LOTL tradecraft evades detection and discover practical ways to close critical visibility gaps.
Volt Typhoon held access to US critical infrastructure for at least five years without dropping malware. The TTPs are documented by CISA, NSA, FBI and Microsoft Threat Intelligence: native admin tools, valid sessions, signed binaries with sideloaded components. Nothing they did ever looked wrong.
This 25-minute lab walks the Volt Typhoon anatomy phase by phase, then puts three other campaigns next to it: Salt Typhoon’s telco intrusions, Flax Typhoon’s edge-device persistence, and the BRICKSTORM activity Mandiant tracked in 2024 and 2025. Each one exploits the same gap from a different angle.
You will leave with the behavior signals that connect all four campaigns, the categories of telemetry your tools cannot produce alone, and three changes worth shipping on Monday.

Vectra AI is the leader in hybrid attack detection, investigation and response. The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Vectra AI’s patented Attack Signal Intelligence empowers security teams to rapidly detect, prioritize, investigate and stop the most advanced hybrid cyber-attacks. With 35 patents in AI-driven detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI Platform and MXDR services to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai.