
Michael Horka

2026
The Network That Doesnât Exist: Tracking Volt Typhoonâs Silent Train
In late 2023, Lumen's Black Lotus Labs exposed a covert network used by Volt Typhoon, known as the KV botnet, which was ultimately disrupted through a coordinated effort between industry and government. While that operation significantly degraded the actor's capabilities, it also marked the beginning of a notable evolution in Volt Typhoon's tradecraft.
In the aftermath, Black Lotus Labs began tracking a far more elusive operational network used by Volt Typhoon, which we call Silent Train. Built from ephemeral, compromised SOHO and IoT devices, Silent Train enables highly covert operations while minimizing opportunities for detection, monitoring, attribution, and retrospective investigation. Unlike traditional operational relay infrastructure, this capability is designed for flexibility, resiliency, and operational security, allowing operators to rapidly establish and discard session paths as desired.
In this talk, we detail how Silent Train supports some of Volt Typhoon's most sensitive operations, enabling highly targeted intrusions against critical infrastructure, telecommunications providers, government entities, military organizations, and the defense industrial base. We will discuss how the actor has combined operational innovation with 0-day exploitation to establish access, maintain flexibility, and reduce visibility throughout the intrusion lifecycle. The emergence of this model reflects a broader shift in how sophisticated adversaries conduct covert operations and maintain access to strategically significant targets.
Finally, we will share lessons learned from years of tracking these activities, discuss approaches for identifying operations specifically designed to minimize forensic evidence, and explore what this evolution signals for the future of nation-state intrusion campaigns. After years of persistent investigation, surreptitious disruption efforts, and collaboration with partners across industry and government, we are now ready to provide an unprecedented look into one of the most advanced cyber espionage operations observed to date.
About Michael Horka
Michael Horka is a cybersecurity leader with over a decade of experience identifying, tracking, and disrupting covert networks, botnets, and advanced nationâstate actors. At Lumenâs Black Lotus Labs, he leads efforts to uncover and dismantle obfuscation networks leveraged by sophisticated threat groups.Â
Prior to joining the private sector, he served as a Special Agent with the FBIâs Houston Field Office, where he conducted inâdepth threat analysis and reported on nationâstate cyber campaigns.
