logo

China's Volt Typhoon crew and its botnet surge back with a vengeance

ID: 3e4b7f6e-e4be-56a0-99e4-0c5ccd9ac145

STIX ID: report--3e4b7f6e-e4be-56a0-99e4-0c5ccd9ac145

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2024-11-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Security researchers report that Volt Typhoon, a China-linked APT, has reconstituted a botnet by compromising end-of-life Cisco RV320/325 and Netgear ProSafe routers—using JDYFJ SSL certificates, new C2 servers, and web shells—to maintain persistent access and pivot into critical infrastructure and telecommunications networks despite an earlier FBI disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.