The Botnet is Back: SSC STRIKE Team Uncovers a Renewed Cyber Threat
ID: 9e169fb3-7bed-5443-a679-74264c75905e
STIX ID: report--9e169fb3-7bed-5443-a679-74264c75905e
Feed Name: SecurityScorecard Blog
SecurityScorecard’s STRIKE Team reports that the Asia-Pacific state-sponsored group Volt Typhoon has resurfaced and is actively exploiting end-of-life Cisco RV320/325 and Netgear ProSafe routers to assemble the JDYFJ botnet and covert transfer network; observed TTPs include MIPS-based malware (Mirai-like), implanted webshells (fy.sh), port-forwarding over 8443, a JDYFJ self-signed SSL certificate, and a compromised VPN in New Caledonia used to bridge Asia‑Pacific and the Americas, posing significant risk to governments and critical infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
