logo

The Botnet is Back: SSC STRIKE Team Uncovers a Renewed Cyber Threat

ID: 9e169fb3-7bed-5443-a679-74264c75905e

STIX ID: report--9e169fb3-7bed-5443-a679-74264c75905e

Feed Name: SecurityScorecard Blog

Threat Score
90/100

Date Published: 2025-04-17

Date Updated: 2026-04-29

...
...

SecurityScorecard’s STRIKE Team reports that the Asia-Pacific state-sponsored group Volt Typhoon has resurfaced and is actively exploiting end-of-life Cisco RV320/325 and Netgear ProSafe routers to assemble the JDYFJ botnet and covert transfer network; observed TTPs include MIPS-based malware (Mirai-like), implanted webshells (fy.sh), port-forwarding over 8443, a JDYFJ self-signed SSL certificate, and a compromised VPN in New Caledonia used to bridge Asia‑Pacific and the Americas, posing significant risk to governments and critical infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.