logo

The Botnet is Back: SSC STRIKE Team Uncovers a Renewed Cyber Threat

ID: b919bfae-77fa-5774-b000-2b906f194bc7

STIX ID: report--b919bfae-77fa-5774-b000-2b906f194bc7

Feed Name: SecurityScorecard Blog

Threat Score
88/100

Date Published: 2026-03-30

Date Updated: 2026-06-07

...
...

SecurityScorecard’s STRIKE Team details the resurgence of Volt Typhoon, a state-sponsored APT that compromises end-of-life Cisco RV320/325 and Netgear ProSafe routers to build a JDYFJ botnet using MIPS-based malware and webshells (e.g., fy.sh), routes traffic via C2 servers and a VPN pivot in New Caledonia, and targets energy and critical infrastructure with persistent, hard-to-detect operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.