The Botnet is Back: SSC STRIKE Team Uncovers a Renewed Cyber Threat
ID: b919bfae-77fa-5774-b000-2b906f194bc7
STIX ID: report--b919bfae-77fa-5774-b000-2b906f194bc7
Feed Name: SecurityScorecard Blog
Threat Score
SecurityScorecard’s STRIKE Team details the resurgence of Volt Typhoon, a state-sponsored APT that compromises end-of-life Cisco RV320/325 and Netgear ProSafe routers to build a JDYFJ botnet using MIPS-based malware and webshells (e.g., fy.sh), routes traffic via C2 servers and a VPN pivot in New Caledonia, and targets energy and critical infrastructure with persistent, hard-to-detect operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
