logo

Threat Intelligence Research: Volt Typhoon Compromises 30% of Cisco RV320/325 Devices in 37 Days

ID: beaecb00-03c7-52c2-bfb0-5e5755c511a7

STIX ID: report--beaecb00-03c7-52c2-bfb0-5e5755c511a7

Feed Name: SecurityScorecard Blog

Threat Score
85/100

Date Published: 2024-08-27

Date Updated: 2026-04-29

...
...

SecurityScorecard STRIKE reports that Volt Typhoon (a China‑linked state‑sponsored threat actor) is leveraging compromised SOHO/network‑edge devices—primarily Cisco RV320/325 routers—to build covert infrastructure for data transfer and possible access to target networks; researchers observed communication between many Cisco devices and known Volt Typhoon IoCs across multiple regions, highlighted the risk posed by end‑of‑life devices, and recommended identifying vulnerable devices, upgrading unsupported hardware, and continuous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.