Internet Footprint of SOHO Devices Exploited by Volt Typhoon
ID: ede8f67a-bf5d-5cf6-b1d0-cf0ae9042644
STIX ID: report--ede8f67a-bf5d-5cf6-b1d0-cf0ae9042644
Feed Name: Censys Blog
Threat Score
Microsoft and allied agencies disclosed Volt Typhoon, a Chinese state-sponsored group active since mid‑2021 that conducts stealthy intrusions against US and Guam communications infrastructure. The actor leverages living‑off‑the‑land techniques and proxies traffic through compromised SOHO networking devices (notably routers with SSH/HTTP exposed) from vendors such as Cisco, Draytek, FatPipe, Netgear Prosafe, and Zyxel to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
