logo

Internet Footprint of SOHO Devices Exploited by Volt Typhoon

ID: ede8f67a-bf5d-5cf6-b1d0-cf0ae9042644

STIX ID: report--ede8f67a-bf5d-5cf6-b1d0-cf0ae9042644

Feed Name: Censys Blog

Threat Score
90/100

Date Published: 2023-05-25

Date Updated: 2026-04-27

Author: Ivonne Francia

...
...

Microsoft and allied agencies disclosed Volt Typhoon, a Chinese state-sponsored group active since mid‑2021 that conducts stealthy intrusions against US and Guam communications infrastructure. The actor leverages living‑off‑the‑land techniques and proxies traffic through compromised SOHO networking devices (notably routers with SSH/HTTP exposed) from vendors such as Cisco, Draytek, FatPipe, Netgear Prosafe, and Zyxel to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.