logo

Feds Confirm Remote Killing of Volt Typhoon's SOHO Botnet

ID: 5918a0f4-7a40-5028-8021-b8f4495f02b7

STIX ID: report--5918a0f4-7a40-5028-8021-b8f4495f02b7

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2024-02-01

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

US authorities executed a court-authorized operation to disrupt Volt Typhoon (aka Bronze Silhouette / Vanguard Panda) by mimicking the group's C2 to remove KV Botnet malware from vulnerable Cisco and Netgear SOHO routers. The takedown temporarily severed the botnet and blocked C2 communications, but officials and analysts warn the state-sponsored APT—which targets utilities, energy, telecoms and industrial sites to establish footholds for future disruptive operations—remains at large and likely to rebuild or use alternate methods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.