Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure
ID: dcc4275c-b602-5d3d-afd8-bf23cf8cb0b9
STIX ID: report--dcc4275c-b602-5d3d-afd8-bf23cf8cb0b9
Feed Name: Dark Reading
Threat Score
China-backed APT Volt Typhoon is actively exploiting known 2019 vulnerabilities in end-of-life Cisco RV320/325 and other SOHO routers to compromise devices, deploy a new web shell (fy.sh), and build a C2 botnet used to target critical infrastructure sectors (water, power, transportation, communications) across the US, UK, and Australia while employing stealthy living-off-the-land techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
