logo

Volt Typhoon Ramps Up Malicious Activity Against Critical Infrastructure

ID: dcc4275c-b602-5d3d-afd8-bf23cf8cb0b9

STIX ID: report--dcc4275c-b602-5d3d-afd8-bf23cf8cb0b9

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-01-11

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

China-backed APT Volt Typhoon is actively exploiting known 2019 vulnerabilities in end-of-life Cisco RV320/325 and other SOHO routers to compromise devices, deploy a new web shell (fy.sh), and build a C2 botnet used to target critical infrastructure sectors (water, power, transportation, communications) across the US, UK, and Australia while employing stealthy living-off-the-land techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.