logo

Volt Typhoon rebuilds malware botnet following FBI disruption

ID: 0a9be409-746d-5b6b-a0cc-f08aa537dc73

STIX ID: report--0a9be409-746d-5b6b-a0cc-f08aa537dc73

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-11-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Volt Typhoon, a Chinese state-sponsored APT, has begun rebuilding its KV‑Botnet by compromising outdated Cisco RV320/325 and Netgear ProSafe routers using MIPS-based malware and webshells; SecurityScorecard observed roughly 30% of internet-exposed RV320/325 devices compromised in 37 days, with the botnet employing a self-signed 'jdyfj' certificate, non-standard ports, and geographically chosen bridges to proxy and obfuscate traffic, showing active, persistent campaign activity following a January disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.