Volt Typhoon rebuilds malware botnet following FBI disruption
ID: 0a9be409-746d-5b6b-a0cc-f08aa537dc73
STIX ID: report--0a9be409-746d-5b6b-a0cc-f08aa537dc73
Feed Name: Bleeping Computer
Volt Typhoon, a Chinese state-sponsored APT, has begun rebuilding its KV‑Botnet by compromising outdated Cisco RV320/325 and Netgear ProSafe routers using MIPS-based malware and webshells; SecurityScorecard observed roughly 30% of internet-exposed RV320/325 devices compromised in 37 days, with the botnet employing a self-signed 'jdyfj' certificate, non-standard ports, and geographically chosen bridges to proxy and obfuscate traffic, showing active, persistent campaign activity following a January disruption.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
