Chinese hackers fail to rebuild botnet after FBI takedown
ID: 99130046-6241-5cc7-b33b-ffceb410e0e2
STIX ID: report--99130046-6241-5cc7-b33b-ffceb410e0e2
Feed Name: Bleeping Computer
Volt Typhoon, a Chinese state-linked threat actor, attempted to rebuild its KV-botnet after an FBI court-authorized takedown by scanning thousands of SOHO devices (targeting ~33% of NetGear ProSAFE devices exposed online) and successfully infecting several hundred devices in early December 2023; Lumen Technologies' Black Lotus Labs and the FBI mitigated the resurgence by null-routing the attackers' C2 and payload servers, and no active KV C2s have been observed since January 3, 2024.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
