216.73.216.233

Will the Real Volt Typhoon Please Stand Up?

· Published 17/01/2025 17:26 · Modified 17/01/2025 17:54

Export JSON

Essential information

Published
17/01/2025 17:26
Modified
17/01/2025 17:54
Tags
2025-01-17 china cisco routers critical-infrastructure jdy cluster kv botnet
Related entities
9 observables, 1 intrusion sets (apt), 6 techniques (mitre), 1 malware, 1 others

Description

This analysis tracks the evolution of the , attributed to the Volt Typhoon threat group, following FBI disruption in December 2023. Despite sophisticated operations, the botnet's infrastructure remained largely consistent, only changing hosting providers. The , targeting , showed activity with new control servers using a 'jdyfj' certificate. Three current hosts were identified using this certificate. The contrast between Volt Typhoon's sophisticated targeting and the botnet's simple evasion tactics raises questions about their relationship. The analysis suggests the might be operated by a different entity than Volt Typhoon, highlighting the complexity of attribution in cyber threats.

External references