Will the Real Volt Typhoon Please Stand Up?

Jan. 17, 2025, 5:54 p.m.

Description

This analysis tracks the evolution of the KV Botnet, attributed to the Volt Typhoon threat group, following FBI disruption in December 2023. Despite sophisticated operations, the botnet's infrastructure remained largely consistent, only changing hosting providers. The JDY cluster, targeting Cisco routers, showed activity with new control servers using a 'jdyfj' certificate. Three current hosts were identified using this certificate. The contrast between Volt Typhoon's sophisticated targeting and the botnet's simple evasion tactics raises questions about their relationship. The analysis suggests the KV Botnet might be operated by a different entity than Volt Typhoon, highlighting the complexity of attribution in cyber threats.

Date

  • Created: Jan. 17, 2025, 5:26 p.m.
  • Published: Jan. 17, 2025, 5:26 p.m.
  • Modified: Jan. 17, 2025, 5:54 p.m.

Indicators

  • 172.233.211.226
  • 2.58.15.30
  • 66.85.27.190
  • 144.202.49.189
  • 108.61.132.157
  • 174.138.56.21
  • 159.203.113.25
  • 45.63.60.39
  • 45.32.174.131

Attack Patterns

  • KV Botnet
  • Volt Typhoon
  • T1011
  • T1071
  • T1102
  • T1020
  • T1584
  • T1133

Additional Informations

  • United States of America