SecurityScorecard reported that the China-linked espionage group Volt Typhoon appears to have built a botnet from end-of-life Cisco RV320 and RV325 routers and other SOHO edge devices, with roughly 30% of 1,116 observed devices communicating with known command-and-control infrastructure over a 37-day period. The activity is tied to exploitation of older Cisco flaws including CVE-2019-1652 and CVE-2019-1653, and researchers identified a previously unspecified payload or webshell, fy.sh, linked to a Volt Typhoon payload server at 45.11.92[.]176. Additional suspected infrastructure, including 45.63.60[.]39 and 45.32.174[.]131, was associated with the group's JDY cluster through shared SSL certificate traits.
The findings add technical detail to broader U.S. warnings that Volt Typhoon has implanted malware in critical infrastructure networks, including utilities supporting military bases, in what officials and reporting have described as preparation for potential disruption during a Taiwan-related crisis. Separate analysis by DCSO challenged one part of the public reporting, saying evidence does not show that 67.205.139[.]175 functioned as a Tor exit relay when it communicated with 45.63.60[.]39, leaving open other explanations such as use of a Tor hidden service or a relay for operational cover. Even with that dispute, the reporting collectively points to a stealthy China-backed campaign using compromised edge devices and covert infrastructure to support long-term access near sensitive U.S. government and military-adjacent networks.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
DCSO published an analysis concluding that 67.205.139[.]175 did not appear to be configured as a Tor exit relay during the December 28-30, 2023 communications with 45.63.60[.]39, and said the evidence was insufficient to determine whether Volt Typhoon used a hidden service or a Tor relay as disguise.
On January 11, 2024, SecurityScorecard published research linking exploitation of vulnerable internet-exposed SOHO devices, especially end-of-life Cisco RV320/325 routers, to Volt Typhoon and assessed the activity was expanding the JDY botnet used for scanning and reconnaissance.
According to Tor Metrics cited by DCSO, the relay with fingerprint C899F20DC8005037C86B0E447857383D95FC7422 was first seen on January 10, 2024, though DCSO noted this may reflect an inconsistency.
SecurityScorecard said the Volt Typhoon-linked payload server at 45.11.92[.]176, associated with retrieval of the fy.sh file, was offline as of January 8, 2024.
SecurityScorecard reported that 45.63.60[.]39 communicated 25 times with 67.205.139[.]175 between December 28 and December 30, 2023, and described the latter IP as a Tor exit node.
SecurityScorecard observed 45.63.60[.]39 and 45.32.174[.]131 communicating 3,097 and 3,358 times respectively with 202.22.227[.]179 between December 28 and December 31, 2023, linking the servers to the JDY cluster.
SecurityScorecard reported that 144.202.49[.]189, a Volt Typhoon proxy router previously identified by Lumen, communicated 68,164 times with 82.117.159[.]158 between December 1 and December 7, 2023, leading to moderate-confidence assessment that the latter IP was Volt Typhoon-linked.
SecurityScorecard observed 325 of 1,116 Cisco RV320/325 devices communicating with known Volt Typhoon C2 proxy IPs during a 37-day period, suggesting widespread compromise or botnet participation.
SecurityScorecard observed four communications on November 18, 2023 between 31.19.153[.]48, where a DrayTek Vigor 2960 router was in use, and 202.22.227[.]179, where a Cisco RV325 device was in use.
On the same day as Microsoft's disclosure, CISA issued an advisory warning that Chinese government-sponsored Volt Typhoon actors were active across U.S. critical infrastructure sectors.
Microsoft published a blog post describing stealthy Volt Typhoon intrusions affecting U.S. critical infrastructure sectors, including Guam and other U.S. locations.
DCSO said Tor traffic history graphs suggested the relay with fingerprint C899F20DC8005037C86B0E447857383D95FC7422, associated with 67.205.139[.]175, had been active since as early as August 31, 2022.
Microsoft said the China-backed Volt Typhoon threat actor had been conducting stealthy activity since mid-2021, primarily focused on espionage and information gathering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcegovtech.com
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.