https://www.theregister.com/2024/01/31/volt_typhoon_botnet/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Cloud Infrastructure Week Cybersecurity Month Blackhat and DEF CON Sysadmin Month The Reg in Space Emerging Clean Energy Tech Week Spotlight on RSA Energy Efficient Datacenters Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Amazon Web Services (AWS) Business Transformation Google Cloud Infrastructure Hewlett Packard Enterprise: AI & ML solutions Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [front] Security 3 comment bubble on white FBI confirms it issued remote kill command to blow out Volt Typhoon's botnet 3 comment bubble on white Remotely disinfects Cisco and Netgear routers to block Chinese critters icon Jessica Lyons Hardcastle Wed 31 Jan 2024 // 19:24 UTC # China's Volt Typhoon attackers used "hundreds" of outdated Cisco and NetGear routers infected with malware in an attempt to break into US critical infrastructure facilities, according to the Justice Department. On Tuesday news broke that the Feds had blocked the malicious network that was set up on end-of-life, US-based small office/home office routers. Now more details have come out about how an FBI team infiltrated the attack and harvested the key data before remotely wiping the KV Botnet, according to four warrants (5018, 5530, 5451 and 5432) filed by the FBI in the Southern District Court of Texas last month and released today. "China's hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict," FBI Director Christopher Wray said in a statement. "Volt Typhoon malware enabled China to hide as they targeted our communications, energy, transportation, and water sectors." [front] The Feds claim the Middle Kingdom keyboard warriors downloaded a virtual private network module to the vulnerable routers and set up an encrypted communication channel to control the botnet and hide their illegal activities. Specifically: Volt Typhoon used the US-based routers and IP addresses to target US critical infrastructure, we're told. * US shorts China's Volt Typhoon crew targeting America's criticals * Five Eyes and Microsoft accuse China of attacking US infrastructure again * We know nations are going after critical systems, but what happens when crims join in? * Ivanti releases patches for VPN zero-days, discloses two more high-severity vulns The warrants allowed law enforcement to remotely install software on the routers to search for, and then seize or copy, information about the illicit activity before wiping the malware from the compromised devices. To do this -- and to limit the cops' search to routers infected with the botnet -- the FBI sent specific KV Botnet commands to compromised routers to collect "non-content information about those nodes," according to the warrants. [front] This includes the IP address, port numbers used by infected routers to communicate with other nodes, as well as IP addresses and ports used by each node's parent, and data on the command-and-control nodes. "A router that is not infected by the KV Botnet malware would not receive or respond to this command," court documents claim. [front] The Feds, along with foreign agency partners in Five Eyes nations, first warned about this threat in May 2023. Also today, the US Cybersecurity Agency and FBI issued an alert urging manufacturers to eliminate defects in SOHO router web management interfaces. This, according to the agencies, includes automating update capabilities, locating the web management interface on LAN-side ports, and requiring a manual override to remove security settings. (r) Get our Tech Resources # Share More about * China * Cybercrime * Security More like these x More about * China * Cybercrime * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * China Mobile * China telecom * China Unicom * Common Vulnerability Scoring System * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Cyberspace Administration of China * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Encryption * Exploit * Firewall * Great Firewall * Hacker * Hacking * Hacktivism * Hong Kong * Identity Theft * Incident response * Infosec * JD.com * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Semiconductor Manufacturing International Corporation * Shenzhen * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Uyghur Muslims * Vulnerability * Wannacry * Zero trust Broader topics * APAC More about # Share 3 comment bubble on white COMMENTS More about * China * Cybercrime * Security More like these x More about * China * Cybercrime * Security Narrower topics * 2FA * Advanced persistent threat * Application Delivery Controller * Authentication * BEC * Black Hat * BSides * Bug Bounty * China Mobile * China telecom * China Unicom * Common Vulnerability Scoring System * Cybersecurity * Cybersecurity and Infrastructure Security Agency * Cybersecurity Information Sharing Act * Cyberspace Administration of China * Data Breach * Data Protection * Data Theft * DDoS * DEF CON * Digital certificate * Encryption * Exploit * Firewall * Great Firewall * Hacker * Hacking * Hacktivism * Hong Kong * Identity Theft * Incident response * Infosec * JD.com * Kenna Security * NCSAM * NCSC * Palo Alto Networks * Password * Phishing * Quantum key distribution * Ransomware * Remote Access Trojan * REvil * RSA Conference * Semiconductor Manufacturing International Corporation * Shenzhen * Spamming * Spyware * Surveillance * TLS * Trojan * Trusted Platform Module * Uyghur Muslims * Vulnerability * Wannacry * Zero trust Broader topics * APAC TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Russians invade Microsoft exec mail while China jabs at VMware vCenter Server Plus: Uncle Sam says Ivanti exploits 'consistent with PRC' snoops Cyber-crime20 Jan 2024 | 9 US shorts China's Volt Typhoon crew targeting America's criticals Invaders inveigle infrastructure Security30 Jan 2024 | 7 What Microsoft's latest email breach says about this IT security heavyweight Comment Senator Wyden tells The Reg this latest infosec lapse is 'inexcusable' CSO24 Jan 2024 | 44 Turbo-charging the WLAN with Wi-Fi 7 New Huawei AP designed to boost speed, access and efficiency in campus wireless networks Sponsored Feature [front] Atlassian Confluence Server RCE attacks underway from 600+ IPs If you're still running a vulnerable instance then 'assume a breach' Security22 Jan 2024 | 5 Psst ... wanna jailbreak ChatGPT? Thousands of malicious prompts for sale Turns out it's pretty easy to make the model jump its own guardrails AI + ML25 Jan 2024 | 24 China loathes AirDrop so much it's publicized an old flaw in Apple's P2P protocol Infosec academic suggests Beijing's warning that iThing owners aren't anonymous deserves attention outside the great firewall too Security15 Jan 2024 | 13 Microsoft sheds some light on Russian email heist - and how to learn from Redmond's mistakes Step one, actually turn on MFA CSO27 Jan 2024 | 17 Two more Citrix NetScaler bugs exploited in the wild Just when you thought you had recovered from Bleed Cyber-crime18 Jan 2024 | 2 Slug slimes aerospace biz AerCap with ransomware, brags about 1TB theft Loanbase admits massive loss of customer data to thieves, too Security22 Jan 2024 | 1 Trickbot malware scumbag gets five years for infecting hospitals, businesses Most of the crew still at large Cyber-crime25 Jan 2024 | 8 CISA boss swatted: 'While my own experience was certainly harrowing, it was unfortunately not unique' Election officials, judges, politicians, and gamers are in swatters' crosshairs Cyber-crime23 Jan 2024 | 46 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * T's & C's * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js