Chinese botnet containing hundreds of end-of-life Cisco and Netgear routers disrupted by US government

The US government has successfully disrupted a botnet created by a Chinese hacking group known as Volt Typhoon. The botnet was responsible for cyber attacks on critical national infrastructure (CNI) organizations in the US and other countries.

According to a security alert from the US Office of Public Affairs, Volt Typhoon had hijacked hundreds of small-office/home office routers from Cisco and Netgear brands across America. These routers were infected with the KV Botnet malware, which allowed the hackers to disguise themselves as the source of subsequent attacks on CNI organizations in the US and overseas.

In May 2025, the UK National Cyber Security Centre (NCSC) and other international intelligence agencies issued guidance to CNI operators, urging them to take preventive measures against Volt Typhoon’s attempts to access and hide on their systems.

The botnet takedown was authorized by a US court in December 2023. It involved removing the malware from the affected routers and taking additional steps to block other devices from communicating with the botnet. FBI Director Christopher Wray stated that Volt Typhoon’s actions posed a threat to sectors such as communications, energy, transportation, and water, and emphasized the FBI’s commitment to combating such threats. Attorney General Merrick Garland also highlighted the Justice Department’s proactive approach to protecting the nation’s CNI.

Deputy Attorney General Lisa Monaco emphasized the Department of Justice’s use of various tools to disrupt national security threats in real-time. She also underscored the importance of partnership with the private sector, as victim reporting is crucial in fighting cyber crime.

Sandra Joyce, Vice-President of Intelligence at Mandiant, a cyber threat intelligence company owned by Google, explained that Volt Typhoon’s methods make it challenging to detect their activity. They use compromised systems to blend in with normal network activity and continuously change the source of their activity. Despite the difficulties, Joyce believes tracking and identifying their actions is not impossible.

Unlock your business potential with our expert guidance. Get in touch now!

silenced-gagged-secret-Michael-adobe.jpg

Post Office Criticized for Deleting Comments on IT Scandal from Social Media

Whitehouse-fotolia-scaled.jpg

When Leaders Overlook Cybersecurity Guidelines, the Entire System Suffers

Police-crime-2-adobe.jpg

Police Digital Service Board Director Resigns Months After CISO’s Departure

surveillance-CCTV-facial-recognition-Gorodenkoff-adobe.jpg

Essex Police Reveals ‘Incoherent’ Facial Recognition Evaluation

chatbot-1-fotolia.jpg

Podcast: RSA 2025 – Navigating AI Risks and the CISO’s Role

hybrid-cloud-storage-fotolia.jpg

Trump’s Visit Strengthens Saudi Arabia’s AI Initiatives

threat-management-fotolia.jpg

Security Tests Uncover Major Vulnerability in Government’s One Login Digital ID System