CISA and FBI issue an emergency advisory on Volt Typhoon. The state-aligned actor is now using

What CISA and the FBI Are Warning About

CISA and the FBI have issued an emergency advisory covering Volt Typhoon, a state-aligned threat actor, and a shift in how it hides inside victim environments. Rather than relying on obvious malware or attacker-controlled infrastructure, the group is increasingly building covert networks out of routers and other edge devices to route command-and-control traffic. The advisory frames this as a change in tradecraft that makes the activity harder to spot, not a new vulnerability in any single product.

The core idea is blending in. Traffic that hops between compromised routers looks like ordinary device-to-device communication, so it rarely trips the alerts that watch for connections to known-bad external hosts. That is the point of a covert router network: it moves the attacker's presence into equipment defenders often treat as plumbing rather than as part of the attack surface.

Why Routers Are the Target

Edge routers sit at the boundary between networks and are frequently under-monitored. They may run outdated firmware, ship with default credentials, or expose management interfaces that were never meant to be reachable. Because these devices are always on and rarely rebooted or inspected, a foothold on them can persist quietly for a long time. Chaining several compromised routers together lets an actor relay traffic through infrastructure that looks legitimate and geographically unremarkable.

This approach also sidesteps a lot of endpoint defense. Security tooling tends to concentrate on servers and workstations, while the router forwarding the traffic is invisible to those agents. Living on the network device itself means the attacker leaves few traces on the systems most teams actually watch.

Practical Steps for Defenders

The advisory points toward hardening and monitoring the edge devices that are usually left alone. The goal is to remove easy footholds and to make unusual router-to-router traffic visible instead of assumed-benign.

  • Inventory every router and edge device, and confirm which management interfaces are exposed and to whom.
  • Replace default or reused credentials, and apply the latest vendor firmware to close known weaknesses.
  • Restrict administrative access to trusted networks and require strong authentication for it.
  • Log and review traffic patterns between network devices, treating unexpected relay behavior as a signal worth investigating.
  • Periodically reboot and inspect edge devices, since some footholds do not survive a clean restart.

What This Shift Means for Detection

Defenders who rely mainly on reputation-based blocking of external addresses will struggle here, because the traffic never leaves for an obviously suspicious destination. Detection has to move toward behavior: which devices are talking to each other, whether those paths make sense for the network's design, and whether a router is doing anything beyond its normal forwarding role.

Treating routers as monitored assets rather than background infrastructure is the practical takeaway. That means bringing edge devices into asset inventories, configuration baselines, and logging pipelines so a compromise stands out against a known-good picture instead of hiding in an ungoverned corner of the network.

Automate Your Content with AI Video Generator

Try it Free →