Not every router attack is about stealing from the person behind the router. Some are about using it. Volt Typhoon, a Chinese state-sponsored group, spent years quietly taking over ordinary home and small-office routers, not to rob their owners, but to hide behind them while it burrowed into US critical infrastructure. The owners had no idea their equipment was part of it.
It is a different kind of edge-device risk from a credential-harvesting campaign, and arguably a more sobering one, because it shows how an unmanaged router in someone’s home can be quietly conscripted into a geopolitical operation.
What happened
Volt Typhoon, a group US agencies attribute to the Chinese state, was found to be running a network of compromised routers known as the KV Botnet, first disclosed by researchers at Lumen’s Black Lotus Labs in December 2023. In January 2024, the US Department of Justice and FBI announced a court-authorised operation that removed the malware from hundreds of infected routers. The FBI Director described the wider Volt Typhoon threat as one of the defining cyber threats of this era.
What made these routers vulnerable
The vast majority of the compromised devices were Cisco and NETGEAR routers that had reached end of life. That is the detail that matters. End of life means the manufacturer has stopped issuing security updates, so any known flaw stays open permanently, with no patch ever coming. Researchers examining the botnet found models such as Cisco RV320s, NETGEAR ProSAFE devices and DrayTek Vigor routers, the kind of small-office and home-office kit that quietly keeps running for years after support ends. For hardware like that, as one researcher observed, the realistic fix is to rip it out and replace it.
Why a router is such a useful hiding place
Volt Typhoon did not use these routers to attack their owners. It used them as cover. By routing its operations through ordinary residential and small-business devices near its real targets, the group’s traffic blended in with normal local activity, which made it far harder for defenders to spot or block than traffic from a known malicious server. The aim, according to US officials, was to pre-position quietly inside critical infrastructure, establishing footholds that could be used in a future crisis.
Why this is hard to defend against
Router forensics are often thin. Logs may not exist, the devices sit outside any routine patching cycle, and nobody is monitoring them. Even after law enforcement cleans a botnet, the underlying hardware remains vulnerable, so abandoned devices can simply be re-compromised. Volt Typhoon demonstrated exactly that: within months of the January 2024 takedown it had begun rebuilding, again using end-of-life Cisco and NETGEAR devices.
Why it matters for organisations
It is tempting to file nation-state pre-positioning under someone else’s problem. But the devices being used are the same ones your staff connect through from home and small offices, and the reason they are attractive is the reason they are a risk to you: they are unmanaged, unpatched and invisible to the organisation. A router good enough to conceal a state actor is a router you have no control over, carrying your people’s traffic.
How Loxada addresses this
Loxada Secure removes the end-of-life problem at its root. Every device runs Loxada’s own firmware rather than the manufacturer’s, and that firmware is maintained and updated centrally, so there is no point at which security patches simply stop arriving. The managed router replaces the unknown local device as the network edge your people work from, centrally controlled rather than left to age quietly in a cupboard.
Loxada does not claim to detect botnet activity or monitor traffic, and it is not a replacement for network monitoring. What it does is take the unmanaged, unsupported router, the exact class of device Volt Typhoon relied on, out of the picture.
Common questions
Who is Volt Typhoon? A cyber group US agencies attribute to the Chinese state, known for pre-positioning inside critical infrastructure using compromised routers and living-off-the-land techniques rather than conventional malware.
What does end of life mean for a router? It means the manufacturer no longer issues security updates for that model, so known vulnerabilities stay unpatched permanently and the device becomes progressively easier to exploit.
Was the data on these networks stolen? The routers were used mainly as concealment and staging infrastructure rather than to steal the owners’ data, though compromise of any device on the path to sensitive systems is a serious risk in itself.
Does rebooting or resetting fix it? It can remove the current infection, but an end-of-life device stays vulnerable and can be re-compromised. The durable answer is managed, updatable firmware, or replacing unsupported hardware.
Sources: US Department of Justice and FBI, January 2024; CISA advisory AA24-038A; Lumen Black Lotus Labs. Volt Typhoon is attributed to the Chinese state.