Skip to main content
Mallory
MalwareUsed by 1 actor

KV Botnet

KV Botnet is a botnet malware/infrastructure cluster attributed by U.S. authorities and multiple public reports to the PRC-linked threat actor Volt Typhoon. It consists primarily of compromised small office/home office routers and other internet-connected edge devices used as covert relay and proxy infrastructure to conceal the origin of follow-on intrusions and espionage activity. Reporting states that the botnet was used to support operations against U.S. and foreign victims, including critical infrastructure organizations, and that Volt Typhoon used it as part of broader pre-positioning activity affecting sectors such as communications, energy, transportation, and water. The botnet has also been described as including cameras and routers, and as relying heavily on end-of-life Cisco and NETGEAR devices that no longer received security patches.

High-confidence reporting in the provided content states that KV Botnet malware infected hundreds of privately owned SOHO routers, with the vast majority being Cisco and NETGEAR devices. The malware-enabled botnet was used to route malicious traffic and support espionage operations without the owners’ knowledge. Multiple sources in the content state that Volt Typhoon used compromised Cisco and NETGEAR end-of-life SOHO routers implanted with KV Botnet malware to support operations and to obscure PRC attribution. One report also states that the botnet mainly involved end-of-life Cisco and NetGear routers, while another notes that legacy routers targeted by KV Botnet often lacked protections such as signed firmware enforcement.

The content further states that KV Botnet activity used acquired virtual private servers as control systems for infected devices. A tracked infrastructure cluster referred to as the JDY cluster or JDYFJ Botnet is associated with KV Botnet in the supplied material. Researchers observed infected systems communicating with control servers using a certificate containing the string "jdyfj" beginning in November 2023. Publicly cited infrastructure associated with this activity included 159.203.113[.]25, 174.138.56[.]21, 108.61.132[.]157, 144.202.49[.]189, 45.32.174[.]131, 45.63.60[.]39, 2.58.15[.]30, 66.85.27[.]190, and 172.233.211[.]226. The content also identifies certificate SHA256 2b640582bbbffe58c4efb8ab5a0412e95130e70a587fd1e194fbcd4b33d432cf as associated with some of this infrastructure.

Behaviorally, the supplied ATT&CK-oriented reporting says KV Botnet activity focuses on compromising SOHO network devices to build a botnet, uses multiple Bash scripts during installation, supports command execution via Bash, uses libevent to manage events, and terminates processes whose paths reference tools such as busybox, wget, curl, tftp, telnetd, or lua unless the string "bioset" is present. The content also states that the malware/control activity used custom or non-standard command-and-control approaches and that VPS infrastructure served as control systems for infected devices.

In December 2023, the FBI conducted a court-authorized disruption operation against KV Botnet in the United States. According to the provided content, the operation remotely deleted KV Botnet malware from affected routers and temporarily severed communications with botnet controllers without affecting legitimate router functions or collecting content information. Authorities warned that the mitigation was temporary and that restarting a router without additional remediation could leave it vulnerable to reinfection. The FBI strongly encouraged replacement of end-of-life SOHO routers because the underlying devices remained vulnerable to future exploitation by Volt Typhoon and other actors. Subsequent reporting in the content states that the botnet’s control infrastructure persisted and migrated across hosting providers after the disruption.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Volt Typhoon

The hackers, known to the private sector as “Volt Typhoon,” used privately-owned SOHO routers infected with the “KV Botnet” malware to conceal the PRC origin of further hacking activities directed against U.S. and other foreign victims.

via us department of justicejustice.gov
MITRE ATT&CK

Techniques & procedures

9 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.003Virtual Private ServerEvidence1

APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure... APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment... HAFNIUM has operated from leased virtual private servers (VPS) in the United States.

T1584Compromise InfrastructureEvidence2

For example, China's Integrity Technology Group controlled and managed the so-called Raptor Train network, which in 2024 infected more than 200,000 devices worldwide, including small office home office (SOHO) routers, internet-connected web cameras and video recorders, plus firewalls and network-attached storage (NAS) devices.

T1584.005BotnetEvidence9

A December 2023 court-authorized operation has disrupted a botnet of hundreds of U.S.-based small office/home office (SOHO) routers hijacked by People’s Republic of China (PRC) state-sponsored hackers. The hackers, known to the private sector as “Volt Typhoon,” used privately-owned SOHO routers infected with the “KV Botnet” malware to conceal the PRC origin of further hacking activities directed against U.S. and other foreign victims.

T1584.008Network DevicesEvidence3

T1584.008 Compromise Infrastructure: Network Devices — Devices are compromised and added to botnets

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence3

The vast majority of routers that comprised the KV Botnet were Cisco and NetGear routers that were vulnerable because they had reached “end of life” status; that is, they were no longer supported through their manufacturer’s security patches or other software updates.

Discovery

1 technique
T1120Peripheral Device DiscoveryEvidence1
TacticDiscovery

Volt Typhoon ... has primarily targeted outdated Cisco and Netgear routers to be part of its KV Botnet.

T1071Application Layer ProtocolEvidence1

On 14 November 2023, infected systems from this cluster were seen communicating with new control servers with a different certificate containing “jdyfj”... The Censys research team has identified three hosts currently leveraging this certificate.

T1090ProxyEvidence4

A majority of China-linked threat actors are using compromised routers and IoT devices worldwide, turning this gear into proxy networks to carry out further intrusions, steal sensitive data, and disrupt victim organizations’ operations.

T1090.003Multi-hop ProxyEvidence8

The hackers, known to the private sector as “Volt Typhoon,” used privately-owned SOHO routers infected with the “KV Botnet” malware to conceal the PRC origin of further hacking activities directed against U.S. and other foreign victims.

INDICATORS OF COMPROMISE

IOCs tracked for this family

11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
10 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
1 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
ip.v4●●●●●●●●●●●●View more in app1 year ago
ip.v4●●●●●●●●●●●●View more in app1 year ago
ip.v4●●●●●●●●●●●●View more in app1 year ago
ip.v4●●●●●●●●●●●●View more in app1 year ago
hash.sha256●●●●●●●●●●●●View more in app1 year ago
ip.v4●●●●●●●●●●●●View more in app1 year ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching11

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping9

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.