Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
botnet-infrastructurestate-sponsored-espionagecritical-infrastructure-threatembedded-device-vulnerability

US Disrupts Volt Typhoon KV Botnet Built on Compromised SOHO Routers

Updated 28d agoFirst seen May 25, 20266 sources

The U.S. Department of Justice said a court-authorized FBI operation disrupted the KV Botnet, a network of hundreds of compromised small office and home office routers that the PRC-linked group Volt Typhoon used to mask follow-on intrusions against U.S. and foreign targets, including critical infrastructure. Officials said the botnet relied heavily on end-of-life Cisco and NetGear devices, and that the FBI removed malware from affected U.S.-based routers and severed communications with botnet controllers without disrupting legitimate router functions or collecting content. The government tied the activity to broader Chinese pre-positioning against sectors including communications, energy, transportation, and water, while warning that unsupported devices remain vulnerable to reinfection unless replaced or fully remediated.

Reporting on the takedown said the action mirrored earlier U.S. botnet disruptions such as the 2022 operation against Cyclops Blink, the Sandworm/GRU botnet that abused WatchGuard and ASUS devices as command-and-control infrastructure. Subsequent research from Censys found that KV Botnet control infrastructure evolved after the December 2023 disruption, with operators in the JDY cluster largely retaining the same infrastructure patterns while shifting hosting providers and continuing activity linked to vulnerable Cisco RV320/RV325 routers. The researchers said the botnet’s comparatively exposed infrastructure did not fully match Volt Typhoon’s usual stealthy tradecraft, raising questions about whether the KV Botnet was operated directly by Volt Typhoon or by a separate but related actor.

Share:
US Disrupts Volt Typhoon KV Botnet Built on Compromised SOHO Routers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jan 16, 20251y ago

Censys questions whether KV Botnet is truly operated by Volt Typhoon

On 2025-01-16, Censys published analysis of the JDY/KV Botnet's 2024 infrastructure evolution and argued that its relatively exposed, unsophisticated operational behavior did not fully match Volt Typhoon's known stealthy tradecraft. The researchers suggested the botnet may be operated by a separate party despite public attribution to Volt Typhoon.

Jan 31, 20242y ago

U.S. publicly announces KV Botnet takedown

On 2024-01-30/31, the DOJ and FBI publicly disclosed the December 2023 disruption of the KV Botnet, warning that many end-of-life Cisco and NetGear routers remained vulnerable to reinfection unless replaced or mitigated. The announcement also said the FBI was notifying affected owners and continuing to investigate Volt Typhoon intrusions.

Dec 6, 20233y ago

FBI disrupts KV Botnet used by Volt Typhoon

In December 2023, the U.S. government conducted a court-authorized operation to remove KV Botnet malware from hundreds of compromised U.S.-based SOHO routers and temporarily cut communications with botnet controllers. Officials said the PRC-linked Volt Typhoon group used the botnet to conceal follow-on intrusions against critical infrastructure and other targets.

Nov 14, 20233y ago

JDY/KV Botnet control servers appear with 'jdyfj' certificate

Beginning in November 2023, researchers observed new control servers associated with the JDY cluster using a certificate containing the string "jdyfj." Later analysis linked this infrastructure to the KV Botnet ecosystem tied to Volt Typhoon activity.

Mar 22, 20224y ago

DOJ disrupts Sandworm's Cyclops Blink botnet

In March 2022, the Justice Department and FBI carried out a court-authorized operation to copy and remove Cyclops Blink malware from vulnerable firewall devices used as command-and-control infrastructure and to close management ports used by Sandworm. The action severed Russian GRU control over thousands of infected devices, while victim notification and remediation efforts continued.

Feb 23, 20224y ago

Agencies publicly identify Cyclops Blink malware and Sandworm ties

On 2022-02-23, the UK NCSC, CISA, the FBI, and the NSA issued a joint advisory identifying Cyclops Blink malware, attributing it to Sandworm/GRU, and warning that it targeted WatchGuard and ASUS network devices. Vendors also began publishing detection and remediation guidance.

KV Botnet operators migrate infrastructure after disruption

By April 2024, researchers assessed that some JDY/KV Botnet servers had been brought online in response to the FBI disruption and were later migrated again, largely by changing hosting providers rather than overhauling the infrastructure. This showed the botnet's control infrastructure persisted after the takedown.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.