logo

Resurgence of KV Botnet Linked to Chinese State Actors

ID: b964dadb-dfbe-5dd0-95fd-2ffed6619daf

STIX ID: report--b964dadb-dfbe-5dd0-95fd-2ffed6619daf

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

...
...

Chinese-linked operators have revived the KV botnet, exploiting end-of-life SOHO routers and IoT devices (notably NetGear ProSAFE models) to re-establish covert C2 and reconnaissance infrastructure; Lumen reports ~1,500 compromised devices in the JDY cluster with targeting focused on U.S. military and critical infrastructure, though the articles omit specific IOCs or CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.