Resurgence of KV Botnet Linked to Chinese State Actors
ID: b964dadb-dfbe-5dd0-95fd-2ffed6619daf
STIX ID: report--b964dadb-dfbe-5dd0-95fd-2ffed6619daf
Feed Name: ThreatCluster
Threat Score
Chinese-linked operators have revived the KV botnet, exploiting end-of-life SOHO routers and IoT devices (notably NetGear ProSAFE models) to re-establish covert C2 and reconnaissance infrastructure; Lumen reports ~1,500 compromised devices in the JDY cluster with targeting focused on U.S. military and critical infrastructure, though the articles omit specific IOCs or CVEs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
