U.S. Feds Shut Down China-Linked "KV-Botnet" Targeting SOHO Routers
ID: b11f09a4-2ce8-56b4-851b-ba5656cf251b
STIX ID: report--b11f09a4-2ce8-56b4-851b-ba5656cf251b
Feed Name: The Hacker News
**KV-botnet disruption and national-security implications:** U.S. authorities disrupted the KV-botnet — a network of compromised end-of-life SOHO routers (Cisco, NetGear, DrayTek, Fortinet) used since at least 2022 to anonymize and relay encrypted traffic for China-linked Volt Typhoon and other actors — deleting malware payloads from infected devices temporarily, notifying victims, and prompting CISA guidance for secure-by-design router manufacturing to mitigate reuse of legacy, unpatched devices in nation-state campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
