logo

U.S. Feds Shut Down China-Linked "KV-Botnet" Targeting SOHO Routers

ID: b11f09a4-2ce8-56b4-851b-ba5656cf251b

STIX ID: report--b11f09a4-2ce8-56b4-851b-ba5656cf251b

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2024-02-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**KV-botnet disruption and national-security implications:** U.S. authorities disrupted the KV-botnet — a network of compromised end-of-life SOHO routers (Cisco, NetGear, DrayTek, Fortinet) used since at least 2022 to anonymize and relay encrypted traffic for China-linked Volt Typhoon and other actors — deleting malware payloads from infected devices temporarily, notifying victims, and prompting CISA guidance for secure-by-design router manufacturing to mitigate reuse of legacy, unpatched devices in nation-state campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.