After FBI Takedown, KV-Botnet Operators Shift Tactics in Attempt to Bounce Back
ID: bcb2c071-fa57-5a5a-aee0-fc9afe0e8bbb
STIX ID: report--bcb2c071-fa57-5a5a-aee0-fc9afe0e8bbb
Feed Name: The Hacker News
**KV-botnet:** The report describes a globally distributed botnet of compromised SOHO routers and network devices (KV and JDY clusters, and a related x.sh cluster) attributed to PRC-linked actors supporting Volt Typhoon; it details activity observed since 2022, a U.S. court-authorized disruption in December 2023 that reduced active bots, observed exploitation spikes and operator restructuring, affected device families (NETGEAR, Cisco RV320/325, Axis cameras, DrayTek), and recommended mitigation steps such as patching, device replacement, reboots, and monitoring for large outbound transfers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
