logo

After FBI Takedown, KV-Botnet Operators Shift Tactics in Attempt to Bounce Back

ID: bcb2c071-fa57-5a5a-aee0-fc9afe0e8bbb

STIX ID: report--bcb2c071-fa57-5a5a-aee0-fc9afe0e8bbb

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-02-07

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

**KV-botnet:** The report describes a globally distributed botnet of compromised SOHO routers and network devices (KV and JDY clusters, and a related x.sh cluster) attributed to PRC-linked actors supporting Volt Typhoon; it details activity observed since 2022, a U.S. court-authorized disruption in December 2023 that reduced active bots, observed exploitation spikes and operator restructuring, affected device families (NETGEAR, Cisco RV320/325, Axis cameras, DrayTek), and recommended mitigation steps such as patching, device replacement, reboots, and monitoring for large outbound transfers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.