KV Botnet is a Linux and IoT-focused botnet activity cluster associated with the compromise of small office/home office network edge devices, particularly SOHO routers and similar appliances, to build a covert proxy and command-and-control layer. The activity has been publicly linked to infrastructure used in support of Volt Typhoon operations. Infected devices have been used as intermediary nodes and controlled through acquired virtual private servers. The botnet’s tradecraft emphasizes lightweight shell-based deployment and operational flexibility on embedded systems. It uses multiple Bash scripts during installation and supports remote command execution through a Bash shell in later stages. Observed behavior includes system and environment discovery, such as collecting device architecture and other host information with native utilities, enumerating files from common executable directories, and identifying running processes and installed tooling on compromised devices. A defining characteristic of KV Botnet is aggressive defense evasion and competitive exclusion on infected devices. Installation and follow-on scripts identify, remove, or disable security tools and other IoT malware already present on the host. The malware has also been observed terminating or suppressing processes associated with administrative and transfer utilities, and later infection stages rename process metadata to appear more benign or less attributable. This combination of discovery, shell execution, process manipulation, and security-tool removal is consistent with maintaining durable control over constrained edge devices while minimizing interference from defenders or rival botnets. Known reporting treats KV Botnet Activity as a distinct campaign or activity cluster rather than a traditional named intrusion set. It is most widely recognized as KV Botnet and is notable for enabling stealthy proxying and botnet operations through compromised SOHO infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Uses scripts to remove or disable security tools and competing botnet-related tooling on victim devices.
Botnet activity cluster gathered filename lists from key Linux binary directories during final-stage execution.
Referenced as an activity cluster involving removal of security tools from compromised devices.
Using deployment scripts to identify security-tool and rival-botnet processes for disabling during installation.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.