KV Botnet is a covert botnet of compromised small-office/home-office routers and firewall devices, principally end-of-life Cisco and Netgear equipment. It was used as relay infrastructure to proxy and obscure the origin of follow-on intrusions, including activity directed at U.S. critical infrastructure and foreign victims. U.S. authorities and multiple security organizations associated the botnet with the PRC-linked Volt Typhoon threat actor and assessed its use as supporting espionage and pre-positioning activity against communications, energy, transportation, and water-sector organizations.
KV Botnet malware executes entirely in device memory and does not establish persistence; rebooting an infected device removes it, requiring operators to exploit the device again to restore access. The botnet’s operators conducted large-scale re-exploitation of exposed network devices following disruption efforts, attempting to rebuild command-and-control capacity. In December 2023, the FBI used a court-authorized operation to remove the malware from affected U.S. routers and temporarily block their botnet-control communications without disrupting normal router functionality. Subsequent mitigation and infrastructure-disruption actions substantially degraded the principal KV Botnet cluster by January 2024, although related reconnaissance activity persisted separately.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The article compares the QScan/QTRouter takedown with the disruption of the KV Botnet used by Volt Typhoon in early 2024.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure... APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment... HAFNIUM has operated from leased virtual private servers (VPS) in the United States.
Resource Development: In observed attacks, Volt Typhoon exploits End of Life (EoL) Cisco and NETGEAR SOHO routers to use as proxies for Command and Control infrastructure These devices are infected with the KV Botnet malware
For example, China's Integrity Technology Group controlled and managed the so-called Raptor Train network, which in 2024 infected more than 200,000 devices worldwide, including small office home office (SOHO) routers, internet-connected web cameras and video recorders, plus firewalls and network-attached storage (NAS) devices.
As documented in the malware analysis section of our initial report, the KV malware resides completely in-memory and therefore did not have a persistence mechanism.
KV-botnet: ... a covert data transfer network used by state-sponsored actors based in China to conduct espionage and intelligence activities targeting U.S. critical infrastructure.
We observed a brief but concentrated period of exploitation activity in early December 2023, as the threat actors attempted to re-establish their command and control (C2) structure and return the botnet to working order.
These compromised devices associated with the KV-cluster were chained together to form a covert data transfer network supporting various Chinese state-sponsored actors including Volt Typhoon.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet cited as a prior operational capability used by Volt Typhoon and disrupted by U.S. authorities.
Mentioned only as a comparison example of a campaign using shared external infrastructure; no operational details are provided.
Botnet listed among the top malware families affecting victims in Mexico in 2025.
Botnet malware deployed on compromised SOHO routers and used as an anonymizing relay infrastructure to conceal state-sponsored access and operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.