← Back to all campaigns
ActiveMITRE ATT&CK

KV Botnet Activity

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster. This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.

First observedOct 1, 2022
Last observedJan 1, 2024
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

Volt Typhoon

Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

Volt Typhoon attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

KV Botnet Activity last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

KV Botnet Activity first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

ATT&CK techniques 81

Malware and tools 17

  • VersaMemMalware | Volt Typhoon
  • FRPTool | Volt Typhoon
  • ImpacketTool | Volt Typhoon
  • MimikatzTool | Volt Typhoon
  • NetTool | Volt Typhoon
  • NltestTool | Volt Typhoon
  • PingTool | Volt Typhoon
  • PsExecTool | Volt Typhoon
  • RegTool | Volt Typhoon
  • SysteminfoTool | Volt Typhoon
  • TasklistTool | Volt Typhoon
  • WevtutilTool | Volt Typhoon

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.

Continue investigating

Campaigns with shared actors