KV Botnet is a covert botnet and relay network composed primarily of compromised small-office/home-office routers, firewall appliances, and some IoT devices. It has been publicly attributed to the China-linked threat actor Volt Typhoon and has been used to obscure the origin of follow-on intrusion activity, support covert data transfer, and enable espionage operations targeting U.S. critical infrastructure sectors including communications, energy, water, and transportation. The botnet has been described as relying heavily on end-of-life Cisco and Netgear devices, while related activity also involved other edge and embedded devices such as Axis cameras and DrayTek routers.
The malware associated with KV Botnet is notable for residing entirely in memory and lacking a persistence mechanism. Power cycling an infected device removes the malware, forcing operators to re-exploit exposed devices to regain access. Following a U.S. court-authorized disruption in December 2023, operators attempted to rapidly rebuild the network through concentrated re-exploitation of vulnerable internet-exposed edge devices. The botnet’s infrastructure included leased virtual private servers used as control systems for infected devices, and researchers tracked associated clusters used for scanning, reconnaissance, and relay operations.
KV Botnet functioned primarily as covert operational infrastructure rather than as a conventional monetization-focused botnet. Its role was to provide proxying and obfuscation for state-sponsored activity, allowing operators to blend malicious traffic with legitimate traffic from compromised consumer and small-business equipment. Reporting also links the broader ecosystem around KV Botnet to reconnaissance-focused clusters such as JDY, which supported large-scale service discovery and vulnerability targeting. Law-enforcement disruption significantly degraded the main KV cluster by early 2024, although related infrastructure and associated reconnaissance activity persisted beyond the initial takedown.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
On December 13, 2023, Black Lotus Labs reported our findings on the KV-botnet, a covert data transfer network used by state-sponsored actors based in China to conduct espionage and intelligence activities targeting U.S. critical infrastructure.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
APT-C-36 has incorporated virtual private servers (VPS) into its operational infrastructure... APT42 has used anonymized infrastructure and Virtual Private Servers (VPSs) to interact with the victim’s environment... HAFNIUM has operated from leased virtual private servers (VPS) in the United States.
For example, China's Integrity Technology Group controlled and managed the so-called Raptor Train network, which in 2024 infected more than 200,000 devices worldwide, including small office home office (SOHO) routers, internet-connected web cameras and video recorders, plus firewalls and network-attached storage (NAS) devices.
As documented in the malware analysis section of our initial report, the KV malware resides completely in-memory and therefore did not have a persistence mechanism.
KV-botnet: ... a covert data transfer network used by state-sponsored actors based in China to conduct espionage and intelligence activities targeting U.S. critical infrastructure.
We observed a brief but concentrated period of exploitation activity in early December 2023, as the threat actors attempted to re-establish their command and control (C2) structure and return the botnet to working order.
These compromised devices associated with the KV-cluster were chained together to form a covert data transfer network supporting various Chinese state-sponsored actors including Volt Typhoon.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet listed among the top malware families affecting victims in Mexico in 2025.
Botnet malware deployed on compromised SOHO routers and used as an anonymizing relay infrastructure to conceal state-sponsored access and operations.
A botnet cluster previously hosting or associated with JDY before U.S. government disruption in early 2024.
KV-botnet is the larger botnet cluster within which JDY was initially identified before JDY evolved into an independent reconnaissance capability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.