U.S. authorities disrupted the China-linked KV botnet by remotely removing malware from infected U.S.-based small-office and home-office routers and firewalls, a network the government said had been used to conceal intrusions targeting critical infrastructure. Reporting from Lumen’s Black Lotus Labs described the botnet as active since at least 2022 and split into a broad JDY scanning cluster and a more selective KV cluster used for hands-on-keyboard operations through compromised edge devices including Cisco RV320/RV325, NETGEAR ProSAFE, DrayTek Vigor routers, and later Axis IP cameras. Lumen linked the activity to Volt Typhoon, citing overlapping infrastructure, relay-node behavior, Guam-related targeting patterns, and stealth techniques such as in-memory execution, artifact deletion, process masquerading, and covert tunneling via manipulated iptables rules and high ports.
After the FBI’s court-authorized action in December 2023, the operators rapidly tried to rebuild the botnet by re-exploiting exposed devices, with Lumen observing attempts against roughly 2,100 NETGEAR ProSAFE systems in three days as well as renewed activity involving Cisco, DrayTek, and Axis devices. Lumen said mitigation and null-routing weakened the main KV cluster, while the JDY cluster continued operating with reduced capacity; later Censys analysis found the botnet’s command-and-control infrastructure remained unusually stable despite public exposure and law-enforcement action, changing mainly through hosting-provider migration. Censys also noted that the persistence and comparatively unsophisticated management of the infrastructure raised questions about whether the same operators directly controlled both the KV botnet and Volt Typhoon’s more stealthy intrusion activity.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
30 events from the most recent confirmed update back to the earliest known activity.
Censys identified host 172.233.211[.]226 using the same JDY-related certificate beginning on 25 November 2024 on Akamai Connected Cloud in Singapore.
Censys identified hosts 2.58.15[.]30 and 66.85.27[.]190 using the current JDY-related certificate beginning on 16 April 2024.
Censys indicates the JDY-related infrastructure migrated again in April 2024 to hosts carrying the same certificate on new providers.
On February 7, 2024, Black Lotus Labs published a follow-up report describing the botnet's recovery attempts after the FBI disruption and Lumen mitigation activity.
Lumen again null-routed JDY-related router proxy servers on January 12, 2024.
Lumen assessed the backup KV-related servers remained active until at least January 3, 2024.
By mid-January 2024, the number of bots communicating with the JDY router proxy server had fallen from around 1,500 to about 650, though the cluster remained operational.
Lumen reported that it had not detected any net new KV cluster command-and-control servers during January 2024.
In early January 2024, Lumen null-routed newly identified KV infrastructure to impede reinfection efforts.
Censys scans indicate hosts 45.32.174[.]131 and 45.63.60[.]39 began using the JDY-related certificate on 28 December 2023, likely in response to law-enforcement disruption.
Lumen null-routed JDY-related router proxy servers on December 13, 2023 as part of mitigation efforts.
On December 13, 2023, Black Lotus Labs publicly reported on KV-botnet, describing its KV and JDY clusters, malware behavior, and overlap with Volt Typhoon activity.
From December 8 to December 11, 2023, KV-botnet operators targeted about 2,100 NETGEAR ProSAFE devices in an effort to restore command-and-control after the disruption.
Lumen identified a secondary or backup set of KV-related servers that became operational around December 5, 2023.
On December 5, 2023, Lumen observed exploitation that infected more than 170 NETGEAR ProSAFE devices.
In December 2023, the FBI conducted a court-authorized disruption of the KV Botnet by remotely uninstalling malware from infected U.S. systems; the action did not directly affect the botnet's control infrastructure.
On November 29–30, 2023, Lumen observed a new wave of exploitations against Axis IP cameras, including models M1045-LW, M1065-LW, and P1367-E.
Censys historical records show host 159.203.113[.]25 using the JDY-related certificate beginning on 18 November 2023 on DigitalOcean.
Censys historical records show host 174.138.56[.]21 using the JDY-related certificate beginning on 17 November 2023 on DigitalOcean.
Censys historical records show JDY-related hosts 108.61.132[.]157 and 144.202.49[.]189 using the "jdyfj" certificate beginning on 15 November 2023 on Choopa.
On 14 November 2023, infected JDY-cluster systems were observed communicating with new control servers using a different certificate containing the string "jdyfj."
In mid-November 2023, Lumen observed the actor remodel the botnet infrastructure.
Lumen reported that KV-botnet bots interacted with a European renewable energy firm from August through November 2023.
Beginning in August 2023, Lumen observed an uptick in exploitation activity to add new KV-botnet bots.
Lumen observed a decline in KV-botnet operations in June and early July 2023 after U.S. government agencies and partners publicly disclosed Volt Typhoon on May 24, 2023.
Lumen said telemetry showed a third activity cluster called x.sh had existed since at least January 2023.
Lumen reported the JDY cluster peaked in September 2022, adding about 1,350 new bots that month.
From August 2022 through May 2023, Lumen observed similar techniques against an ISP, two telecommunications firms, and a U.S. territorial government entity in Guam, supporting overlap with Volt Typhoon operations.
From July 2022 through February 2023, Lumen observed overlap between NETGEAR ProSAFE relay nodes in the KV-botnet and networks compromised by Volt Typhoon.
Lumen assessed the KV-botnet had been active since at least February 2022 as a covert data-transfer network using compromised SOHO routers and firewalls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
censys.com
Open sourceblog.lumen.com
Open sourceblog.lumen.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.