Overview
KV Botnet Activity (MITRE ATT&CK ID C0035) consisted of exploitation of primarily “end-of-life” small office/home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek, per MITRE’s campaign profile. MITRE documents this activity as used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunications companies and entities based on the US territory of Guam. MITRE notes that while the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster. Per MITRE’s citations, this botnet was disrupted by US law enforcement entities in early 2024, after periods of activity from October 2022 through January 2024.
Timeline
Per MITRE ATT&CK’s ingested data, this campaign’s documented activity window runs from October 2022 to January 2024, ending with the documented US law-enforcement disruption action.
Actors involved (per MITRE ATT&CK relationship data)
MITRE ATT&CK attributes this campaign to Volt Typhoon — consistent with Volt Typhoon’s broader documented emphasis on living-off-the-land techniques and compromised edge infrastructure for stealth, as detailed in its own group profile.
What we don’t have
MITRE’s ingested data doesn’t include the specific technical details of the January 2024 law-enforcement disruption action beyond noting it occurred. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no confirmation of whether related botnet infrastructure (the noted overlapping “JDY cluster”) was affected by the same disruption action.
Frequently Asked Questions
What was KV Botnet Activity? A campaign, per MITRE ATT&CK, in which Volt Typhoon exploited end-of-life SOHO routers (Cisco, NETGEAR, DrayTek) to obfuscate connectivity to US critical infrastructure victims, active October 2022 to January 2024.
Who was behind the KV Botnet? Volt Typhoon, per MITRE ATT&CK’s relationship data.
Was the KV Botnet shut down? Per MITRE’s citations, yes — US law enforcement entities disrupted the botnet in early 2024.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), campaign ID C0035, aggregated August 28, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more campaign profiles.