{
  "modified": "2024-10-03T10:11:13.072Z",
  "name": "KV Botnet Activity",
  "description": "[KV Botnet Activity](https://attack.mitre.org/campaigns/C0035) consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. [KV Botnet Activity](https://attack.mitre.org/campaigns/C0035) was used by [Volt Typhoon](https://attack.mitre.org/groups/G1017) to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.(Citation: Lumen KVBotnet 2023) This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.(Citation: DOJ KVBotnet 2024)",
  "aliases": [
    "KV Botnet Activity"
  ],
  "first_seen": "2022-10-01T04:00:00.000Z",
  "last_seen": "2024-01-01T05:00:00.000Z",
  "x_mitre_first_seen_citation": "(Citation: Lumen KVBotnet 2023)",
  "x_mitre_last_seen_citation": "(Citation: DOJ KVBotnet 2024)",
  "x_mitre_deprecated": false,
  "x_mitre_version": "1.0",
  "type": "campaign",
  "spec_version": "2.1",
  "id": "campaign--0c259854-4044-4f6c-ac49-118d484b3e3b",
  "created": "2024-06-10T18:57:09.920Z",
  "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "revoked": false,
  "external_references": [
    {
      "source_name": "mitre-attack",
      "url": "https://attack.mitre.org/campaigns/C0035",
      "external_id": "C0035"
    },
    {
      "source_name": "Lumen KVBotnet 2023",
      "description": "Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.",
      "url": "https://blog.lumen.com/routers-roasting-on-an-open-firewall-the-kv-botnet-investigation/"
    },
    {
      "source_name": "DOJ KVBotnet 2024",
      "description": "US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.",
      "url": "https://www.justice.gov/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical"
    }
  ],
  "object_marking_refs": [
    "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
  ],
  "x_mitre_attack_spec_version": "3.2.0",
  "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
  "x_mitre_domains": [
    "enterprise-attack"
  ]
}