C0035: KV Botnet Activity
KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]
Security context for executives and security teams
C0035: KV Botnet Activity describes [KV Botnet Activity](https://attack.mitre.org/campaigns/C0035) consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. [KV Botnet Activity](https://attack.mitre.org/campaigns/C0035) was used by [Volt Typhoon](https://attack.mitre.org/groups/G1017) to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Gua...
Executive priority
C0035: KV Botnet Activity is an official MITRE ATT&CK campaign. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate C0035: KV Botnet Activity by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether C0035: KV Botnet Activity appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
KV Botnet Activity
KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster.[1] This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.[2]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1685 | Disable or Modify Tools | KV Botnet Activity used various scripts to remove or disable security tools, such as |
| Enterprise | T1016 | System Network Configuration Discovery | KV Botnet Activity gathers victim IP information during initial installation stages.[1] |
| Enterprise | T1057 | Process Discovery | Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.[1] |
| Enterprise | T1584.008 | Network DevicesSub-technique | KV Botnet Activity focuses on compromise of small office-home office (SOHO) network devices to build the subsequent botnet.[1] |
| Enterprise | T1105 | Ingress Tool Transfer | KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.[1] |
| Enterprise | T1583.003 | Virtual Private ServerSub-technique | KV Botnet Activity used acquired Virtual Private Servers as control systems for devices infected with KV Botnet malware.[1] |
| Enterprise | T1055.009 | Proc MemorySub-technique | KV Botnet Activity final payload installation includes mounting and binding to the |
| Enterprise | T1095 | Non-Application Layer Protocol | KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication.[1] |
| Enterprise | T1059.004 | Unix ShellSub-technique | KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell.[1] |
| Enterprise | T1222.002 | Linux and Mac PermissionsSub-technique | KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines.[1] |
| Enterprise | T1036.004 | Masquerade Task or ServiceSub-technique | KV Botnet Activity installation steps include first identifying, then stopping, any process containing |
| Enterprise | T1070.004 | File DeletionSub-technique | KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.[1] |
| Enterprise | T1573 | Encrypted Channel | KV Botnet Activity command and control activity includes transmission of an RSA public key in communication from the server, but this is followed by subsequent negotiation stages that represent a form of handshake similar to TLS negotiation.[1] |
| Enterprise | T1036 | Masquerading | KV Botnet Activity involves changing process filename to |
| Enterprise | T1564.013 | Bind MountsSub-technique | KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory.[1] |
| Enterprise | T1571 | Non-Standard Port | KV Botnet Activity generates a random port number greater than 30,000 to serve as the listener for subsequent command and control activity.[1] |
| Enterprise | T1083 | File and Directory Discovery | KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| Enterprise | T1082 | System Information Discovery | KV Botnet Activity includes use of native system tools, such as |
| Enterprise | T1518.001 | Security Software DiscoverySub-technique | KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices.[1] |
| Enterprise | T1546 | Event Triggered Execution | KV Botnet Activity involves managing events on victim systems via |
Groups, software, and campaigns
G1017: Volt Typhoon
Volt Typhoon is a People's Republic of China (PRC) state-sponsored actor that has been active since at least 2021, primarily targeting critical infrastructure organizations in the US and its territories including Guam. Volt Typhoon's targeting and pattern of behavior have been assessed as pre-positioning to enable lateral movement to operational technology (OT) assets for potential destructive or disruptive attacks. Volt Typhoon has emphasized stealth in operations using web shells, living-off-the-land (LOTL) binaries, hands on keyboard activities, and stolen credentials.[1][2][3][4]. The group has leveraged compromised SOHO routers to proxy command and control traffic and obscure its infrastructure, activity associated with the KV botnet.[5].
Reporting indicates a separate initial access cluster, SYLVANITE, has been observed exploiting internet-facing edge devices and transferring access to Volt Typhoon, also tracked as VOLTZITE, for follow-on operations. [6]
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 1.0 | Current bundle | e04e1a4a2e84… | ||
| 19.1 | 1.0 | Older bundle | 3919978e3189… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]Lumen KVBotnet 2023
Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.
Open source URL - [2]DOJ KVBotnet 2024
US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.
Open source URL - [3]mitre-attackC0035Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
