HomeSecurityKV-Botnet Operators Try to Rebound After FBI Actions

KV-Botnet Operators Attempt to Rebound After FBI Actions

The attackers behind the KV-botnet are making changes to their malicious network, following actions by US law enforcement authorities to neutralize its activity.

FBI KV-Botnet

The KV-botnet is a network of compromised office and home office (SOHO) routers and firewall devices, with a specific cluster acting as a covert system for other Chinese state-sponsored actors, including Volt Typhoon (also known as Bronze Silhouette, Insidious Taurus, or Vanguard Panda).

The KV-botnet has been active since at least February 2022 and includes two main subgroups, KV and JDY, with the latter being used primarily to scan potential targets for reconnaissance.

See also: FritzFrog botnet: It's back and exploits Log4Shell and PwnKit vulnerabilities

Last month, the US government announced a court-mandated effort to eliminate the KV cluster, which is typically reserved for manual operations against high- profile, selected after scanning through the JDY sub-group.

Now, security researchers have discovered that the JDY cluster remained dormant for about fifteen days after the operation by US authorities.

In mid-December 2023, we observed this cluster of activity with approximately 1,500 active bots ,” said security researcher Ryan English. “ When we tested the size of this cluster in mid-January 2024, its size had decreased to approximately 650 bots .”

Since the takedown actions began with a signed warrant issued on December 6, 2023, it is likely that the FBI began transmitting commands to routers located in the US after that date to remove the botnet payload and prevent them from being re-infected.

We observed that the KV-botnet operators are beginning to restructure, performing eight consecutive hours of activity on December 8, 2023, almost ten hours of operation the next day on December 9, 2023, followed by one hour on December 11, 2023, ” Lumen said

During this four-day period, there was interaction with 3,045 unique IP addresses associated with NETGEAR ProSAFE (2,158), Cisco RV320/325 (310), Axis IP cameras (29), DrayTek Vigor routers (17), and other unidentified devices (531).

See also: Bigpanzi hackers: Their botnet targets Android TV boxes

Also, in early December 2023, a huge increase in exploit attempts from the payload server was observed, indicating possible attempts by attackers to re-exploit devices.

KV-Botnet Operators Attempt to Rebound After FBI Actions

The operators of the KV-botnet perform their own reconnaissance and targeting while supporting multiple groups such as Volt Typhoon. Interestingly, the timestamps associated with the bots’ exploitation correlate with working hours in China.

Our telemetry shows that there were administrative connections to known payload servers from IP addresses associated with China Telecom,” said Danny Adamitis, principal information security engineer at Black Lotus Labs.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, the US Department of Justice described the botnet as being controlled by “hackers funded by the People’s Republic of China (PRC).”

There is also evidence that the attackers created a third related, but separate botnet cluster named x.sh, which consists of infected Cisco routers.

See also: AndroxGh0st malware botnet steals AWS, Azure, Office 365 credentials

Protection against botnet malware

To protect yourself from KV-Botnet, it is important to keep your device's software and operating system up to date. attacks exploit known vulnerabilities that have been fixed in more recent versions of the software (as is the case in this case).

Additionally, it is important to use a reliable security program that provides protection against malware and botnets. This should include performing regular scans to detect and remove any attacks.

Using strong passwords and changing them regularly is another way to protect yourself from the FritzFrog Botnet. Botnet attacks often try to guess passwords ,so using strong passwords and changing them regularly can help protect your accounts.

Finally, security training can be particularly useful. Understanding how botnet attacks work and the techniques they use can help you identify and avoid attacks.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS