Campaign, Oct 2022 to Jan 2024.View on attack.mitre.org
KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster. This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.
| Technique | Procedure example |
|---|---|
| T1016 System Network Configuration Discovery |
KV Botnet Activity gathers victim IP information during initial installation stages. |
| T1036 Masquerading |
KV Botnet Activity involves changing process filename to |
| T1036.004 Masquerade Task or Service |
KV Botnet Activity installation steps include first identifying, then stopping, any process containing |
| T1055.009 Proc Memory |
KV Botnet Activity final payload installation includes mounting and binding to the |
| T1057 Process Discovery |
Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation. |
| T1059.004 Unix Shell |
KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell. |
| T1070.004 File Deletion |
KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device. |
| T1082 System Information Discovery |
KV Botnet Activity includes use of native system tools, such as |
| T1083 File and Directory Discovery |
KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| T1095 Non-Application Layer Protocol |
KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication. |
| T1105 Ingress Tool Transfer |
KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes. |
| T1222.002 Linux and Mac Permissions |
KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines. |
| T1518.001 Security Software Discovery |
KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices. |
| T1546 Event Triggered Execution |
KV Botnet Activity involves managing events on victim systems via |
| T1564.013 Bind Mounts |
KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.