The FBI has disrupted the KV Botnet used by Chinese Volt Typhoon state hackers to evade detection during attacks targeting U.S. critical infrastructure. The hacking group (also tracked as Bronze Silhouette) used it to hijack hundreds of small office/home offices (SOHO) across the United States and used them to ensure that their malicious activity blends within legitimate network traffic to avoid detection. Devices compromised and added to this botnet included Netgear ProSAFE, Cisco RV320s, and DrayTek Vigor routers, as well as Axis IP cameras, according to Lumen Technologies' Black Lotus Labs team, who first linked the malware to the Chinese threat group in December. A SecurityScorecard report from earlier this month estimates that Volt Typhoon hackers were able to hijack roughly 30% of all Cisco RV320/325 devices online in just over a month. "The Volt Typhoon malware enabled China to hide, among other things, pre-operational reconnaissance and network exploitation against critical infrastructure like our communications, energy, transportation, and water sectors—steps China was taking, in other words, to find and prepare to destroy or degrade the civilian critical infrastructure that keeps us safe and prosperous," said FBI Director Christopher Wray. "So working with our partners, the FBI ran a court-authorized, on-network operation to shut down Volt Typhoon and the access it enabled." The FBI's operation began on December 6th when the law enforcement agency first obtained a ...
FBI disrupts Chinese botnet by wiping malware from infected routers
BleepingComputer
·Sergiu Gatlan
·Published Jan 31, 2024
·Updated
Affected Software
4 affected components
Netgear ProSAFE
Cisco RV320s
DrayTek Vigor
Axis IP cameras
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the FBI's disruption of the KV Botnet used by Chinese hackers targeting U.S. critical infrastructure.
2
What security implications are discussed?
The article highlights the risks posed by state-sponsored hacking groups and their methods to evade detection.
3
What products or software are affected?
The affected products include Netgear ProSAFE routers, Cisco RV320s, DrayTek Vigor routers, and Axis IP cameras.
4
Who is behind the KV Botnet?
The KV Botnet is reportedly operated by a Chinese state-sponsored hacking group known as Volt Typhoon or Bronze Silhouette.
5
What actions did the FBI take to disrupt the botnet?
The FBI wiped malware from infected routers to neutralize the KV Botnet's operations.