• News/
  • https://www.bleepingcomputer.com/news/security/fbi-disrupts-chinese-botnet-by-wiping-malware-from-infected-routers/

FBI disrupts Chinese botnet by wiping malware from infected routers

BleepingComputer
·
Sergiu Gatlan
·
Published Jan 31, 2024
·
Updated

The FBI has disrupted the KV Botnet used by Chinese Volt Typhoon state hackers to evade detection during attacks targeting U.S. critical infrastructure. The hacking group (also tracked as Bronze Silhouette) used it to hijack hundreds of small office/home offices (SOHO) across the United States and used them to ensure that their malicious activity blends within legitimate network traffic to avoid detection. Devices compromised and added to this botnet included Netgear ProSAFE, Cisco RV320s, and DrayTek Vigor routers, as well as Axis IP cameras, according to Lumen Technologies' Black Lotus Labs team, who first linked the malware to the Chinese threat group in December. A SecurityScorecard report from earlier this month estimates that Volt Typhoon hackers were able to hijack roughly 30% of all Cisco RV320/325 devices online in just over a month. "The Volt Typhoon malware enabled China to hide, among other things, pre-operational reconnaissance and network exploitation against critical infrastructure like our communications, energy, transportation, and water sectors—steps China was taking, in other words, to find and prepare to destroy or degrade the civilian critical infrastructure that keeps us safe and prosperous," said FBI Director Christopher Wray. "So working with our partners, the FBI ran a court-authorized, on-network operation to shut down Volt Typhoon and the access it enabled." The FBI's operation began on December 6th when the law enforcement agency first obtained a ...

Read full article

Affected Software

4 affected components
Netgear ProSAFE
Cisco RV320s
DrayTek Vigor
Axis IP cameras
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the FBI's disruption of the KV Botnet used by Chinese hackers targeting U.S. critical infrastructure.

2

What security implications are discussed?

The article highlights the risks posed by state-sponsored hacking groups and their methods to evade detection.

3

What products or software are affected?

The affected products include Netgear ProSAFE routers, Cisco RV320s, DrayTek Vigor routers, and Axis IP cameras.

4

Who is behind the KV Botnet?

The KV Botnet is reportedly operated by a Chinese state-sponsored hacking group known as Volt Typhoon or Bronze Silhouette.

5

What actions did the FBI take to disrupt the botnet?

The FBI wiped malware from infected routers to neutralize the KV Botnet's operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203