Resurgence of KV Botnet Linked to Chinese State Actors

Resurgence of KV Botnet Linked to Chinese State Actors

First seen 11 Jun 2026, 00:26 UTC Theregisterwww.lumen.com 80% similarity 75.8

Article Content

Browse articles
ThreatCluster

Chinese operatives have revived the KV-botnet, a covert data transfer network previously dismantled by the FBI in January 2024. The botnet, which primarily exploits vulnerable routers and IoT devices, has seen a resurgence with over 1,500 compromised devices, particularly in the JDY cluster used for reconnaissance. This activity follows a significant drop in operations after the FBI's takedown, indicating a shift in tactics by the threat actors. The botnet's resurgence is coupled with attempts to influence public opinion on AI datacenter construction, although these efforts have largely failed. The U.S. military and critical infrastructure sectors remain primary targets of this renewed activity. Lumen Technologies has reported ongoing monitoring and analysis of these developments, emphasizing the need for heightened vigilance against such state-sponsored cyber threats.

Key Points: • KV-botnet, linked to Chinese state actors, has resurfaced with over 1,500 compromised devices. • The JDY cluster, used for reconnaissance, remains active despite previous takedown efforts. • Chinese operatives are also attempting to influence public opinion on AI datacenters.

ThreatCluster AI

Timeline

2023-12-06
FBI initiates takedown of KV-botnet
The FBI conducted a court-authorized operation against the KV-botnet, targeting its command and control structure.
Lumen
2024-01-01
KV-botnet officially declared dismantled
The FBI announced the successful takedown of the KV-botnet, which had been used for espionage against U.S. critical infrastructure.
The Register
2024-01-10
KV-botnet operators attempt to rebuild
Reports indicated that operators were trying to re-establish the KV-botnet's infrastructure shortly after the takedown.
Lumen
2026-06-11
Lumen reports resurgence of KV-botnet
Lumen's Black Lotus Labs reported a significant resurgence of the KV-botnet, with over 1,500 compromised devices active in reconnaissance.
Lumen
2026-06-11
Chinese influence operations using AI reported
OpenAI reported banning accounts likely from China using its AI for covert operations related to public opinion on AI datacenters.
The Register

Community

Browse all →