KV-botnet Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
June 10, 2026
Last Seen
August 26, 2026

Related Threat Clusters

  • US Seizes Chinese Hacking Platforms Targeting Critical Infrastructure

    On August 26, 2026, the U.S. Justice Department and FBI announced the seizure of domains linked to Chinese state-sponsored hacking platforms QScan and QTRouter, operated by the group QTFY. These tools were used to…

    5 articles · Updated August 26, 2026
  • Resurgence of KV Botnet Linked to Chinese State Actors

    Chinese operatives have revived the KV-botnet, a covert data transfer network previously dismantled by the FBI in January 2024. The botnet, which primarily exploits vulnerable routers and IoT devices, has seen a…

    2 articles · Updated June 11, 2026
  • JDY Botnet Grows to 1,500 Devices for Rapid Vulnerability Mapping

    The JDY botnet, linked to Chinese state-sponsored actors, has expanded to over 1,500 compromised small office and IoT devices, primarily in the U.S. and Brazil. This botnet scans for newly disclosed vulnerabilities…

    12 articles · Updated June 10, 2026

Recent Intelligence Reports

  • The Infrastructure Quartermaster Inside A China Nexus State Enablement Model — www.lumen.com · August 26, 2026
  • JDY Botnet Evolves After KV Takedown, Targets Military Networks — Securityaffairs.Co · June 11, 2026
  • China-linked JDY botnet rapidly exploits new flaws, raising fresh Volt Typhoon concerns — Cybernews · June 11, 2026
  • Kv Botnet Dont Call Comeback — www.lumen.com · June 11, 2026
  • JDY botnet expands, enabling rapid exploitation of disclosed vulnerabilities — Scworld · June 10, 2026

CVSS v3.1 Breakdown