ATT&CKCampaignsKV Botnet Activity

KV Botnet Activity

C0035

Campaign, Oct 2022 to Jan 2024.View on attack.mitre.org

About this campaign

KV Botnet Activity consisted of exploitation of primarily “end-of-life” small office-home office (SOHO) equipment from manufacturers such as Cisco, NETGEAR, and DrayTek. KV Botnet Activity was used by Volt Typhoon to obfuscate connectivity to victims in multiple critical infrastructure segments, including energy and telecommunication companies and entities based on the US territory of Guam. While the KV Botnet is the most prominent element of this campaign, it overlaps with another botnet cluster referred to as the JDY cluster. This botnet was disrupted by US law enforcement entities in early 2024 after periods of activity from October 2022 through January 2024.

Techniques used20

Procedure examples20

TechniqueProcedure example
T1016
System Network Configuration Discovery

KV Botnet Activity gathers victim IP information during initial installation stages.

T1036
Masquerading

KV Botnet Activity involves changing process filename to pr_set_mm_exe_file and process name to pr_set_name during later infection stages.

T1036.004
Masquerade Task or Service

KV Botnet Activity installation steps include first identifying, then stopping, any process containing [kworker\/0:1], then renaming its initial installation stage to this process name.

T1055.009
Proc Memory

KV Botnet Activity final payload installation includes mounting and binding to the \/proc\/ filepath on the victim system to enable subsequent operation in memory while also removing on-disk artifacts.

T1057
Process Discovery

Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.

T1059.004
Unix Shell

KV Botnet Activity utilizes multiple Bash scripts during botnet installation stages, and the final botnet payload allows for running commands in the Bash shell.

T1070.004
File Deletion

KV Botnet Activity removes on-disk copies of tools and other artifacts after it the primary botnet payload has been loaded into memory on the victim device.

T1082
System Information Discovery

KV Botnet Activity includes use of native system tools, such as uname, to obtain information about victim device architecture, as well as gathering other system information such as the victim's hosts file and CPU utilization.

T1083
File and Directory Discovery

KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: \/usr\/sbin\/, \/usr\/bin\/, \/sbin\/, \/pfrm2.0\/bin\/, \/usr\/local\/bin\/.

T1095
Non-Application Layer Protocol

KV Botnet Activity command and control traffic uses a non-standard, likely custom protocol for communication.

T1105
Ingress Tool Transfer

KV Botnet Activity included the use of scripts to download additional payloads when compromising network nodes.

T1222.002
Linux and Mac Permissions

KV Botnet Activity altered permissions on downloaded tools and payloads to enable execution on victim machines.

T1518.001
Security Software Discovery

KV Botnet Activity involved removal of security tools, as well as other identified IOT malware, from compromised devices.

T1546
Event Triggered Execution

KV Botnet Activity involves managing events on victim systems via libevent to execute a callback function when any running process contains the following references in their path without also having a reference to bioset: busybox, wget, curl, tftp, telnetd, or lua. If the bioset string is not found, the related process is terminated.

T1564.013
Bind Mounts

KV Botnet Activity leveraged a bind mount to bind itself to the `/proc/` file path before deleting its files from the `/tmp/` directory.

View all 20 procedure examples

Attributed groups1

Software0

None recorded.

References2

  1. DOJ KVBotnet 2024 Open source
    US Department of Justice. (2024, January 31). U.S. Government Disrupts Botnet People’s Republic of China Used to Conceal Hacking of Critical Infrastructure. Retrieved June 10, 2024.
  2. Lumen KVBotnet 2023 Open source
    Black Lotus Labs. (2023, December 13). Routers Roasting On An Open Firewall: The KV-Botnet Investigation. Retrieved June 10, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.