Black Lotus Labs by Lumen Logo with black text on a white background

Routers roasting on an open firewall: the KV-botnet investigation

Lumen tracked KV-botnet as a malware ecosystem built from vulnerable edge devices and used as a proxy botnet. Over six months, the team identified more than 1,300 infected systems by modeling traffic patterns that hid command and control in normal activity. The infection chain exploits known flaws, deploys a hostloader and bot binary, and uses anti-forensics to stay on the device. Lumen also found overlap in infrastructure, victims, and malware that ties this activity to Volt Typhoon with moderate confidence.

Published on Dec 23, 2023 | 11 minute read