Chinese Hackers Seized Outdated Routers for Covert Data Transfer

Volt Typhoon, also known as the Bronze Silhouette, has been discovered to be linked with a complex botnet called “KV-botnet.”

The threat actor has been using this botnet to target Small Office/Home Office routers since at least February 2022. Their primary targets are routers, firewalls, and VPN devices which are utilized for proxying malicious traffic. 

According to reports from Microsoft and the US government, this threat actor is building their infrastructure to disrupt communications between the USA and Asia in case of future conflicts.

Chinese Hackers Seized Outdated Routers

The IP addresses used for the campaign were attributed to the People’s Republic of China, according to the report shared with Cyber Security News.

In addition to this, the operations took place during the working hours of Chinese Standard Time, which adds additional confidence about the threat actor’s origin.

The botnet is divided into two distinct activities: the “JDY cluster,” which has less sophisticated techniques for scanning targets, and the “KV cluster,” which is reserved for manual operations against high-profile targets.

Clusters of botnet (Source: Black Lotus Labs)Clusters of botnet (Source: Black Lotus Labs)
Clusters of botnet (Source: Black Lotus Labs)

Moreover, the botnet also targets end-of-life devices that are being used by SOHO entities as they have low security and are easy to exploit. The devices focussed specifically were Cisco RV320s, DrayTek Vigor routers, and NETGEAR ProSAFE firewalls.

Infection Chain

The threat actor uses multiple files, including a bash script file, for their infection chain. They half-specific processes and remove security tools that defaultly run on the compromised devices.

KV cluster infection chain (Source: Black Lotus Labs)

As part of the evasion techniques, the botnets are set up with random ports for C2 communication and also disguise their names as existing processes.

Threat actors communicate with these botnets and perform data exfiltration, data transmission, creation of network connections, task execution, and many others.

Furthermore, a complete report about this botnet has been published, which provides detailed information about the botnet infection chain, process execution, attack methods, evasion techniques, and other information.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Multiple Cisco Tools at Risk from Erlang/OTP SSH Remote Code Execution Flaw

Cisco has issued a high-severity advisory (cisco-sa-erlang-otp-ssh-xyZZy) warning of a critical remote code execution (RCE)…

23 minutes ago

Commvault RCE Vulnerability Exploited—PoC Released

Enterprises and managed service providers globally are now facing urgent security concerns following the disclosure…

31 minutes ago

Zyxel RCE Flaw Lets Attackers Run Commands Without Authentication

Security researcher Alessandro Sgreccia (aka "rainpwn") has revealed a set of critical vulnerabilities in Zyxel’s…

1 hour ago

Redis DoS Flaw Allows Attackers to Crash Servers or Drain Memory

A high-severity denial-of-service (DoS) vulnerability in Redis, tracked as CVE-2025-21605, allows unauthenticated attackers to crash servers…

4 hours ago

Google Warns: Threat Actors Growing More Sophisticated, Exploiting Zero-Day Vulnerabilities

Google’s Mandiant team has released its M-Trends 2025 report, highlighting the increasing sophistication of threat…

4 hours ago

Critical Langflow Flaw Enables Malicious Code Injection – Technical Breakdown Released

A critical remote code execution (RCE) vulnerability, identified as CVE-2025-3248 with a CVSS score of…

5 hours ago