New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks

Started by ixsky,

Previous topic - Next topic

ixsky

New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks

A new botnet consisting of firewalls and routers from Cisco, DrayTek, Fortinet, and NETGEAR is being used as a covert data transfer network for advanced persistent threat actors, including the China-linked threat actor called Volt Typhoon.
Dubbed KV-botnet by the Black Lotus Labs team at Lumen Technologies, the malicious network is an amalgamation of two complementary activity

Source: New KV-Botnet Targeting Cisco, DrayTek, and Fortinet Devices for Stealthy Attacks