Security News > 2024 > February > FBI disrupts Chinese botnet used for targeting US critical infrastructure
The FBI has disrupted the KV botnet, used by People's Republic of China state-sponsored hackers to target US-based critical infrastructure organizations.
A botnet for probing critical infrastructure organizations.
The threat actors used the KV botnet malware to hijack hundreds of US-based, privately-owned small office/home office routers and to hide their hacking activity towards "US and other foreign victims".
"The court-authorized operation deleted the KV botnet malware from the routers and took additional steps to sever their connection to the botnet, such as blocking communications with other devices used to control the botnet," the US Department of Justice said in a press release published on Wednesday.
"The court-authorized operation deleted the KV Botnet malware from the routers and took additional steps to sever their connection to the botnet, such as blocking communications with other devices used to control the botnet," the DOJ explained.
The FBI has contacted some of the owners or operators of the SOHO routers that were infected with the KV Botnet malware to let them know about the actions taken.
News URL
https://www.helpnetsecurity.com/2024/02/01/botnet-critical-infrastructure/
Related news
- Microsoft: Another Chinese cyberspy crew targeting US critical orgs 'as of yesterday' (source)
- Iran-linked crew used custom 'cyberweapon' in US critical infrastructure attacks (source)
- FBI wipes Chinese PlugX malware from over 4,000 US computers (source)
- FBI deletes Chinese PlugX malware from thousands of US computers (source)
- CISA, FBI Issue Guidance for Securing Communications Infrastructure (source)
- 8 US telcos compromised, FBI advises Americans to use encrypted communications (source)
- US sanctions Chinese firm for hacking firewalls in ransomware attacks (source)
- US sanctions Chinese cybersecurity company for firewall compromise, ransomware attacks (source)
- US names Chinese national it alleges was behind 2020 attack on Sophos firewalls (source)
- US Sanctions Chinese Cybersecurity Firm for 2020 Ransomware Attack (source)