News report

# Volt Typhoon rebuilds malware botnet following FBI disruption

BleepingComputer, November 12, 2024. The rebuild of the KV-Botnet after the FBI's January 2024 disruption, tracked by SecurityScorecard as the 'JDYFJ Botnet' after a self-signed SSL certificate seen on compromised Cisco RV320/325 and Netgear ProSafe devices..

**Source type:** News report

**Published:** November 12, 2024

**Research grade:** S2

**Used in entries:** 1

## Bibliographic record

**Publisher:** BleepingComputer

**Published:** November 12, 2024

**Source type:** News report

**Research grade:** Source grade S2

**Language:** English

**Official record:** Not an official publication

**Address:** [https://www.bleepingcomputer.com/news/security/volt-typhoon-rebuilds-malware-botnet-following-fbi-disruption/](https://www.bleepingcomputer.com/news/security/volt-typhoon-rebuilds-malware-botnet-following-fbi-disruption/)

**What it supports:** The rebuild of the KV-Botnet after the FBI's January 2024 disruption, tracked by SecurityScorecard as the 'JDYFJ Botnet' after a self-signed SSL certificate seen on compromised Cisco RV320/325 and Netgear ProSafe devices.

**Dataset id:** src\_bleepingcomputer\_volt\_typhoon\_rebuilds

## Research notes

- By Bill Toulas.

How this source is used

Cited 1 time across 1 record type.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.

## Cited by

### Later activity

1 citation

Cited for activity recorded after the takedown.

-
[Rebuilt KV-Botnet cluster (JDYFJ botnet)](https://takedownindex.org/takedowns/kv-botnet-disruption)

Same operators, KV Botnet disruption

Later outcome

[All sources](https://takedownindex.org/sources)
