[Back to the takedown index](https://takedownindex.org/takedowns)

# KV Botnet disruption

December 2023, State sponsored
Led by [Federal Bureau of Investigation](https://takedownindex.org/organizations/federal-bureau-of-investigation)

Verified core entry, last reviewed August 21, 2026

What was taken down?

Malware deleted from compromised routers; command-and-control connections severed; steps taken to prevent reinfection without affecting legitimate router functions.[[1]](#source-1)[[2]](#source-2)

[See what happened](#what-happened)

What happened to the people?

No individual outcomes are recorded against this entry.
Group accounted for: Not applicable

[See people and accountability](#people)

Did it stay down?

Not established in the public record. No later activity is recorded against this entry.

[See what happened afterward](#afterward)

## What happened

Court-authorized FBI operation deleting malware from hundreds of end-of-life US small office and home office routers compromised by the PRC state-sponsored actor tracked as Volt Typhoon, and severing their connection to the botnet.[[1]](#source-1)[[2]](#source-2)

Announced January 31, 2024.

**Date:** December 1, 2023 to January 31, 2024

**Target:** KV Botnet, compromised soho router network

**Activity:** State sponsored, Malware and botnets

**Operational lead:** FBI

**Partners**

USAO-WDPA, CISA[[1]](#source-1)[[2]](#source-2)

- [United States Attorney's Office for the Western District of Pennsylvania](https://takedownindex.org/organizations/united-states-attorney-s-office-for-the-western-district-of-pennsylvania), prosecuting
- [Cybersecurity and Infrastructure Security Agency](https://takedownindex.org/organizations/cybersecurity-and-infrastructure-security-agency), supporting

**Jurisdiction:** United States

**Outcome:** Malware deleted from compromised routers; command-and-control connections severed; steps taken to prevent reinfection without affecting legitimate router functions.

**Status:** Completed

**Legal mechanism:** Rule 41 search and seizure warrants, Western District of Pennsylvania

**Group accounted for:** Not applicable

### Infrastructure

Malware installations remediated and command and control servers disabled, with no count in the record.

| Identifier | Recorded as | Status | Notes |
| --- | --- | --- | --- |
| Not published | Malware installation | Remediated, United States | Malware deleted from hundreds of compromised end-of-life SOHO routers in the United States. Exact count reported as hundreds.[[1]](#source-1) |
| Not published | Command and control server | Disabled | Router connections to the botnet command-and-control severed.[[1]](#source-1) |

Domains and onion addresses are shown defanged. Where the record gives a count but no identifier, the count is shown in place of one. This list carries only what appears in the cited sources.

## People and accountability

No individual is named against this entry in the cited record. That is a gap in what has been published rather than a finding that nobody was involved.

Group accounted for: Not applicable

State-sponsored infrastructure disruption. No criminal operator roster applies.

State-sponsored actor rather than a finite criminal operator group.

[See the organizations and roles behind this action](https://takedownindex.org/takedowns/kv-botnet-disruption/organizations)

## What happened afterward

Ongoing investigation. Routers remain vulnerable to reinfection if not replaced or patched.[[1]](#source-1)[[2]](#source-2)

Not established in the public record. No later activity is recorded against this entry.

Return class G. The class is a research grading carried in the source dataset and its scale is not published, so this page relies on the relationship and confidence values instead. [How this index handles it](https://takedownindex.org/about).

## Sources

Numbered markers throughout this entry link to the source that supports the claim beside them.

### Official sources

1.
[U.S. Government Disrupts Botnet People's Republic of China Used to Conceal Hacking of Critical Infrastructure](https://takedownindex.org/sources/united-states-department-of-justice-u-s-government-disrupts-botnet-people-s-repu)

United States Department of Justice, January 31, 2024, Source grade P1

Court-authorized malware deletion from routers, Rule 41 warrants in WDPA, reinfection caveat

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

2.
[CISA guidance on Volt Typhoon activity against critical infrastructure](https://takedownindex.org/sources/cybersecurity-and-infrastructure-security-agency-cisa-guidance-on-volt-typhoon-a)

Cybersecurity and Infrastructure Security Agency, February 7, 2024, Source grade P2

Threat context for the KV Botnet disruption

No address recorded for this source. Publisher, title, and date are given so it can be retrieved from the publisher.

Coverage note. Reinfection risk was explicitly acknowledged by authorities, so no claim of permanent eradication is recorded.

Research context

## How this entry was checked

This entry went through a dedicated source verification pass. Publisher, title, publication date, and docket numbers were confirmed against each cited source.

Source review: Verified core

Sources cited: 2

Research cutoff: August 20, 2026

Last reviewed August 21, 2026

See also

[About the Internet Takedown Index](https://takedownindex.org/about)

Related entries

- [Kingdom Market seizure](https://takedownindex.org/takedowns/kingdom-market-seizure)
- [Sinbad cryptocurrency mixer seizure](https://takedownindex.org/takedowns/sinbad-cryptocurrency-mixer-seizure)
- [ALPHV/BlackCat disruption](https://takedownindex.org/takedowns/alphv-blackcat-disruption)

Report updates or corrections

Help keep this record accurate.

[Submit feedback](https://takedownindex.org/about#corrections-and-updates)
