Skip to main content
See every side of every news story
Published loading...Updated

Cyber Agencies Warn Organisations to Guard Against China-Linked Covert Networks

The advisory says China-nexus actors are using vast botnets of hacked routers and other devices to hide attacks and defeat static IP-blocking defenses.

  • On Thursday, the United States and allies issued a joint advisory warning that China-nexus hackers are increasingly using large-scale botnets of compromised SOHO routers and IoT devices to hide malicious activity.
  • These networks are mainly made up of compromised SOHO routers and Internet of Things devices; new nodes are constantly added as old equipment is patched or removed, making them difficult for defenders to track.
  • China-Linked actors previously used the KV-Botnet for attacks on U.S. critical infrastructure and the Raptor Train botnet, which infected more than 260,000 devices worldwide in 2024. The FBI disrupted both operations by removing malware from infected routers.
  • "Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices," said Paul Chichester, NCSC-UK's Director of Operations. Traditional IP blocking defenses are becoming less effective.
  • Network defenders should implement multifactor authentication, map edge devices, and apply zero-trust principles to limit external connections. Organizations are advised to use IP allowlisting and dynamic threat feeds to detect covert network indicators.
Insights by Ground AI

18 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 67% of the sources are Center
67% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news on Thursday, April 23, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal