Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagebotnet-infrastructurethreat-infrastructure-trackingembedded-device-vulnerability

China-Linked Groups Built Covert Botnets From Compromised Routers and IoT Devices

Updated 2mo agoFirst seen Apr 14, 20267 sources

A joint advisory from the UK NCSC, the United States, and other international partners warned that China-nexus threat actors are increasingly using large covert networks of compromised SOHO routers, IoT devices, firewalls, and NAS systems to route malicious traffic, hide attribution, and support espionage and disruptive operations. The warning said these botnet-style proxy networks are used across the full cyber kill chain, from reconnaissance and malware delivery to command-and-control and data theft, and identified activity tied to Volt Typhoon, Flax Typhoon, and the Raptor Train botnet. Officials said Volt Typhoon’s KV Botnet relied heavily on end-of-life Cisco and Netgear routers, while Raptor Train infected more than 200,000 devices worldwide and was reportedly controlled by Integrity Technology Group.

Governments said the scale and churn of these compromised-device networks make traditional static IP blocklists increasingly ineffective, creating what some reporting described as rapid indicator loss or “IOC extinction.” Agencies urged organizations to map internet-facing and edge assets, baseline normal traffic from routers and IoT devices, enforce MFA, apply dynamic threat intelligence, use allow-listing and zero trust controls, and actively hunt for suspicious proxy-node behavior on residential, branch, and enterprise-connected infrastructure. The disclosures also linked the threat to broader Chinese pre-positioning activity against critical infrastructure and telecom environments, underscoring how weakly secured edge devices continue to provide durable operational cover for state-backed intrusions.

Share:
China-Linked Groups Built Covert Botnets From Compromised Routers and IoT Devices
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Apr 23, 20262mo ago

International advisory warns China-linked actors use covert device networks

On 2026-04-23, the UK NCSC and multiple international partners published a joint advisory warning that China-nexus actors had shifted to large-scale covert networks of compromised SOHO routers, IoT devices, firewalls, and NAS systems. The advisory said these networks support the full cyber kill chain, hinder attribution, and are used for espionage and pre-positioning against targets including critical infrastructure.

Apr 24, 20242y ago

Cisco discloses ArcaneDoor-linked ASA/FTD vulnerabilities and releases fixes

Cisco disclosed multiple serious vulnerabilities affecting ASA and FTD products, including CVE-2024-20353, CVE-2024-20359, and CVE-2024-20358, and released software updates for weaknesses in the attack chain tied to the ArcaneDoor espionage campaign. Guidance urged organizations to patch immediately and investigate for signs of compromise using forensic indicators from Cisco and partner agencies.

Jan 1, 20242y ago

Raptor Train botnet infects more than 200,000 devices worldwide

During 2024, the Raptor Train botnet compromised over 200,000 devices globally. Later reporting and advisories said the network was controlled by Integrity Technology Group and exemplified large-scale covert infrastructure used by China-linked actors.

ArcaneDoor attacks begin targeting Cisco ASA and FTD devices

Cisco PSIRT observed attacks starting in early 2024 in which threat actors targeted vulnerable Cisco ASA and Firepower Threat Defense devices, attempting to install malware and steal data from perimeter systems.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

29 LINKEDOpen in app
Affected products
1 linked
Junos Os
Organizations
18 linked
Cisco SystemsNetgearIntegrity Technology GroupThe RegisterGoogleJuniper NetworksVerizon CommunicationsBT GroupTaniumLinkedinAT&TTP-LinkCisco SystemsF5XMandiant IntelligenceAmdocsVodafoneThree
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.