China-Nexus Botnets Turn Everyday Devices Into Cover
The break is not just device compromise. China-nexus actors are using large, covert networks of hacked SOHO routers and IoT devices as reusable infrastructure, which hides origin, blunts attribution, and makes routine reconnaissance and exfiltration harder to spot. The standard response of blocking a single source IP misses the point because the source is now a moving layer of compromised consumer gear.
The joint advisory from CISA, the FBI, NSA, NCSC-UK, and partners says this is a broad shift in tactics over the past few years. It ties the pattern to Volt Typhoon and Flax Typhoon, and cites botnets such as KV Botnet and Raptor Train, with Raptor Train reaching more than 200,000 devices worldwide. The advisory also says there is evidence that Chinese information security companies build and maintain some of these covert networks.
For defenders, the risk persists even after one botnet is disrupted. The infrastructure is large, constantly updated, and can be shared across actors, so takedowns reduce capacity but do not end the model.
Global agencies issue a major warning on China-nexus covert networks, as hackers shift tactics to exploit SOHO routers and IoT devices to target infrastructure.
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it
Defending Against China-Nexus Covert Networks of Compromised Devices Defending against china-nexus covert networks of compromised devices executive summary Defending against China-nexus covert networks of compromised devices Explaining the widespread shift in tactics, techniques…