China-Nexus Botnets Turn Everyday Devices Into Cover
The break is not just device compromise. China-nexus actors are using large, covert networks of hacked SOHO routers and IoT devices as reusable infrastructure, which hides origin, blunts attribution, and makes routine reconnaissance and exfiltration harder to spot. The standard response of blocking a single source IP misses the point because the source is now a moving layer of compromised consumer gear.
The joint advisory from CISA, the FBI, NSA, NCSC-UK, and partners says this is a broad shift in tactics over the past few years. It ties the pattern to Volt Typhoon and Flax Typhoon, and cites botnets such as KV Botnet and Raptor Train, with Raptor Train reaching more than 200,000 devices worldwide. The advisory also says there is evidence that Chinese information security companies build and maintain some of these covert networks.
For defenders, the risk persists even after one botnet is disrupted. The infrastructure is large, constantly updated, and can be shared across actors, so takedowns reduce capacity but do not end the model.