China-nexus cyber actors’ turn routers and IoT infrastructure into covert botnets ‘at scale’ – NCSC, Five Eyes and others warn of campaigns involving Typhoon-designated groups


  • A joint advisory from 10 nations warns that Chinese state-sponsored groups are using large botnets of compromised IoT and SOHO devices.
  • These secret networks allow attackers to hide their location, launch DDoS attacks, spread malware and steal sensitive data at scale.
  • Agencies are urging organizations to patch devices, enforce strong credentials and monitor for indicators of compromise to reduce exposure.

Most Chinese state-sponsored threat actors are using botnets of compromised IoT and SOHO devices as their cybercriminal infrastructure, says a new 10-nation joint security advisory.

Earlier this week, security agencies from 10 countries, including the NSA, DOJ, NCSC and others, published a new paper called “Defending against China-nexus’ secret network of compromised devices,” which claims these groups use botnets to steal people’s data or disrupt activities.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top