A joint advisory from the UK NCSC, the United States, and other international partners warned that China-nexus threat actors are increasingly using large covert networks of compromised SOHO routers, IoT devices, firewalls, and NAS systems to route malicious traffic, hide attribution, and support espionage and disruptive operations. The warning said these botnet-style proxy networks are used across the full cyber kill chain, from reconnaissance and malware delivery to command-and-control and data theft, and identified activity tied to Volt Typhoon, Flax Typhoon, and the Raptor Train botnet. Officials said Volt Typhoon’s KV Botnet relied heavily on end-of-life Cisco and Netgear routers, while Raptor Train infected more than 200,000 devices worldwide and was reportedly controlled by Integrity Technology Group.
Governments said the scale and churn of these compromised-device networks make traditional static IP blocklists increasingly ineffective, creating what some reporting described as rapid indicator loss or “IOC extinction.” Agencies urged organizations to map internet-facing and edge assets, baseline normal traffic from routers and IoT devices, enforce MFA, apply dynamic threat intelligence, use allow-listing and zero trust controls, and actively hunt for suspicious proxy-node behavior on residential, branch, and enterprise-connected infrastructure. The disclosures also linked the threat to broader Chinese pre-positioning activity against critical infrastructure and telecom environments, underscoring how weakly secured edge devices continue to provide durable operational cover for state-backed intrusions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-23, the UK NCSC and multiple international partners published a joint advisory warning that China-nexus actors had shifted to large-scale covert networks of compromised SOHO routers, IoT devices, firewalls, and NAS systems. The advisory said these networks support the full cyber kill chain, hinder attribution, and are used for espionage and pre-positioning against targets including critical infrastructure.
Cisco disclosed multiple serious vulnerabilities affecting ASA and FTD products, including CVE-2024-20353, CVE-2024-20359, and CVE-2024-20358, and released software updates for weaknesses in the attack chain tied to the ArcaneDoor espionage campaign. Guidance urged organizations to patch immediately and investigate for signs of compromise using forensic indicators from Cisco and partner agencies.
During 2024, the Raptor Train botnet compromised over 200,000 devices globally. Later reporting and advisories said the network was controlled by Integrity Technology Group and exemplified large-scale covert infrastructure used by China-linked actors.
Cisco PSIRT observed attacks starting in early 2024 in which threat actors targeted vulnerable Cisco ASA and Firepower Threat Defense devices, attempting to install malware and steal data from perimeter systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcetheregister.com
Open sourcesdxcentral.com
Open sourcekyberturvallisuuskeskus.fi
Open sourcekyberturvallisuuskeskus.fi
Open sourceic3.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.