NEWS Is your router acting strange? It might already be working for the Chinese government.

Gold Surfer

Administrator
Staff member
Administrator
Moon-Club
Exclusive
Infinity
Premium
Member
Joined
Jan 20, 2026
Messages
345
Reaction score
2,571
How Chinese hackers turn other people's technology into an invisible attack surface.
1777135148990.png
Chinese hacker groups are increasingly launching attacks through compromised routers, cameras, and other internet-connected devices to disguise the real source of their traffic. These devices are transformed into proxy networks: through these nodes, attackers launch new intrusions, steal data, and disrupt organizations' operations.

The issue was addressed in a joint alert issued by the UK's National Cyber Security Centre and 15 other government agencies from the US, Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain, and Sweden. The alert was also published on the CISA and NCSC websites . The document's authors believe that all organizations of interest to Chinese-linked hacker groups are at risk.

The use of botnets from hacked devices has long been known to security experts, but the scale and approach have changed. According to agencies, Chinese-linked groups have begun to systematically and massively exploit hidden networks. This infrastructure includes SOHO routers, network cameras, DVRs, firewalls, and network storage devices.

Some of these networks, according to the warning's authors, are created and maintained by Chinese information security companies. The document cites the example of Integrity Technology Group. The Chinese company operated the Raptor Train network, which infected over 200,000 devices worldwide in 2024. The botnet included small office and home routers, cameras, DVRs, firewalls, and NAS storage devices.

The FBI previously linked Integrity Technology Group to the activities of the Flax Typhoon group . Other groups in the Typhoon family, according to the alert, also use hidden networks as part of their infrastructure. Sometimes, multiple China-linked groups operate through the same proxy network.

The document specifically mentions Volt Typhoon. US authorities believe the group is linked to China and accuse it of infiltrating US critical infrastructure to prepare for future destructive attacks. For the KV Botnet, the attackers primarily used outdated Cisco and Netgear routers, which had already reached the end of their support lifespan.

The warning's authors chose not to detail all known hidden networks. The number of botnets is too large: some networks quickly emerge, others cease operations, and law enforcement shuts down some infrastructure. A complete catalog would be out of date almost immediately and would be of little help to administrators.

Experts advise organizations to start by taking into account edge devices and a baseline network traffic profile. Particular attention should be paid to VPNs , remote access, and unusual connections. Agencies also recommend using multi-factor authentication, zero-trust elements, IP whitelists, and machine certificate validation if the infrastructure supports such protection.

Large organizations and companies in risk groups are advised to look for suspicious traffic from SOHO devices and IoT equipment, and to use geographic profiling and machine-learning-based anomaly detection systems.

Similar methods aren't limited to state-sponsored hacker groups. Financially motivated criminals also hack routers and connected devices to conceal fraudulent transactions. In March, the FBI, along with law enforcement agencies in eight other countries, disrupted SocksEscort, a residential proxy service. Through the service, attackers exploited hundreds of thousands of compromised routers worldwide, causing millions of dollars in damage to companies and individual users.
 

darkwebmoonforum

Member
Member
Joined
Jul 20, 2026
Messages
15
Reaction score
1
How Chinese hackers turn other people's technology into an invisible attack surface.
View attachment 111
Chinese hacker groups are increasingly launching attacks through compromised routers, cameras, and other internet-connected devices to disguise the real source of their traffic. These devices are transformed into proxy networks: through these nodes, attackers launch new intrusions, steal data, and disrupt organizations' operations.

The issue was addressed in a joint alert issued by the UK's National Cyber Security Centre and 15 other government agencies from the US, Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain, and Sweden. The alert was also published on the CISA and NCSC websites . The document's authors believe that all organizations of interest to Chinese-linked hacker groups are at risk.

The use of botnets from hacked devices has long been known to security experts, but the scale and approach have changed. According to agencies, Chinese-linked groups have begun to systematically and massively exploit hidden networks. This infrastructure includes SOHO routers, network cameras, DVRs, firewalls, and network storage devices.

Some of these networks, according to the warning's authors, are created and maintained by Chinese information security companies. The document cites the example of Integrity Technology Group. The Chinese company operated the Raptor Train network, which infected over 200,000 devices worldwide in 2024. The botnet included small office and home routers, cameras, DVRs, firewalls, and NAS storage devices.

The FBI previously linked Integrity Technology Group to the activities of the Flax Typhoon group . Other groups in the Typhoon family, according to the alert, also use hidden networks as part of their infrastructure. Sometimes, multiple China-linked groups operate through the same proxy network.

The document specifically mentions Volt Typhoon. US authorities believe the group is linked to China and accuse it of infiltrating US critical infrastructure to prepare for future destructive attacks. For the KV Botnet, the attackers primarily used outdated Cisco and Netgear routers, which had already reached the end of their support lifespan.

The warning's authors chose not to detail all known hidden networks. The number of botnets is too large: some networks quickly emerge, others cease operations, and law enforcement shuts down some infrastructure. A complete catalog would be out of date almost immediately and would be of little help to administrators.

Experts advise organizations to start by taking into account edge devices and a baseline network traffic profile. Particular attention should be paid to VPNs , remote access, and unusual connections. Agencies also recommend using multi-factor authentication, zero-trust elements, IP whitelists, and machine certificate validation if the infrastructure supports such protection.

Large organizations and companies in risk groups are advised to look for suspicious traffic from SOHO devices and IoT equipment, and to use geographic profiling and machine-learning-based anomaly detection systems.

Similar methods aren't limited to state-sponsored hacker groups. Financially motivated criminals also hack routers and connected devices to conceal fraudulent transactions. In March, the FBI, along with law enforcement agencies in eight other countries, disrupted SocksEscort, a residential proxy service. Through the service, attackers exploited hundreds of thousands of compromised routers worldwide, causing millions of dollars in damage to companies and individual users.
 
6,252Threads
83,862Messages
6,016Members
PetraLatest member
Top Bottom