15 Cyber Agencies Issue Joint Warning on China-Linked Covert Botnet Threat

Source Beincrypto

The National Cyber Security Centre (NCSC) and 15 international partners issued a joint advisory. It warns that China-linked threat actors are hiding attacks behind networks of compromised everyday internet devices.

The advisory details a major tactical shift. Groups affiliated with Beijing now route activity through hundreds of thousands of compromised home routers and smart devices. That approach replaces dedicated attacker infrastructure.

Botnets Built From Compromised Home Devices

The document identifies a pattern across Volt Typhoon and Flax Typhoon operations. In each case, traffic passes through compromised small office and home office routers before reaching its target.

These covert networks help China-linked operators scan targets, deliver malware, and exfiltrate data. They also obscure the origin of each attack.

Raptor Train, one such network, infected more than 200,000 devices worldwide in 2024, according to the NCSC. The FBI attributed its management to Integrity Technology Group, a Beijing-based cybersecurity firm.

The United Kingdom sanctioned the company in December 2025 for reckless cyber activity against its allies.

Many of the compromised machines are end-of-life web cameras, video recorders, firewalls, and network storage devices. These no longer receive security patches from manufacturers. That leaves them easy targets for bulk exploitation.

GCHQ’s National Cyber Security Centre with UK industry and 15 international partners, Source: NCSC

Western Infrastructure Already Pre-Positioned

Volt Typhoon has used a separate covert network called the KV Botnet. The group established footholds on critical national infrastructure across the United States and allied countries.

Department of Justice filings referenced in the advisory support this finding. Energy grids, transport systems, and government networks are named as active targets.

Paul Chichester, NCSC Director of Operations, flagged a separate problem known as indicator of compromise extinction. Identifiers used to track attackers disappear almost as fast as researchers publish them.

The problem mirrors wider difficulties in tracking state-backed hacking campaigns across both critical infrastructure and financial sectors.

In recent years, we have seen a deliberate shift in cyber groups based in China utilising these networks to hide their malicious activity in an attempt to avoid accountability,” Paul Chichester, NCSC Director of Operations.

The advisory urges organisations to baseline normal network traffic and adopt dynamic threat feeds. It also recommends tracking China-linked covert networks as advanced persistent threats in their own right.

2024 recorded more than $2 billion in digital-asset losses from cyber activity. The coming months will test whether defenders can keep pace. The adversary has made attribution itself the first victim.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Semiconductor Sector Continues to Rise, Should Retail Investors Buy Intel or AMD? On April 23, Eastern Time, Intel (INTC) reported its latest quarterly earnings results, showing that revenue grew 7% to $13.6 billion and earnings per share was $0.29, beating expectation
Author  TradingKey
5 hours ago
On April 23, Eastern Time, Intel (INTC) reported its latest quarterly earnings results, showing that revenue grew 7% to $13.6 billion and earnings per share was $0.29, beating expectation
placeholder
Gold drops below $4,700 on stronger US Dollar, Middle East tensions Gold price (XAU/USD) falls to around $4,690 during the early Asian session on Friday. The precious metal attracts some sellers amid a stronger US Dollar (USD) and elevated oil prices that stoked inflation worries. 
Author  FXStreet
14 hours ago
Gold price (XAU/USD) falls to around $4,690 during the early Asian session on Friday. The precious metal attracts some sellers amid a stronger US Dollar (USD) and elevated oil prices that stoked inflation worries. 
placeholder
Silver Price Forecast: XAG/USD plummets below $76 as oil price posts fresh weekly highSilver price (XAG/USD) is down almost 2.3% to near $76.00 during the European trading session on Thursday. The white metal faces selling pressure as oil prices extends its winning streak for the third trading day on Thursday.
Author  FXStreet
Yesterday 10: 10
Silver price (XAG/USD) is down almost 2.3% to near $76.00 during the European trading session on Thursday. The white metal faces selling pressure as oil prices extends its winning streak for the third trading day on Thursday.
placeholder
WTI sticks to positive bias above $92.00 amid Middle East tensionsWest Texas Intermediate (WTI) – the benchmark US Crude Oil price – fades an Asian session spike to the $95.80-$95.85 area, or a one-and-a-half-week top, and retreats to the lower end of its daily range in the last hour.
Author  FXStreet
Yesterday 01: 24
West Texas Intermediate (WTI) – the benchmark US Crude Oil price – fades an Asian session spike to the $95.80-$95.85 area, or a one-and-a-half-week top, and retreats to the lower end of its daily range in the last hour.
placeholder
JPMorgan Raises S&P 500 Target; Can AI Sector Continue to Drive US Stocks?JPMorgan Chase has raised its year-end target for the S&P 500, noting that the core driver is not a simple recovery in sentiment, but rather upward earnings revisions for AI-related techn
Author  TradingKey
Apr 22, Wed
JPMorgan Chase has raised its year-end target for the S&P 500, noting that the core driver is not a simple recovery in sentiment, but rather upward earnings revisions for AI-related techn
goTop
quote