23 Avril

UK NCSC warns China-nexus hackers have switched to botnet infrastructure

Ten countries issued a joint advisory on Wednesday warning that China-linked hacking groups have fundamentally changed their infrastructure strategy. Instead of individually procured servers, the majority now rely on massive botnets of compromised consumer devices.

The UK National Cyber Security Centre (NCSC-UK), along with agencies from the United States, Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain, and Sweden, published the advisory on April 23, 2026.

The shift to covert networks

Chinese cyber actors now operate large-scale “covert networks” built from hijacked routers, cameras, NAS devices, and other IoT equipment. These are not just delivery mechanisms. The botnets handle reconnaissance, command and control, malware hosting, and data exfiltration.

“The NCSC believes that the majority of China-nexus threat actors are using these networks,” the advisory states. Multiple covert networks exist, constantly updated, with single networks potentially shared across multiple hacking groups.

Why this matters

Traditional defense relies heavily on IP blocklists. That model breaks here.

Because these networks refresh constantly and share nodes across groups, security teams face what the NCSC calls “IOC extinction” - indicators of compromise vanish as quickly as analysts discover them. Static defenses become obsolete almost immediately.

The advisory cites known Chinese botnets like Raptor Train, which infected over 260,000 devices before FBI disruption in September 2024. KV-Botnet is another example, used by groups including Volt Typhoon.

The technical reality

SOHO routers make up the bulk of compromised devices. Home office gear, security cameras, video recorders, network storage. The boring edge infrastructure that everyone has and few monitor closely.

Attackers route traffic through chains of these devices - entering at one node, hopping through intermediates, exiting near targets to mask geographic origin. The result is deniable, dynamic infrastructure that reshapes faster than defenders can map it.

What the NCSC recommends

The guidance splits by organization size but shares core principles:

  • Map and baseline edge device traffic - Know what your VPN and remote access connections should look like
  • Dynamic threat feeds - Static blocklists are insufficient; you need continuously updated indicators
  • Zero trust controls - Machine certificate verification, IP allowlists, two-factor authentication for remote access
  • Active hunting - Larger organizations should hunt for suspicious SOHO/IoT traffic patterns and use ML-based anomaly detection

The advisory is explicit: organizations relying solely on static defenses risk being bypassed. Adaptive, intelligence-driven measures are now essential.

Background context

This is not theoretical. The FBI disrupted the Raptor Train botnet in September 2024 after linking it to Flax Typhoon, a Chinese state-sponsored group targeting military, government, and telecommunications sectors. Integrity Technology Group, a Chinese company linked to the operation, was sanctioned in January 2025.

Volt Typhoon, another Chinese group, has used similar covert infrastructure to target critical infrastructure in the US and Guam.

The NCSC advisory represents formal acknowledgment from ten major cyber agencies that this tactic has become the standard operating procedure for Chinese cyber operations, not an exception.

Mots-cles

cybersecurity china botnet ncsc covert networks infrastructure threat intelligence