logo

A dozen allied agencies say China is building covert hacker networks out of everyday routers

ID: 3a8c7242-dfa2-5329-b54f-41bf3b9fefc3

STIX ID: report--3a8c7242-dfa2-5329-b54f-41bf3b9fefc3

Feed Name: CyberScoop

Threat Score
88/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Greg Otto

...
...

U.S. and international cybersecurity agencies warn that China-nexus actors are increasingly using large, externally provisioned covert networks of compromised SOHO routers and IoT devices—including botnets like Raptor Train (≈200,000 devices)—to enable reconnaissance, malware delivery, espionage, and pre-positioning against critical infrastructure; the advisory names groups such as Volt Typhoon and Flax Typhoon and recommends layered defensive measures and active hunting by high-risk organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.