logo

China-linked threat actors use consumer device botnets to evade detection, warn UK and partners

ID: bc8f6f5c-c138-5236-b9eb-ea00a1146880

STIX ID: report--bc8f6f5c-c138-5236-b9eb-ea00a1146880

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Pierluigi Paganini

...
...

The UK NCSC and international partners warn that China-linked actors are increasingly using vast botnets of compromised SOHO/IoT devices as dynamic proxy networks to hide and route attacks across the full cyber kill chain; the advisory outlines mitigation measures (traffic baselining, MFA, zero trust, dynamic threat feeds, active hunting) and references the large Raptor Train botnet attributed to Flax Typhoon/Ethereal Panda.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.