logo

China-Backed Hackers Are Industrializing Botnets

ID: b7cbe812-efc7-51af-a750-ac9b01f6d861

STIX ID: report--b7cbe812-efc7-51af-a750-ac9b01f6d861

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2026-04-23

Date Updated: 2026-04-24

Author: Jai Vijayan

...
...

This joint advisory warns that China-nexus actors and related entities are systematically building and maintaining large, dynamic covert botnets composed mostly of SOHO routers and IoT/edge devices, which are being used at scale for reconnaissance, malware delivery/C2, and data exfiltration. The advisory highlights an operational model of specialization (compromise, curation, provisioning, operational use) that increases scale and plausible deniability, makes attribution and static-mitigation approaches ineffective, and recommends defenders profile and harden network edge devices, apply zero-trust controls, and conduct targeted threat hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.