logo

Chinese botnet infects 260,000 SOHO routers, IP cameras with malware

ID: 52cd337c-7b27-5fc0-94f5-c6076e17784a

STIX ID: report--52cd337c-7b27-5fc0-94f5-c6076e17784a

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-09-18

Date Updated: 2026-04-20

Author: Ionut Ilascu

...
...

Black Lotus Labs and the FBI disrupted “Raptor Train,” a multi‑tier botnet active since May 2020 that used a Mirai variant called Nosedive to infect over 260,000 routers, IP cameras, NVR/DVRs and NAS devices across sectors including military, government, telecom and higher education; the report attributes the operation to China-linked Flax Typhoon, documents use of zero‑day and known vulnerabilities (with targeted campaigns named Canary/Oriole), and notes that authorities executed court‑authorized actions to take control of infrastructure and remediate devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.