Chinese botnet infects 260,000 SOHO routers, IP cameras with malware
ID: 52cd337c-7b27-5fc0-94f5-c6076e17784a
STIX ID: report--52cd337c-7b27-5fc0-94f5-c6076e17784a
Feed Name: Bleeping Computer
Black Lotus Labs and the FBI disrupted “Raptor Train,” a multi‑tier botnet active since May 2020 that used a Mirai variant called Nosedive to infect over 260,000 routers, IP cameras, NVR/DVRs and NAS devices across sectors including military, government, telecom and higher education; the report attributes the operation to China-linked Flax Typhoon, documents use of zero‑day and known vulnerabilities (with targeted campaigns named Canary/Oriole), and notes that authorities executed court‑authorized actions to take control of infrastructure and remediate devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
