logo

China-Backed Groups are Using Massive Botnets in Espionage, Intrusion Campaigns

ID: 6b957d57-41dc-5247-9b0c-51f3362190f5

STIX ID: report--6b957d57-41dc-5247-9b0c-51f3362190f5

Feed Name: Security Boulevard

Threat Score
85/100

Date Published: 2026-04-27

Date Updated: 2026-04-27

Author: Jeffrey Burt

...
...

CISA and partner agencies warn that China-nexus APTs are increasingly leveraging large botnets of compromised SOHO, IoT, and edge devices ("covert networks" such as Raptor Train and KV Botnet) to conduct reconnaissance, deliver malware, exfiltrate data, and stage deniable attacks against critical infrastructure and enterprise environments; the advisory calls out end-of-life routers, cameras, NAS, and other IoT as primary targets and urges improved device security and best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.