China-Linked Cyber Actors Turn to Massive Covert Botnets to Evade Detection
ID: 18b2faea-2569-5ffd-8e07-793f1df9d689
STIX ID: report--18b2faea-2569-5ffd-8e07-793f1df9d689
Feed Name: The Cyber Express
A coordinated advisory from the NCSC-UK and partners warns that China‑Nexus actors increasingly rely on large, dynamic covert networks of compromised SOHO routers, IoT devices, and other internet‑connected hardware to mask operations, route traffic, and pre-position capabilities; the report gives examples (Raptor Train, KV Botnet, Volt and Flax Typhoon), explains attribution and detection challenges (IOC extinction, node churn), and recommends inventorying edge devices, baselining activity, applying zero‑trust and allow‑listing, and using threat intelligence and ML for detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
