Executive brief
State-sponsored actors are increasingly using large-scale networks of compromised small-office/home-office (SOHO) routers and Internet of Things (IoT) devices to hide their malicious activities. These 'covert networks' allow attackers to conduct reconnaissance, deliver malware, and steal data while appearing as legitimate internet traffic, making it difficult for organizations to identify and block them. This shift in tactics poses a significant risk to critical infrastructure and corporate data by bypassing traditional security filters that rely on known malicious addresses.
Technical details
China-nexus threat actors (such as Volt Typhoon and Flax Typhoon) are utilizing large-scale botnets, or 'covert networks,' composed of compromised SOHO routers, IoT devices, and end-of-life hardware. These networks, such as Raptor Train and KV Botnet, are used to route malicious traffic for reconnaissance, malware delivery, and data exfiltration, effectively neutralizing static IP blocklists. The root cause is often the exploitation of unpatched vulnerabilities in edge devices that are no longer supported by manufacturers. Attackers leverage these multi-tier proxy architectures to maintain anonymity and persistence within target environments, particularly critical national infrastructure. Defenders are advised to move beyond static IOCs and focus on behavioral analysis and securing edge device configurations.
Affected products
- Various (Cisco, Netgear, etc) SOHO Routers
- Generic IoT Devices (Webcams, DVRs)
- Generic Network Attached Storage (NAS)
- Generic Firewalls
Timeline
- 2026-04-23: advisory: Joint advisory released by CISA, NCSC-UK, and international partners.