UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times

Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times

19 June 2026

A26 northbound between A259 and A27 | Northbound | Road Works

19 June 2026

link road from A26 northbound to A27 westbound | Northbound | Road Works

19 June 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Defending against China-nexus covert networks of compromised devices
News

Defending against China-nexus covert networks of compromised devices

By uk-times.com25 April 2026No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. Actors have been observed using them for each phase of their Cyber Kill Chains, from performing scans as part of reconnaissance, to the delivery of malware, communicating with said malware, and exfiltrating stolen data from a victim. They can also be used for general deniable internet browsing, allowing threat actors to research exploitation techniques, new TTPs, and their victims without attribution. Some covert networks are also used by legitimate customers to browse the internet, making it challenging to attribute malicious activity.

There is evidence that covert networks used by China-nexus actors are created and maintained by Chinese information security companies. A network known to network defenders as Raptor Train, which in 2024 infected more than 200,000 devices worldwide, was controlled and managed by the Chinese company, Integrity Technology Group. This company was also assessed by the FBI to be responsible for the computer intrusion activities attributed to China-based hackers known as Flax Typhoon.

“Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks” 

NCSC Director of Operations, Paul Chichester

Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices. The KV Botnet used by Volt Typhoon was mainly made up of vulnerable Cisco and NetGear routers. The edge devices were vulnerable because they were “end of life” – out of date and no longer receiving updates or security patches by their manufacturers.

The cyber security industry has been aware of examples of these networks for some time and has publicly reported on the widespread scale of the threat and its implications. Mandiant Intelligence produced a public blog in May 2024 talking about covert networks in which they highlighted a key issue for defenders – indicator of compromise (IOC) Extinction. If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defence paradigms of static malicious IP block lists will be less effective. This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use.
 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times

Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times

19 June 2026

A26 northbound between A259 and A27 | Northbound | Road Works

19 June 2026

link road from A26 northbound to A27 westbound | Northbound | Road Works

19 June 2026
Luigi Mangione’s lawyers withdraw psychiatric defense in CEO murder trial – UK Times

Luigi Mangione’s lawyers withdraw psychiatric defense in CEO murder trial – UK Times

19 June 2026

A26 southbound between A27 and A259 | Southbound | Road Works

19 June 2026
How Switzerland’s super-subs made World Cup statement with Bosnia bashing – UK Times

How Switzerland’s super-subs made World Cup statement with Bosnia bashing – UK Times

19 June 2026
Top News
Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times

Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times

19 June 2026

A26 northbound between A259 and A27 | Northbound | Road Works

19 June 2026

link road from A26 northbound to A27 westbound | Northbound | Road Works

19 June 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • Jonathan David’s hat trick propels Canada to its first World Cup win, 6-0 over Qatar – UK Times
  • A26 northbound between A259 and A27 | Northbound | Road Works
  • link road from A26 northbound to A27 westbound | Northbound | Road Works
  • NHL fans in uproar as popular presenter fired a month after she married her partner of five years
  • Luigi Mangione’s lawyers withdraw psychiatric defense in CEO murder trial – UK Times

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version