UK TimesUK Times
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
What's Hot
Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times

Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times

25 April 2026

A47 westbound between A148 and A17 | Westbound | Road Works

25 April 2026
NFL reveals the Dallas Cowboys’ opponent for first-ever game in Rio de Janeiro next season

NFL reveals the Dallas Cowboys’ opponent for first-ever game in Rio de Janeiro next season

25 April 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
UK TimesUK Times
Subscribe
  • Home
  • News
  • TV & Showbiz
  • Money
  • Health
  • Science
  • Sports
  • Travel
  • More
    • Web Stories
    • Trending
    • Press Release
UK TimesUK Times
Home » Defending against China-nexus covert networks of compromised devices
News

Defending against China-nexus covert networks of compromised devices

By uk-times.com25 April 2026No Comments3 Mins Read
Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
Share
Facebook Twitter LinkedIn Pinterest Email

Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. Actors have been observed using them for each phase of their Cyber Kill Chains, from performing scans as part of reconnaissance, to the delivery of malware, communicating with said malware, and exfiltrating stolen data from a victim. They can also be used for general deniable internet browsing, allowing threat actors to research exploitation techniques, new TTPs, and their victims without attribution. Some covert networks are also used by legitimate customers to browse the internet, making it challenging to attribute malicious activity.

There is evidence that covert networks used by China-nexus actors are created and maintained by Chinese information security companies. A network known to network defenders as Raptor Train, which in 2024 infected more than 200,000 devices worldwide, was controlled and managed by the Chinese company, Integrity Technology Group. This company was also assessed by the FBI to be responsible for the computer intrusion activities attributed to China-based hackers known as Flax Typhoon.

“Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks” 

NCSC Director of Operations, Paul Chichester

Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices. The KV Botnet used by Volt Typhoon was mainly made up of vulnerable Cisco and NetGear routers. The edge devices were vulnerable because they were “end of life” – out of date and no longer receiving updates or security patches by their manufacturers.

The cyber security industry has been aware of examples of these networks for some time and has publicly reported on the widespread scale of the threat and its implications. Mandiant Intelligence produced a public blog in May 2024 talking about covert networks in which they highlighted a key issue for defenders – indicator of compromise (IOC) Extinction. If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defence paradigms of static malicious IP block lists will be less effective. This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use.
 

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Related News

Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times

Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times

25 April 2026

A47 westbound between A148 and A17 | Westbound | Road Works

25 April 2026

M54 westbound within J3 | Westbound | AuthorityOperation

25 April 2026

‘Falklands tell Trump to back off’ and ‘Harry does a Diana’ | UK News

25 April 2026
Growing wildfires in Georgia leave one firefighter dead and 120 homes destroyed – UK Times

Growing wildfires in Georgia leave one firefighter dead and 120 homes destroyed – UK Times

25 April 2026

A303 eastbound between B3048 and A34 | Eastbound | AuthorityOperation

25 April 2026
Top News
Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times

Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times

25 April 2026

A47 westbound between A148 and A17 | Westbound | Road Works

25 April 2026
NFL reveals the Dallas Cowboys’ opponent for first-ever game in Rio de Janeiro next season

NFL reveals the Dallas Cowboys’ opponent for first-ever game in Rio de Janeiro next season

25 April 2026

Subscribe to Updates

Get the latest UK news and updates directly to your inbox.

Recent Posts

  • Casino operator with machines in three states shuts down one of its locations as financial woes continue – UK Times
  • A47 westbound between A148 and A17 | Westbound | Road Works
  • NFL reveals the Dallas Cowboys’ opponent for first-ever game in Rio de Janeiro next season
  • M54 westbound within J3 | Westbound | AuthorityOperation
  • ‘Falklands tell Trump to back off’ and ‘Harry does a Diana’ | UK News

Recent Comments

No comments to show.
© 2026 UK Times. All Rights Reserved.
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact Us

Type above and press Enter to search. Press Esc to cancel.

Go to mobile version