Particle.news
Download on the App Store

Western Agencies Warn China-Linked Hackers Are Hiding Behind Hijacked Home and Small-Business Devices

Tailored botnets now mask intrusions, leaving many victims unaware.

Overview

  • Led by the UK’s National Cyber Security Centre on Thursday, a joint advisory with German, US and other partners warned that China‑affiliated operators now route attacks through devices owned by small firms and households.
  • The actors build large, campaign‑specific botnets from routers, smart cameras, DVRs, network storage and firewalls, including a 2024 network dubbed Raptor Train that spanned more than 200,000 devices for covert spying and data theft.
  • Tracked groups such as Volt Typhoon and Flax Typhoon have used distinct concealment networks tailored to each operation, and officials cited signs of involvement by Chinese information‑security companies.
  • Germany’s domestic intelligence service said compromised devices inside the country have been detected only when attackers used them in live operations, which shows how hard these takeovers are to spot.
  • Agencies urged basic defenses like prompt firmware updates, network traffic checks, clear segmentation and multi‑factor logins for remote access, and they reported no public response yet from China’s foreign ministry.