Overview
- Led by the UK’s National Cyber Security Centre on Thursday, a joint advisory with German, US and other partners warned that China‑affiliated operators now route attacks through devices owned by small firms and households.
- The actors build large, campaign‑specific botnets from routers, smart cameras, DVRs, network storage and firewalls, including a 2024 network dubbed Raptor Train that spanned more than 200,000 devices for covert spying and data theft.
- Tracked groups such as Volt Typhoon and Flax Typhoon have used distinct concealment networks tailored to each operation, and officials cited signs of involvement by Chinese information‑security companies.
- Germany’s domestic intelligence service said compromised devices inside the country have been detected only when attackers used them in live operations, which shows how hard these takeovers are to spot.
- Agencies urged basic defenses like prompt firmware updates, network traffic checks, clear segmentation and multi‑factor logins for remote access, and they reported no public response yet from China’s foreign ministry.