Full Breakdown
China-Linked Hackers Deploy Global Covert Networks of Compromised Devices
4/24/2026, 12:35:34 PM
Joint Advisory Details the Shift to Large-Scale Covert Networks
A joint advisory released on 23 April 2026 by the UK National Cyber Security Centre (NCSC) and 15 international partners warns that China-nexus actors are increasingly using “covert networks” – botnets built from compromised small-office/home-office (SOHO) routers, Internet-of-Things (IoT) and other smart devices – to conceal malicious activity. Partner agencies include the United States Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA, Australia’s Australian Cyber Security Centre (ACSC), Canada’s Canadian Centre for Cyber Security (Cyber Centre), Germany’s BfV, BND and BSI, Japan’s National Cybersecurity Office, the Netherlands’ AIVD and MIVD, New Zealand’s NCSC-NZ, Spain’s CCN, Sweden’s NCSC-SE and others.
Background: Evolution of China-Nexus Tactics
The advisory notes a “major shift” from individually procured infrastructure to externally provisioned, large-scale networks of compromised devices. These networks are constantly updated, and a single botnet may be shared by multiple threat actors.
Key Actors and Supporting Agencies
State-backed groups identified include Volt Typhoon, which has pre-positioned on U.S. communications, energy, transport and water systems, and Flax Typhoon, which conducts cyber-espionage using a separate botnet. The advisory attributes creation and maintenance of the networks to Chinese information-security firms such as Integrity Technology Group, which was sanctioned by the UK in December 2025. Supporting agencies span the Five Eyes alliance (UK, US, Canada, Australia, New Zealand) and ten additional nations.
Scale and Scope: Data on Compromised Devices
- Botnet “Raptor Train” infected ? 200 000 devices worldwide.
- Flax Typhoon’s network comprised ? 260 000 routers, firewalls, webcams and CCTV cameras.
- Routers now contain an average of 32 security flaws each, more than double the average for computers, and account for ? 33 % of the most critical vulnerabilities (Forescout 2026).
- Multiple covert networks are reported to be active simultaneously, each capable of rapid reconfiguration.
Implications for Critical Infrastructure and Espionage
Covert networks enable actors to launch reconnaissance, malware delivery, command-and-control and data exfiltration while masking origin. Volt Typhoon’s foothold in rail, aviation and water services illustrates the risk to critical national infrastructure (CNI). Flax Typhoon’s espionage activities target government and commercial entities across several countries, extending the reach of Chinese state-sponsored intelligence operations.
Official Statements and Government Responses
- Paul Chichester, NCSC Director of Operations, said the shift “allows cyber groups based in China to hide their malicious activity in an attempt to avoid accountability.”
- Richard Horne, NCSC Chief Executive, described China’s intelligence and military agencies as having an “eye-watering level of sophistication in their cyber-operations.”
- Nick Andersen, CISA Acting Director, affirmed that “CISA continues to identify and warn organizations of Chinese state-sponsored cyber actors threatening critical infrastructure.”
- The UK government sanctioned Integrity Technology Group for “reckless and indiscriminate malicious cyber activity.”
- The Chinese foreign ministry offered no comment.
Criticism, Opposition, and Gaps
Chinese officials’ silence is noted as a direct opposition to the allegations. Discrepancies exist between reported botnet sizes (200 000 vs 260 000 devices) and the advisory provides limited technical detail on how private Chinese firms construct the networks, leaving a gap in attribution evidence.
Recommendations for Defenders
Agencies advise organisations to: map all IT assets—including consumer broadband links; enforce multi-factor authentication for remote access; restrict connections to external devices; adopt adaptive, intelligence-driven traffic monitoring; conduct active hunting and maintain dynamic blocklists; use the free Cyber Action Toolkit for small firms and pursue Cyber Essentials certification for larger entities.
Verbatim Quotes
- “In recent years, we have seen a deliberate shift in cyber groups based in China utilising these networks to hide their malicious activity in an attempt to avoid accountability.” — Paul Chichester, NCSC Director of Operations
- “we know that China’s intelligence and military agencies now display an eye-watering level of sophistication in their cyber operations.” — Richard Horne, NCSC Chief Executive
- “and international partners, CISA continues to identify and warn organizations of Chinese state-sponsored cyber actors threatening critical infrastructure,” CISA Acting Director Nick Andersen said Thursday.” — Nick Andersen, CISA Acting Director
- “Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity.” — NCSC advisory
What’s Next
The advisory will be updated quarterly as new botnet activity emerges. Joint cyber-exercise drills among the 15 partner nations are planned for later 2026, and further sanctions against firms facilitating covert networks are under consideration.
