惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
L
LangChain Blog
I
InfoQ
D
Docker
F
Fortinet All Blogs
Y
Y Combinator Blog
Martin Fowler
Martin Fowler
月光博客
月光博客
B
Blog
Engineering at Meta
Engineering at Meta
T
Tailwind CSS Blog
罗磊的独立博客
博客园_首页
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
IT之家
IT之家
V
V2EX

Cybersecurity Dive - Latest News

Dozens of Red Hat npm packages targeted in supply chain attack Turning tension into collaboration: How CIOs and CISOs can lead together Trump signs EO seeking early government access to powerful AI models Anthropic shares Mythos with 150 more organizations, including critical infrastructure operators Without strong governance, companies put credit ratings at risk in AI era CISA adds critical Palo Alto Networks firewall flaw to KEV as company, researchers warn of exploitation How Canva scaled to 260+M users while elevating security and productivity Top 4 data security best practices for the AI-enabled enterprise CISA urges security teams to check for software development compromises How CISOs can manage sovereign-cloud security risks IBM’s new $5B initiative will help enterprises rapidly patch open-source vulnerabilities Enterprise data is creeping its way into shadow AI tools Coordinated operation takes down Glassworm botnet Leading AI models are more vulnerable to malicious prompts than vendors claim Iranian government, not hacktivist group, breached LA Metro system, security firm says FBI warns about PhaaS platform used to access Microsoft 365 environments Iran-linked hackers target key US, allied sectors with sophisticated spear-phishing messages New York regulator calls for additional cyber mitigation amid heightened threat environment CISA asks cybersecurity community to alert it to vulnerability exploitation Grafana Labs links GitHub environment breach to TanStack npm supply chain attack 7-Eleven hit by data breach Microsoft disrupts cybercrime operation that hid behind legitimate software Compromised coding tool helped hackers breach thousands of GitHub repositories Telecom sector launches its own private ISAC Patch bypass allows hackers to exploit prior flaw in SonicWall SSL-VPN Grafana Labs says hacker gained access to codebase through leaked token How a government contest launched a revolution in AI-based bug hunting Attackers exploit critical flaw in Cisco Catalyst SD-WAN Controller MSPs need AI to fight AI-fueled cyberthreats: Guardz More money is going to physical security, but it’s often CISOs that oversee it: EY
China disguises cyberattacks with ‘covert network’ botnet...
Eric Geller · 2026-04-23 · via Cybersecurity Dive - Latest News

Hackers working for the Chinese government are increasingly hiding their attacks behind ready-made networks of hacked routers and other networking equipment, the U.S. and several allies said on Thursday.

Attackers’ use of these so-called covert networks is not new, the agencies said in a joint advisory, “but China-nexus cyber actors are now using them strategically, and at scale.”

By funneling their activity through compromised networking equipment — mostly small office and home office (SOHO) routers, but also internet of things devices — hackers can obfuscate their origins and make it harder for defenders to spot reconnaissance, malware deployment and data exfiltration.

China-linked hackers used the KV Botnet, which included hundreds of malware-infected devices, for the Volt Typhoon attacks on U.S. critical infrastructure, and the Raptor Train botnet, which included more than 200,000 devices, for the Flax Typhoon attacks on Taiwan. Justice Department operations disrupted both of those botnets by removing the hackers’ malware from the infected devices.

Another China-linked SOHO botnet supported “a vast, prolonged intrusion operation” against Japan and Taiwan, according to a June 2025 report from SecurityScorecard, which dubbed the botnet LapDog.

The U.S. and its allies have evidence that Chinese cybersecurity companies build and maintain covert networks for Beijing’s use, according to the new advisory.

The Cybersecurity and Infrastructure Security Agency, the FBI, the NSA, and the Department of Defense’s Cyber Crime Center issued the alert with cybersecurity and intelligence agencies from Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain and Sweden.

Router hacking frenzy

Other governments have used botnets to disguise their cyberattacks. In April, the FBI erased malware from SOHO routers that Russia’s military intelligence agency was using to hack government and critical infrastructure organizations.

Concerns about routers’ security vulnerabilities have grown so intense that the Federal Communications Commission in March banned the import of foreign-made routers, saying the devices represented too great of a supply-chain risk. In mid-April, the FCC exempted Netgear routers from the ban.

What defenders can do

To prevent their internet-connected devices from becoming part of a covert network, the advisory said, security professionals should map their networks, develop clear understandings of what normal connectivity looks like, consult threat intelligence about botnets and require remote connections to use multifactor authentication.

High-risk organizations should consider using IP allowlisting and other access controls to limit external connections, requiring SSL certificates, segmenting networks and otherwise applying zero-trust principles, according to the advisory.

“If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defense paradigms of static malicious IP block lists will be less effective,” the advisory warned. “This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use.”

Correction: A previous version of this story misstated the extent of Netgear’s exception to the FCC router import ban.