NCSC-UK joint advisory on covert botnets and proxy networks
Public Sector Action
Summary
Hide ▲
Show ▼
NCSC-UK and partner agencies issued a joint advisory warning that China-nexus hackers are using hijacked consumer devices as covert proxy networks to hide malicious traffic. The warning spans SOHO routers, internet-connected cameras, video recorders, and NAS equipment across multiple countries. It matters because the networks help attackers evade detection and make static IP-based blocking less effective.
Related Happenings
CISA-led joint advisory on Russian router targeting
Public Sector Action
H score32
First: 14.07.2026 15:00
Last: 14.07.2026 15:00
Sources 1
About this happening:
CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
CISA-led joint advisory on Russian router targeting
Public Sector ActionAbout this happening: CISA and partner agencies released a joint cybersecurity advisory warning that Russian state-sponsored actors are targeting vulnerable networking devices in crit...
OFAC sanctions First VPN Service and two individuals
Regulatory/Legal Action
H score27
First: 14.07.2026 11:02
Last: 14.07.2026 11:02
Sources 1
About this happening:
OFAC sanctioned First VPN Service (1VPNS), Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev for enabling ransomware attacks and helping malicious software...
OFAC sanctions First VPN Service and two individuals
Regulatory/Legal ActionAbout this happening: OFAC sanctioned First VPN Service (1VPNS), Dmytro Rashevskyi, and Yegeniy Vladimirovich Silayev for enabling ransomware attacks and helping malicious software...
Cybersecurity agencies from 12 countries fresh warning / joint advisory for published on 2026-07-13
Public Sector Action
H score53
First: 13.07.2026 13:40
Last: 13.07.2026 13:40
Sources 1
About this happening:
Cybersecurity agencies from 12 countries issued a fresh advisory urging defenders to harden vulnerable routers amid active targeting by a Russian state-sponsored cyber u...
Cybersecurity agencies from 12 countries fresh warning / joint advisory for published on 2026-07-13
Public Sector ActionAbout this happening: Cybersecurity agencies from 12 countries issued a fresh advisory urging defenders to harden vulnerable routers amid active targeting by a Russian state-sponsored cyber u...
Russian FSB Center 16 router intrusion campaign
Campaign
H score40
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Russian FSB Center 16 router intrusion campaign
CampaignAbout this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
NSA/FBI/CISA router hardening advisory
Advisory/Mitigation
H score33
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...
NSA/FBI/CISA router hardening advisory
Advisory/MitigationAbout this happening: NSA, FBI, CISA and 15 allied agencies issued a joint router hardening advisory after hackers targeted vulnerable and poorly configured routers in critical infrastruc...
Timeline
-
23.04.2026 15:28 2 articles · 2mo ago
NCSC-UK joint advisory warns of hijacked-device proxy networks
Industry Or Public Sector UpdateOn 2026-04-23, NCSC-UK and partner agencies from the United States, Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain, and Sweden issued a joint advisory warning that China-nexus hackers are increasingly using large-scale proxy networks built from hijacked consumer devices, including compromised Small Office Home Office (SOHO) routers, Internet of Things (IoT) and smart devices, video recorders, and network-attached storage (NAS) equipment, to route traffic through multiple nodes and evade geographic detection. The advisory also said static malicious-IP blocking is becoming less effective and urged multifactor authentication, network edge device mapping, dynamic threat feeds, IP allowlists, zero-trust controls, and machine certificate verification.
Show sources
- UK warns of Chinese hackers using proxy networks to evade detection — www.bleepingcomputer.com — 23.04.2026 15:28
- In Other News: Unauthorized Mythos Access, Plankey CISA Nomination Ends, New Display Security Device — www.securityweek.com — 24.04.2026 17:31