Foreign-run botnets relaying traffic through infected Canadian devices
Malware Activity
Summary
Hide ▲
Show ▼
The public ruling confirms two foreign-run botnets used infected Canadian devices as traffic relays, a setup that can conceal probing of critical infrastructure, government, and military networks. The botnets relied on a command tier and a relay layer of compromised devices, including servers, SOHO routers, and IoT gear. The activity mattered because the relay pattern let operators blend malicious traffic into ordinary-looking connections and increase stealth. The same infrastructure also created a path for potential disruption against sensitive networks.
Related Happenings
Russian FSB Center 16 router intrusion campaign
Campaign
H score40
First: 13.07.2026 12:32
Last: 13.07.2026 12:32
Sources 1
About this happening:
A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
Russian FSB Center 16 router intrusion campaign
CampaignAbout this happening: A Russian FSB Center 16 campaign is targeting vulnerable and poorly configured routers to infiltrate critical infrastructure networks, raising the risk of device takeo...
FBI seizure of NetNut proxy domains
Law Enforcement
H score33
First: 03.07.2026 12:35
Last: 03.07.2026 12:35
Sources 1
About this happening:
The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
FBI seizure of NetNut proxy domains
Law EnforcementAbout this happening: The FBI seized NetNut domains in a law-enforcement takedown of proxy infrastructure abused for cybercrime, disrupting a network that routed malicious traffic through r...
CSIS court-authorized botnet disruption on Canadian devices
Public Sector Action
H score25
First: 22.06.2026 12:11
Last: 22.06.2026 12:11
Sources 1
How related:
Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.
About this happening:
CSIS used a judge-authorized threat reduction warrant to disrupt two foreign-run botnets on Canadian devices, marking the service's first use of those powers in th...
CSIS court-authorized botnet disruption on Canadian devices
Public Sector ActionHow related: Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.
About this happening: CSIS used a judge-authorized threat reduction warrant to disrupt two foreign-run botnets on Canadian devices, marking the service's first use of those powers in th...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
Campaign
H score88
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Vo1d botnet campaign targeting unofficial Android-based TV boxes
CampaignAbout this happening: NetNut used the Popa botnet and deceptive SDKs on off-brand Android-based smart TVs, streaming media boxes, and unofficial apps to turn home connections into residen...
Latest development: 03.07.2026 12:35
Google disabled all Google accounts used by NetNut for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing the compromised SDKs. The FBI’s seizure banner appeared on netnut.com while netnut.io briefly remained accessible, and Google said the coordinated actions caused significant degradation to NetNut’s proxy network and business operations.
Popa botnet forcing consumer TV boxes to relay traffic
Malware Activity
H score76
First: 18.06.2026 20:37
Last: 18.06.2026 20:37
Sources 1
About this happening:
Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Popa botnet forcing consumer TV boxes to relay traffic
Malware ActivityAbout this happening: Popa is an Android-based botnet that turns consumer TV boxes and related devices into relay infrastructure, maintaining encrypted connectivity and opening tunnels on d...
Latest development: 03.07.2026 12:35
Google disabled NetNut accounts used for malware command-and-control, updated Google Play Protect to warn Android users, and disabled apps containing compromised SDKs while FBI legal actions and domain seizures targeted NetNut infrastructure. The coordinated disruption was described as degrading NetNut’s proxy network and shrinking the pool of devices available to the operator.
Timeline
-
22.06.2026 12:11 1 articles · 23d ago
Federal Court grants CSIS first-of-its-kind botnet disruption warrant
Legal Policy Action UpdateJustice Catherine Kane granted CSIS a first-of-its-kind threat reduction warrant authorizing remote alteration, degradation, and destruction of botnet data on Canada-based servers, SOHO routers, and IoT devices, and allowing the devices to be cut loose from the networks after the court found the threat to Canada clearly established and imminent.
Show sources
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices — thehackernews.com — 22.06.2026 12:11
-
22.06.2026 12:11 2 articles · 23d ago
Federal Court publicly releases redacted ruling on CSIS botnet cleanup
Initial DisclosureThe Federal Court made public a redacted ruling revealing that CSIS had been authorized to reach into infected Canadian servers, SOHO routers, and IoT devices to neutralize two foreign-run botnets, marking the first public use of CSIS threat reduction warrant powers in this way.
Show sources
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices — thehackernews.com — 22.06.2026 12:11
- Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices — thehackernews.com — 22.06.2026 12:11