Site navigation

NCSC Warns of Covert China-linked Networks

Elizabeth Greenberg

,

china covert networks network security
“The NCSC will not shy away from shining a light of these techniques and we call on organisations to act now to better defend their critical assets,” Paul Chichester, NCSC Director of Operations said.

International cyber agencies are calling on organisations to understand and better defend against the cyber threat from covert networks by following new joint advice.

The National Cyber Security Centre (NCSC)  alongside industry and 15 international partners from across nine other countries, have issued a new advisory highlighting how to defend against these attacker tactics which are believed to be used by the majority of China-linked actors to obscure malicious cyber activity.

Covert networks are often made up of vulnerable everyday internet-connected edge devices, such as home routers and smart devices, that have been compromised. These networks are being leveraged at scale to target critical sectors globally, steal sensitive data, and maintain persistent access.

The new advisory, produced with members of the NCSC’s Cyber League programme with industry, has been published on the second day of the UK government’s flagship CYBERUK conference and is designed to assist organisations with the latest protective advice.

It includes comprehensive mitigation advice to help defend against activity originating from a covert network.

It also warns of a key issue for network defenders: IOC extinction, where indicators of compromise disappear as quickly as they are discovered, requiring more adaptive, intelligence-driven measures to mitigate the risks.

“Our new joint advisory consolidates insights and proactive advice from across the international cyber security community to help network defenders combat the use of covert networks,” Paul Chichester, NCSC Director of Operations said.

“In recent years, we have seen a deliberate shift in cyber groups based in China utilising these networks to hide their malicious activity in an attempt to avoid accountability.

“The NCSC will not shy away from shining a light of these techniques and we call on organisations to act now to better defend their critical assets.”

The advisory describes how covert networks used by China-linked actors are being created and maintained, externally, by Chinese information security companies.


Recommended reading


In September 2024, alongside international partners, the NCSC called out, an information security company based in China, Integrity Technology Group, for controlling and managing a botnet, which was utilised by Flax Typhoon.

In December 2025, the UK government sanctioned Integrity Technology Group alongside another China-based information security company, for their reckless and indiscriminate malicious cyber activity against the UK and its allies.

Small organisations are encouraged to use the free Cyber Action Toolkit, with larger organisations encouraged to secure Cyber Essentials certification and use the updated Cyber Assessment Framework.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data