Site navigation

NCSC Issues Advisory to Combat China-linked Cyber Threat

Tom Quinn

,

botnet attack
“Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks,” said NCSC director of operations, Paul Chichester.

The UK’s National Cyber Security Centre (NCSC) and international allies, including the FBI and NSA, are urging individuals and organisations to take protective action after exposing a global network of compromised internet-connected devices operated by a China-linked company and used for malicious purposes.

The new advisory, issued alongside partners in the United States, Australia, Canada, and New Zealand, reveals that a company based in China and with links to China’s government has managed a botnet consisting of over 260,000 compromised devices around the world.

A botnet is a network of internet-connected devices, infected with malware and used to conduct coordinated cyber-attacks without the device owners’ knowledge.

According to the advisory, threat actors have compromised thousands of routers, firewalls, and Internet of Things (IoT) devices, including webcams and CCTV cameras, which could be used for a variety of malicious purposes, such as anonymous malware delivery and distributed denial of service (DDoS) attacks.

The advisory names Integrity Technology Group as responsible for controlling and managing the botnet, which has been active since mid-2021, and has been utilised by the malicious threat actor commonly known as Flax Typhoon.

Victim devices have already been identified in North America, South America, Europe, Africa, Southeast Asia and Australia.

To recruit a new ‘bot’, the botnet system first compromises an internet-connected device using a known vulnerability, which in turn provides access to establish a remote command and control execution.

“Whilst the majority of botnets are used to conduct coordinated DDoS attacks, we know that some also have the ability to steal sensitive information,” said Paul Chichester, NCSC director of operations.

“That’s why the NCSC, along with our partners in Five Eyes countries, is strongly encouraging organisations and individuals to act on the guidance set out in this advisory – which includes applying updates to internet-connected devices – to help prevent their devices from joining a botnet.”


Recommended reading


To help defend against malicious activity delivered through this botnet, security organisations recommend disabling unused services and ports, implement network segmentation, monitor for high network traffic volume, and apply regular patches and updates.

Fresh research has shown that bot attacks are responsible for up to £87.8 billion in damages every year across the world, with a recent increase in bot attacks fuelled by the widespread availability of attack tools and genAI models which have enhanced bot evasion techniques and lowered the barrier of entry for attackers to launch sophisticated attacks.

Tom Quinn

Staff Writer, DIGIT

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far