botnet Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/botnet/ Breaking news about the market for products, systems and services for the U.S. intelligence community Tue, 28 Apr 2026 11:30:36 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg botnet Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/botnet/ 32 32 59882712 NSA releases joint guidance on defending against China-nexus covert networks https://intelligencecommunitynews.com/nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-joint-guidance-on-defending-against-china-nexus-covert-networks Tue, 28 Apr 2026 11:30:36 +0000 https://intelligencecommunitynews.com/?p=44424 On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s...

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
On April 23, the National Security Agency (NSA) joined the United Kingdom’s National Cyber Security Centre, the Australian Signals Directorate’s Australian Cyber Security Centre, and others in releasing the joint Cybersecurity Advisory, “Defending against China-nexus covert networks of compromised devices.”

The CSA details how multiple China-nexus threat actors are now using external covert networks to facilitate malicious cyber activity strategically, at scale. These dynamic covert networks include botnets that leverage many compromised devices to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. These botnets frequently include compromised small office/home office network infrastructure (routers, firewalls, network attached storage, etc.) and internet of things devices (web cameras, video recorders, smart devices, etc.).

While many new covert infrastructure networks are regularly developed and deployed for use by multiple China-nexus threat actors, existing networks are also updated because of defensive or legal action, software updates, or new exploits being used to target different technologies, according to the CSA. This renders a detailed list of all known networks (how they are constructed and communicated) and previous defense paradigms ineffective. Legitimate users also browse the internet using the networks and devices involved, making attribution of the malicious activity challenging. However, since most networks of compromised infrastructure use the same basic set up, understanding the generalized structure can help aid in defensive efforts.

This CSA explains the widespread shift in tactics, techniques, and procedures by malicious cyber actors away from using individually procured infrastructure to multiple externally managed large covert networks used by many actors simultaneously. It describes the typical makeup of a covert network and how it is used, and includes protective advice for organizations targeted by cyber activity using a covert network as an access vector. Additionally, the guidance outlines tailored steps organizations of all sizes can take to mitigate the risk of attacks.

Anyone who is a target of China-nexus threat actors may be impacted by the use of covert networks, and anyone using a vulnerable device could have their device co-opted into one of these China-nexus covert networks. Cybersecurity analysts and network defenders — including those protecting national security, Department of War, and Defense Industrial Base systems — are advised to use the protective advice and mitigations listed in this CSA to thwart malicious activities.

Read the full report.

Source: NSA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post NSA releases joint guidance on defending against China-nexus covert networks appeared first on Intelligence Community News.

]]>
44424
NSA warns about PRC-Linked actors and botnet operations https://intelligencecommunitynews.com/nsa-warns-about-prc-linked-actors-and-botnet-operations/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-warns-about-prc-linked-actors-and-botnet-operations Fri, 20 Sep 2024 12:26:48 +0000 https://intelligencecommunitynews.com/?p=39799 On September 18, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the United States Cyber Command’s Cyber...

The post NSA warns about PRC-Linked actors and botnet operations appeared first on Intelligence Community News.

]]>
On September 18, the National Security Agency (NSA) joined the Federal Bureau of Investigation (FBI), the United States Cyber Command’s Cyber National Mission Force (CNMF), and international allies in releasing new information about People’s Republic of China (PRC)-linked cyber actors who have compromised internet-connected devices worldwide to create a botnet and conduct malicious activity.

The Cybersecurity Advisory (CSA) released by the agencies, “People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations,” highlights the threat posed by these actors and their botnet, a network of compromised nodes positioned for malicious activity.

“The botnet incorporates thousands of U.S. devices with victims in a range of sectors,” said Dave Luber, NSA cybersecurity director. “The advisory provides new and timely insight into the botnet infrastructure, the countries where compromised devices are located, and mitigations for securing devices and eliminating this threat.”

Device vendors, owners, and operators are encouraged to update and secure their devices – particularly older devices – from being compromised and joining the botnet. Cybersecurity companies are also urged to use the CSA to help identify malicious activity.

Compromised internet-connected devices include small office/home office (SOHO) routers, firewalls, network-attached storage (NAS), and Internet of Things (IoT) devices, such as webcams, DVRs, and IP cameras. The actors create a botnet from these devices, which can be used to conceal their online activity, launch distributed denial of service (DDoS) attacks, or compromise U.S. networks.

As of June 2024, the botnet consisted of over 260,000 devices in North America, Europe, Africa, and Southeast Asia, according to the CSA.

NSA is releasing this joint advisory to help National Security Systems, Department of Defense, and Defense Industrial Base networks mitigate these cyber threats. The authors of the CSA recommend the following mitigations:

  • Regularly apply patches and updates, using automatic updates from trusted providers when available.
  • Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols, which threat actors may abuse to gain initial access or to spread malware to other networked devices.
  • Replace default passwords with strong passwords.
  • Implement network segmentation with the principle of least privilege to ensure IoT devices within a larger network pose known, limited, and tolerable risks.
  • Monitor for high network traffic volumes to detect and mitigate DDoS incidents.
  • Plan for device reboots to remove non-persistent malware.
  • Replace end-of-life equipment with supported devices.

 

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA warns about PRC-Linked actors and botnet operations appeared first on Intelligence Community News.

]]>
39799