<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="https://www.jain.com/assets/img/6adafce5-1.1"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>botnets &#8211; Jain.com</title>
	<atom:link href="/tag/botnets/feed/" rel="self" type="application/rss+xml" />
	<link></link>
	<description>Data centers, connectivity, and security — news and analysis</description>
	<lastBuildDate>Sat, 22 Aug 2026 21:21:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>/wp-content/uploads/2026/08/jain-com-icon-512-150x150.png</url>
	<title>botnets &#8211; Jain.com</title>
	<link></link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>US and Allies Warn China Hides State Cyberattacks Behind &#8216;Covert Network&#8217; Botnets</title>
		<link>/us-allies-warn-china-covert-network-botnets-cyberattacks/</link>
		
		<dc:creator><![CDATA[Deepak Jain]]></dc:creator>
		<pubDate>Wed, 22 Apr 2026 16:00:00 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[China]]></category>
		<category><![CDATA[critical infrastructure]]></category>
		<category><![CDATA[cyber attribution]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[edge devices]]></category>
		<category><![CDATA[network security]]></category>
		<category><![CDATA[threat intelligence]]></category>
		<guid isPermaLink="false">/us-allies-warn-china-covert-network-botnets-cyberattacks/</guid>

					<description><![CDATA[US and allied agencies warn that China-linked hackers are masking state cyberattacks behind 'covert network' botnets built from compromised devices. We examine what the joint advisory signals, why relay networks defeat traditional IP-based defenses, and what infrastructure operators should do now.]]></description>
										<content:encoded><![CDATA[<div class="jain-post-grid">
<div class="jain-post-main">
<p>The United States and allied governments have issued a joint warning that hackers linked to the Chinese state are disguising cyberattacks by routing them through &ldquo;covert network&rdquo; botnets &mdash; fleets of compromised internet-connected devices that make hostile traffic appear to come from ordinary, innocuous sources. The warning, reported by Cybersecurity Dive on April 22, 2026, represents a coordinated, multi-government attribution effort rather than a single agency&#8217;s finding.</p>
<h2>Executive Summary</h2>
<p>A joint advisory from US and allied cybersecurity authorities alleges that China-linked threat actors are using covert botnet infrastructure to obscure the origin of state-directed intrusions. A botnet is a network of hijacked devices &mdash; often home and small-office routers, cameras, and other poorly secured edge equipment &mdash; that attackers control remotely. Used as relay infrastructure, a botnet lets an attacker&#8217;s traffic emerge from residential and business IP addresses in the victim&#8217;s own region, rather than from servers traceable to a foreign operator.</p>
<p>The significance is twofold. First, joint multi-nation attribution advisories are deliberate diplomatic and defensive instruments: governments generally publish them only when the evidentiary picture is strong enough to share and the activity is serious enough to warrant public exposure. Second, the technique described strikes at a core assumption of network defense &mdash; that malicious traffic looks foreign or anomalous. When an attack arrives via a compromised router in a nearby suburb, geographic blocking and IP-reputation filtering lose much of their value.</p>
<p>For operators of data centers, networks, and critical services, the practical message is that perimeter trust based on source address is increasingly unreliable, and that unmanaged edge devices &mdash; anyone&#8217;s edge devices &mdash; are now strategic assets in state conflict.</p>
<h2>Why Botnet Relays Defeat Traditional Defenses</h2>
<p>Most network defense still leans on reputation: block traffic from known-bad IP ranges, flag connections from unexpected countries, trust what looks local. Covert relay botnets invert that model. By proxying attacks through thousands of compromised consumer and small-business devices, an operator makes each intrusion attempt appear to originate from a legitimate residential ISP address &mdash; often in the same country, sometimes the same city, as the target. Each device may be used briefly and then rotated, so blocklists chase addresses that are already abandoned.</p>
<p>The advisory&#8217;s framing &mdash; a &ldquo;covert network&rdquo; &mdash; suggests infrastructure built for stealth and persistence rather than the noisy, high-volume botnets historically used for spam or denial-of-service floods. That distinction matters: a quiet relay network is harder to detect precisely because it is not doing anything visibly disruptive most of the time.</p>
<h2>Attribution as Policy: What a Joint Advisory Signals</h2>
<p>Public, multi-government attribution is a comparatively recent tool of statecraft. When several allied agencies sign a single document naming a state actor, they are doing three things at once: sharing technical indicators with defenders, imposing reputational cost on the accused state, and signaling to their own critical-infrastructure sectors that the threat is assessed as serious at the national level. Beijing has consistently denied involvement in state-sponsored intrusion campaigns, and readers should note that public advisories typically summarize conclusions rather than publish the full underlying evidence &mdash; a genuine limitation of the format, even when the analysis behind it is extensive.</p>
<p>The pattern is nonetheless consistent with several years of Western advisories describing China-linked groups that favor stealth, living-off-the-land techniques (using a system&#8217;s own legitimate tools rather than detectable malware), and pre-positioning inside critical infrastructure rather than immediate disruption.</p>
<h2>The Edge-Device Problem Nobody Owns</h2>
<p>Covert botnets exist because the internet&#8217;s edge is saturated with devices that are unpatched, unmonitored, and often past end-of-support: home routers, IP cameras, network-attached storage, VPN appliances. No single party is accountable for them &mdash; consumers don&#8217;t patch, many vendors stop shipping updates, and ISPs have limited visibility into customer equipment. That accountability gap is now a national-security externality: every neglected router is potential relay infrastructure for someone else&#8217;s intelligence service.</p>
<p>Expect this advisory to add momentum to policy efforts around device security &mdash; secure-by-design commitments, software support lifecycles, and labeling schemes &mdash; because the demand side of the covert-network economy can only be constrained by shrinking the supply of hijackable devices.</p>
<h2>What Infrastructure Operators Should Take From This</h2>
<p>For enterprises, carriers, and data-center operators, the actionable lesson is architectural: treat source IP address as weak evidence of anything. Defenses that hold up against relay networks are behavioral and identity-based &mdash; anomaly detection on authentication patterns, phishing-resistant multi-factor authentication, network segmentation that limits lateral movement, and logging rich enough to reconstruct an intrusion after the fact. Operators of fleets of edge equipment &mdash; including hosting and connectivity providers &mdash; also sit on the other side of the problem: their unmanaged or end-of-life gear can become part of the covert network itself, making patch discipline and device retirement a matter of ecosystem hygiene, not just self-protection.</p>
<h2>Background</h2>
<p>Public attribution of state-sponsored cyber operations has become a standard instrument of Western policy over the past decade, with the US and partners such as the UK, Canada, Australia, and New Zealand increasingly issuing joint advisories rather than unilateral statements. Since 2023, a series of such advisories has focused on China-linked groups accused of infiltrating critical infrastructure using stealthy techniques, including botnets built from end-of-life routers used as relay infrastructure. China has denied these allegations throughout.</p>
<p>The underlying enabler is the enormous installed base of consumer and small-business network devices that receive few or no security updates. Security researchers have long warned that this unmanaged edge constitutes ready-made anonymization infrastructure for any sophisticated actor willing to compromise it at scale.</p>
<p>Source: <a href="https://news.google.com/rss/articles/CBMinwFBVV95cUxOVmpsY1ZoYVB2WTlvWGNJRF9HcDdUQXRkWE0zbjBlckVURUFvZ19pNEVVY0tCT2lvaHp0SG5qX1Q1dmd6THdPaU95aERiNVU5REltRkdSdFF3NnFVWkczUFBZb25HU3BwTGZwMTJLcnJHcWxaWkJwbDZpb05vMDNqMlMxVkxwTzFDY2Z0VEZfbm45ZWtFV3Y5ei1NOVVmM0k?oc=5">China disguises cyberattacks with &lsquo;covert network&rsquo; botnets, US and allies warn</a> &mdash; Cybersecurity Dive report on a joint US-allied advisory, April 22, 2026.</p>
</div>
<aside class="jain-rail">
<section class="jain-gaps" aria-label="What the release does not say">
<p class="jain-gaps-kicker">⚠ What They Aren’t Saying</p>
<h2>What the Release Doesn&#8217;t Say</h2>
<p>As reported, the warning leaves substantial questions open. The summary coverage does not specify which agencies and which allied nations signed the advisory, which threat groups or botnet infrastructure are named, or how many compromised devices the covert network comprises. Also unclear from this report: which sectors or countries were targeted through the relay network, whether specific intrusions have been attributed to it, what technical indicators (device models, malware families, command-and-control patterns) defenders should hunt for, and whether any takedown or law-enforcement action accompanies the advisory. Finally, the report does not include a response from the Chinese government, which has historically denied such allegations &mdash; readers should consult the full advisory text for the underlying technical detail.</p>
</section>
<section class="jain-faq">
<h2>Frequently Asked Questions</h2>
<h3>What did the US and its allies announce on April 22, 2026?</h3>
<p>A joint warning that China-linked threat actors are disguising state cyberattacks by routing them through &#8216;covert network&#8217; botnets — networks of compromised internet-connected devices used to mask the true origin of hostile traffic.</p>
<h3>What is a botnet?</h3>
<p>A botnet is a collection of internet-connected devices — routers, cameras, storage boxes, computers — that attackers have compromised and control remotely. The devices&#8217; owners typically have no idea their equipment is being used.</p>
<h3>What does a &#x27;covert network&#x27; botnet do differently from a normal botnet?</h3>
<p>Rather than flooding targets with traffic, a covert relay network quietly proxies an attacker&#8217;s connections so intrusions appear to come from ordinary residential or business IP addresses, defeating geographic blocking and IP-reputation defenses.</p>
<h3>Why would state hackers route attacks through home routers?</h3>
<p>Traffic emerging from a local consumer IP address looks legitimate to most defenses. It hides the attacker&#8217;s real infrastructure, complicates attribution, and lets operations blend into normal internet activity.</p>
<h3>Why does it matter that this warning came from multiple governments jointly?</h3>
<p>Joint advisories signal that several allied intelligence and cybersecurity agencies reached consistent conclusions. Governments generally reserve coordinated public attribution for activity they assess as serious and well-evidenced.</p>
<h3>Has China responded to the allegations?</h3>
<p>The report as summarized does not include a response, but Beijing has consistently denied involvement in state-sponsored hacking campaigns in response to previous Western advisories of this kind.</p>
<h3>How does this fit with earlier warnings about Chinese state hacking?</h3>
<p>Western agencies have for several years published advisories describing China-linked groups that emphasize stealth, use of legitimate system tools, and pre-positioning inside critical infrastructure. A covert relay network fits that tradecraft pattern.</p>
<h3>What kinds of devices typically end up in these botnets?</h3>
<p>Commonly home and small-office routers, IP cameras, network-attached storage, and VPN or firewall appliances — especially models that are unpatched, unmonitored, or past their manufacturer&#8217;s end of support.</p>
<h3>Could my own router be part of a covert network without my knowledge?</h3>
<p>Yes. Compromised relay devices usually keep working normally, so owners rarely notice. Keeping firmware updated, changing default passwords, and replacing end-of-life equipment are the main protections.</p>
<h3>Why doesn&#x27;t blocking foreign IP addresses stop these attacks?</h3>
<p>Because relayed traffic exits from compromised devices inside the target&#8217;s own country or region. The hostile connection arrives with a local, reputable-looking source address, so geography-based filtering never triggers.</p>
<h3>What should enterprises and infrastructure operators do in response?</h3>
<p>Shift from IP-reputation defenses toward identity- and behavior-based ones: phishing-resistant multi-factor authentication, network segmentation, anomaly detection on logins, and logging sufficient to investigate intrusions after the fact.</p>
<h3>What does the advisory mean for data center and connectivity providers specifically?</h3>
<p>They face both sides of the problem: relayed attacks that look like local customer traffic, and the risk that their own unmanaged edge equipment gets conscripted into a covert network. Patch discipline and device retirement become ecosystem obligations.</p>
<h3>What key details does this report not disclose?</h3>
<p>The summary coverage does not name the signing agencies or nations, the specific threat groups, the botnet&#8217;s size, targeted sectors, technical indicators for defenders, or whether any takedown action accompanies the warning.</p>
<h3>Are public attribution advisories reliable evidence?</h3>
<p>They reflect assessments by multiple national agencies, but they typically publish conclusions rather than complete underlying evidence. That is a real limitation of the format, and a fair question to ask of any government attribution.</p>
<h3>What policy changes could follow from warnings like this?</h3>
<p>Likely continued pressure for secure-by-design device manufacturing, mandatory software-support lifecycles, security labeling for consumer equipment, and coordinated law-enforcement takedowns of relay infrastructure.</p>
</section>
</aside>
</div>
<p><script type="application/ld+json">{"@context": "https://schema.org", "@graph": [{"@type": "NewsArticle", "headline": "US and Allies Warn China Hides State Cyberattacks Behind 'Covert Network' Botnets", "description": "US and allied agencies warn that China-linked hackers are masking state cyberattacks behind 'covert network' botnets built from compromised devices. We examine what the joint advisory signals, why relay networks defeat traditional IP-based defenses, and what infrastructure operators should do now.", "image": ["/wp-content/uploads/2026/08/china-covert-network-botnet-us-allies-advisory.png"], "author": {"@type": "Organization", "name": "jain.com Editorial"}, "datePublished": "2026-08-20T21:22:16.451781+00:00"}, {"@type": "FAQPage", "mainEntity": [{"@type": "Question", "name": "What did the US and its allies announce on April 22, 2026?", "acceptedAnswer": {"@type": "Answer", "text": "A joint warning that China-linked threat actors are disguising state cyberattacks by routing them through 'covert network' botnets \u2014 networks of compromised internet-connected devices used to mask the true origin of hostile traffic."}}, {"@type": "Question", "name": "What is a botnet?", "acceptedAnswer": {"@type": "Answer", "text": "A botnet is a collection of internet-connected devices \u2014 routers, cameras, storage boxes, computers \u2014 that attackers have compromised and control remotely. The devices' owners typically have no idea their equipment is being used."}}, {"@type": "Question", "name": "What does a 'covert network' botnet do differently from a normal botnet?", "acceptedAnswer": {"@type": "Answer", "text": "Rather than flooding targets with traffic, a covert relay network quietly proxies an attacker's connections so intrusions appear to come from ordinary residential or business IP addresses, defeating geographic blocking and IP-reputation defenses."}}, {"@type": "Question", "name": "Why would state hackers route attacks through home routers?", "acceptedAnswer": {"@type": "Answer", "text": "Traffic emerging from a local consumer IP address looks legitimate to most defenses. It hides the attacker's real infrastructure, complicates attribution, and lets operations blend into normal internet activity."}}, {"@type": "Question", "name": "Why does it matter that this warning came from multiple governments jointly?", "acceptedAnswer": {"@type": "Answer", "text": "Joint advisories signal that several allied intelligence and cybersecurity agencies reached consistent conclusions. Governments generally reserve coordinated public attribution for activity they assess as serious and well-evidenced."}}, {"@type": "Question", "name": "Has China responded to the allegations?", "acceptedAnswer": {"@type": "Answer", "text": "The report as summarized does not include a response, but Beijing has consistently denied involvement in state-sponsored hacking campaigns in response to previous Western advisories of this kind."}}, {"@type": "Question", "name": "How does this fit with earlier warnings about Chinese state hacking?", "acceptedAnswer": {"@type": "Answer", "text": "Western agencies have for several years published advisories describing China-linked groups that emphasize stealth, use of legitimate system tools, and pre-positioning inside critical infrastructure. A covert relay network fits that tradecraft pattern."}}, {"@type": "Question", "name": "What kinds of devices typically end up in these botnets?", "acceptedAnswer": {"@type": "Answer", "text": "Commonly home and small-office routers, IP cameras, network-attached storage, and VPN or firewall appliances \u2014 especially models that are unpatched, unmonitored, or past their manufacturer's end of support."}}, {"@type": "Question", "name": "Could my own router be part of a covert network without my knowledge?", "acceptedAnswer": {"@type": "Answer", "text": "Yes. Compromised relay devices usually keep working normally, so owners rarely notice. Keeping firmware updated, changing default passwords, and replacing end-of-life equipment are the main protections."}}, {"@type": "Question", "name": "Why doesn't blocking foreign IP addresses stop these attacks?", "acceptedAnswer": {"@type": "Answer", "text": "Because relayed traffic exits from compromised devices inside the target's own country or region. The hostile connection arrives with a local, reputable-looking source address, so geography-based filtering never triggers."}}, {"@type": "Question", "name": "What should enterprises and infrastructure operators do in response?", "acceptedAnswer": {"@type": "Answer", "text": "Shift from IP-reputation defenses toward identity- and behavior-based ones: phishing-resistant multi-factor authentication, network segmentation, anomaly detection on logins, and logging sufficient to investigate intrusions after the fact."}}, {"@type": "Question", "name": "What does the advisory mean for data center and connectivity providers specifically?", "acceptedAnswer": {"@type": "Answer", "text": "They face both sides of the problem: relayed attacks that look like local customer traffic, and the risk that their own unmanaged edge equipment gets conscripted into a covert network. Patch discipline and device retirement become ecosystem obligations."}}, {"@type": "Question", "name": "What key details does this report not disclose?", "acceptedAnswer": {"@type": "Answer", "text": "The summary coverage does not name the signing agencies or nations, the specific threat groups, the botnet's size, targeted sectors, technical indicators for defenders, or whether any takedown action accompanies the warning."}}, {"@type": "Question", "name": "Are public attribution advisories reliable evidence?", "acceptedAnswer": {"@type": "Answer", "text": "They reflect assessments by multiple national agencies, but they typically publish conclusions rather than complete underlying evidence. That is a real limitation of the format, and a fair question to ask of any government attribution."}}, {"@type": "Question", "name": "What policy changes could follow from warnings like this?", "acceptedAnswer": {"@type": "Answer", "text": "Likely continued pressure for secure-by-design device manufacturing, mandatory software-support lifecycles, security labeling for consumer equipment, and coordinated law-enforcement takedowns of relay infrastructure."}}]}]}</script></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
