Cyber Security News

Chinese Hackers Hijacked Routers & IoT Devices to Create Botnet, NSA Warns

A joint cybersecurity advisory issued by the Federal Bureau of Investigation (FBI), Cyber National Mission Force (CNMF), and National Security Agency (NSA) has revealed that hackers linked to the People’s Republic of China (PRC) have compromised thousands of Internet-connected devices.

That includes small office/home office (SOHO) routers, firewalls, network-attached storage (NAS), and Internet of Things (IoT) devices, to create a massive botnet.

The advisory, released on September 18, 2024, highlights the threat posed by these actors and their botnet activity, urging exposed device vendors, owners, and operators to update and secure their devices to prevent further compromise.

The botnet, managed by a PRC-based company named Integrity Technology Group, has been active since mid-2021 and has consistently maintained tens to hundreds of thousands of compromised devices.

As of June 2024, the botnet consisted of over 260,000 devices, with victim devices identified in North America, South America, Europe, Africa, Southeast Asia, and Australia.

Decoding Compliance: What CISOs Need to Know – Join Free Webinar

Botnet Devices by Country

CountryNode CountPercentage
United States126,00047.9%
Vietnam21,1008.0%
Germany18,9007.2%
Romania9,6003.7%
Hong Kong9,4003.6%
Canada9,2003.5%
South Africa9,0003.4%
United Kingdom8,5003.2%
India5,8002.2%
France5,6002.1%
Bangladesh4,1001.6%
Italy4,0001.5%
Lithuania3,3001.3%
Albania2,8001.1%
Netherlands2,7001.0%
China2,6001.0%
Australia2,4000.9%
Poland2,1000.8%
Spain2,0000.8%

The hackers used various known vulnerability exploits to compromise devices, including those from vendors such as Zyxel, Fortinet, and QNAP, among others.

The compromised devices were then infected with a customized version of the Mirai malware, which allows threat actors to control the devices remotely and use them for malicious activities such as distributed denial of service (DDoS) attacks and routing nefarious Internet traffic.

The botnet’s command and control (C2) servers were managed using a tier of upstream management servers, which hosted a MySQL database containing information on compromised devices.

The actors used specific IP addresses registered to China Unicom Beijing Province Network to access the botnet management application, known as “Sparrow,” which allowed them to interact with the botnet and issue commands to victim devices.

The advisory provides detailed information on the botnet’s infrastructure, including a list of subdomains associated with the C2 servers and the vulnerabilities exploited to add devices to the botnet.

It also offers recommended mitigations for network defenders to protect against the PRC-linked cyber actors’ botnet activity, including disabling unused services and ports, implementing network segmentation, monitoring for high network traffic volume, applying patches and updates, and replacing default passwords with strong passwords.

The growing threat of state-sponsored cyberattacks and the importance of robust cybersecurity measures to protect against such threats.

Device owners and operators are urged to take immediate action to secure their devices and prevent further compromise.

Are You From SOC/DFIR Teams? - Try Advanced Malware and Phishing Analysis With ANY.RUN - 14-day free trial

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago