ORB Networks Leverages Compromised IoT Devices for Masked Cyberattacks

Operational Relay Box (ORB) networks serve as obfuscated mesh setups that threat actors use to hide the origins of cyberattacks.

These networks blend compromised IoT devices, SOHO routers, and VPS servers to route malicious traffic through seemingly legitimate residential or broadband connections.

ORBs enable strong evasion by mimicking private proxy networks, blending bad traffic with normal user activity on real devices like home routers.

This makes tracing attacks tough and risks collateral damage if defenders block IPs, as it could hit innocent users or services. Attackers scale them easily by swapping nodes, ensuring resilience, while pre-positioning near targets dodges geofencing and aids long-term reconnaissance.

UNC3886 Campaign Targets Singapore Telecoms

In February 2026, Singapore’s Cyber Security Agency (CSA) detailed Operation CYBER GUARDIAN, a major multi-agency effort against APT group UNC3886, which hit all four key telcos: M1, SIMBA Telecom, Singtel, and StarHub.

Detected in July 2025, the campaign used a zero-day to breach firewalls, exfiltrate minor network data, and rootkits for stealthy persistence, evading standard detection.

Mandiant links UNC3886 to China-sponsored espionage, known for zero-days in Fortinet, VMware, and Juniper edge devices, plus custom malware for long access in telecoms, energy, and finance sectors.

A 2025 Mandiant report on Juniper router attacks shared Singapore-based IOCs tied to GOBRAT ORB nodes, targeting M1 and StarHub.

DescriptionIP:PortWHOIS (Team Cymru)GeoIP (Team Cymru)
TINYSHELL C2129.126.109.50:22Alibaba (US) Technology Co., Ltd.Singapore
TINYSHELL C2116.88.34.184:22M1 NET LTDSingapore
TINYSHELL C2223.25.78.136:22MobileOne Ltd.Singapore
TINYSHELL C245.77.39.28:22MyRepublic Ltd.Singapore
TINYSHELL C2101.100.182.122:22MyRepublic Ltd.Singapore
TINYSHELL C2118.189.188.122:22MyRepublic Ltd.Singapore
TINYSHELL C2158.140.135.244:22Starhub LtdSingapore
TINYSHELL C28.222.225.8:22The Constant Company, LLCSingapore

Team Cymru Scout data shows 12 ORB-tagged IPs on victim ISPs in 90 days and 44 in Singapore overall, mostly on AWS, StarHub, and Singtel ASNs.

NetFlow analysis found 42 ORBs communicating with victim networks and 62 victim IPs (mainly D-Link/Asus routers) linking to ORBs in 30 days.

Singapore mandates secure-by-default routers via IMDA’s TS RG-SEC, requiring auto-patches and CLS Level 1 labeling with unique passwords and vuln policies since 2022. Yet legacy devices and imports create gaps exploited by UNC3886.

IndicatorDescriptionASNGeoIPLast Seen
8.218.212.173GOBRAT C2 ServerAS45102 (Alibaba)Singapore2025-12-28
8.218.127.103GOBRAT C2 ServerAS45102 (Alibaba)Singapore2025-12-30
47.82.7.142GOBRAT C2 ServerAS45102 (Alibaba)Singapore2026-02-11

According to Team Cymru, operation CYBER GUARDIAN contained the threat without service disruptions or customer data loss, boosting monitoring across 100+ defenders.

Defenders must hunt ORBs via threat intel, zero-trust, and edge device patches to counter such prepositioned espionage.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories