State-sponsored threat actors linked to China are fundamentally changing how they carry out cyber espionage and offensive operations.
Rather than purchasing and setting up their own dedicated attack infrastructure, these hacking groups are now taking over thousands of regular internet routers and edge devices.
By hijacking these everyday gadgets, they build massive,hidden botnets known as covert networks. This new approach allows them to mask their true locations and intentions, making it much harder for cybersecurity teams to track and block their activities.
These compromised devices are actively used throughout every phase of a cyber attack, often referred to as the Cyber Kill Chain.
First, the hackers use the hijacked routers to scan for vulnerabilities and gather information about their targets.
The Threat of Rapidly Changing Networks
The primary danger of this new tactic is itsincredibly dynamic nature. Operating a botnet composed of compromised home and small-business routers is a low-cost strategy that provides attackers with plausible deniability.
Because the infrastructure legally belongs to innocent third parties, the hackers can easily hide their tracks. Furthermore, the network can be rapidly reshaped, reshuffled, or discarded at a moment’s notice.
This constantly changing structure completely undermines traditional network defense strategies. In the past, security teams relied heavily on static IP blocklists to keep bad actors out.
However, because these covert networks are frequently refreshed and even shared among multiple different threat groups, defenders are now facing a major problem known as indicator of compromise (IOC) extinction.
Malicious IP addresses and other attack signatures disappear or change before defenders can effectively block them.
The impact on targeted organizations is severe and immediate. Covert networks enable these China-nexus actors to successfully launch sophisticated cyber attacks against entities in the UK and worldwide.
The primary goals of these campaigns are to steal highly sensitive data and potentially disrupt critical services. Organizations that continue to rely solely on static defenses and outdated blocklists are at a very high risk of being bypassed entirely.
Defending Against Dynamic Attacks
To help organizations protect themselves, the National Cyber Security Center (NCSC) and the Cyber League, working alongside allied intelligence agencies, have released detailed guidance.
This advisory provides actionable steps for businesses of all sizes, emphasizing that static defenses are no longer enough to stop modern hacking campaigns.
Organizations must take immediate steps to secure their networks and adapt to these shifting threats:
- Map and baseline all traffic flowing through edge devices, paying special attention to virtual private networks (VPNs) and remote access connections.
- Adopt dynamic threat feed filtering that automatically updates to include the latest known indicators from covert networks.
- Implement strong two-factor authentication for all remote access points.
- Apply zero-trust security controls, strict IP allow lists, and machine certificate verification wherever possible to restrict unauthorized access.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.