Advisory ID: NCC-CSIRT-2026-016
Summary:
The United Kingdom’s National Cyber Security Centre (NCSC), in coordination with international cybersecurity and intelligence partners, has warned of ongoing malicious cyber activities conducted by Chinese-linked threat actors using covert networks of compromised internet-connected devices to conceal cyber operations.
The attackers reportedly exploit vulnerable routers, smart devices, and internet-facing infrastructure to create stealth relay networks capable of masking malicious traffic, conducting cyber espionage, and launching cyberattacks against government agencies, critical infrastructure, and private organizations.
The infrastructure allows attackers to hide their real origin, evade attribution, and maintain long-term operational access while blending malicious traffic into legitimate internet activity. The threat poses significant risks to telecommunications providers, Internet Service Providers (ISPs), government networks, and critical national infrastructure globally, including Nigeria and the wider West African region.
Damage: Critical
Probability: High
Product(s):
- Home and Enterprise Routers
- Internet of Things (IoT) Devices
- Smart Home Appliances
- Network Edge Devices
- VPN Gateways
- Firewalls
- Consumer Premises Equipment (CPE)
- Internet-Connected Cameras and Smart Devices
Version(s):
- Devices running outdated or unsupported firmware
- Devices using default or weak administrative credentials
- Unpatched SOHO (Small Office/Home Office) routers and IoT systems
- Unsupported legacy networking equipment
Platform(s):
- Broadband Internet Infrastructure
- Residential Networks
- Enterprise Networks
- Cloud-Connected IoT Environments
- Linux-Based Embedded Systems
- Router Operating Systems
- Smart Device Ecosystems
Description:
According to international cybersecurity authorities, the threat actors are building covert operational networks by compromising internet-connected devices such as routers, smart appliances, and other edge networking systems.
The attackers exploit weak passwords, outdated firmware, exposed remote administration interfaces, and unpatched vulnerabilities to gain unauthorized access to these devices. Once compromised, the devices are incorporated into hidden proxy or relay infrastructures that route malicious traffic on behalf of the attackers.
This infrastructure enables attackers to disguise their real locations and conduct malicious activities while appearing to originate from legitimate residential or enterprise internet connections. Such techniques significantly complicate cyber attribution and detection efforts.
The compromised devices may be used to:
- Relay malicious traffic
- Conduct cyber espionage
- Support command-and-control (C2) communications
- Launch Distributed Denial-of-Service (DDoS) attacks
- Facilitate credential theft and malware distribution
The advisory indicates that the threat actors specifically target poorly secured internet-facing infrastructure and leverage globally distributed networks of compromised devices to sustain persistent cyber operations.
The threat is particularly concerning because compromised devices may continue operating normally while secretly participating in malicious activities without the knowledge of device owners.
Indicators of Compromise (IoCs):
Organizations should monitor the following indicators:
Network Indicators
- Unusual outbound traffic from routers or IoT devices
- Persistent encrypted outbound connections to unknown IP addresses
- Abnormal DNS requests or DNS tunnelling activity
- Unexpected proxy or relay traffic originating from internal networks
- Large volumes of outbound traffic from consumer premises equipment (CPE
Device Indicators
- Unauthorized configuration changes on routers or firewalls
- Unknown administrator accounts
- Unexpected device reboots or degraded performance
- Unusual open ports or remote management services
- Firmware modifications or unauthorized scheduled tasks
Operational Indicators
- Unexpected communications with foreign IP addresses
- Detection of botnet or proxy network signatures
- Devices participating in DDoS traffic patterns
Consequences:
Successful exploitation may result in:
- Unauthorized use of compromised devices as relay infrastructure for cyberattacks
- Concealment of malicious cyber operations behind legitimate residential or enterprise networks
- Data theft and cyber espionage against government and critical infrastructure organizations
- Distributed Denial-of-Service (DDoS) attacks using hijacked devices
- Reputational and attribution risks for affected Internet Service Providers
- Long-term covert access to vulnerable network environments
- Increased exposure of telecommunications infrastructure to an advanced threat actor
Threat Types:
- Advanced Persistent Threat (APT) Activity
- Cyber Espionage
- Botnet Operations
- Proxy / Relay Network Abuse
- Infrastructure Hijacking
- Covert Command-and-Control (C2) Operations
- IoT Device Exploitation
- Network Obfuscation and Evasion
Solutions/Mitigations:
NCC-CSIRT recommends the following mitigation steps:
- Monitor customer networks for unusual proxy or relay traffic patterns.
- Identify and isolate compromised routers or IoT devices.
- Enforce firmware updates and security hardening for managed devices.
- Disable unnecessary remote management interfaces.
- Deploy network anomaly detection systems to identify covert relay activity.
- Conduct threat hunting activities for covert relay or proxy traffic within enterprise and telecom networks.
- Review the security posture of all internet-facing infrastructure and edge devices.
- Monitor for signs of unauthorized access to routers, VPN devices, and firewalls.
- Collaborate with national cybersecurity authorities and ISPs to report suspicious infrastructure
- Deploy endpoint and network monitoring solutions capable of detecting botnet or proxy activity.
References:
-
https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices
-
https://www.helpnetsecurity.com/2026/04/24/ncsc-china-covert-networks-advisory/
-
https://www.ncsc.gov.uk/sites/default/files/2026-04/-Defending-against-China-nexus-covert-networks-of-compromised-devices.pdf