Global cybersecurity authorities have issued a stark warning. The UK National Cyber Security Centre (NCSC), together with 15 international partners, released a joint advisory highlighting a significant threat from China-linked cyber actors who are using compromised everyday internet-connected devices to build massive botnets, masking their attack origins.
Tactical Shift: Hiding Behind Routers and Smart Devices
The advisory points to a tactical evolution where attackers route malicious traffic through hundreds of thousands of compromised home routers and smart devices instead of traditional infrastructure. This method obscures the source of scans, malware delivery, and data exfiltration. Notable operations like Volt Typhoon and Flax Typhoon route traffic through small office/home office (SOHO) routers.
Major Threats and Scale
The Raptor Train botnet infected over 200,000 devices globally in 2024. The FBI attributed its management to Beijing-based Integrity Technology Group, which was sanctioned by the UK in December 2025. Meanwhile, the KV botnet used by Volt Typhoon has established footholds in critical infrastructure in the US and allied nations. The NCSC urges organizations to monitor network traffic and adopt dynamic threat intelligence feeds.
Impact on Digital Assets
Digital asset losses due to cyber activity exceeded $2 billion in 2024. Botnets are increasingly used to target cryptocurrency exchanges and wallets, stealing private keys and credentials. The advisory calls on crypto businesses to strengthen endpoint detection and multi-factor authentication to protect against infiltration of custodial wallets.
The joint alert underscores the evolving sophistication of state-backed hacking, posing an urgent challenge to the global crypto ecosystem.

