WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships Joint Cybersecurity Advisory – People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Joint Cybersecurity Advisory – People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations

Author: Chase Snow

Created: Thursday, September 19, 2024 - 18:35

Categories: Cybersecurity, Federal & State Resources, Security Preparedness

Yesterday, The NSA, FBI, the U.S. Cyber Command’s Cyber National Mission Force (CNMF), and international allies, published a Joint cybersecurity advisory (CSA) “People’s Republic of China-Linked Actors Compromise Routers and IoT Devices for Botnet Operations”.  The Joint CSA states that PRC-linked cyber actors have compromised thousands of internet-connected devices, including small office/home office routers, firewalls, network-attached storage, and Internet of Things devices with the goal of creating a network of compromised nodes (a “botnet”) positioned for malicious activity. The advisory delivers up-to-date insights on botnet infrastructure, the countries where affected devices are found, and strategies for securing devices and addressing this threat.

FBI Director Chris Wray confirmed yesterday that the same botnet (known as “Raptor Train”),operated by the state-sponsored Chinese threat actor Flax Typhoon, has been disrupted by law enforcement and was subsequently abandoned by the group. The botnet infected over 260,000 networking devices and is said to have targeted critical infrastructure in the U.S. and other countries. For more information, visit Help Net Security. Access the full joint advisory at the FBI’s IC3.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 1, 2026)

May 1, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar