Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners issue advice to counter campaign targeting devices

Security

NCSC and partners issue advice to counter campaign targeting devices

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued a new advisory alongside partners in the US, Australia, Canada and New Zealand, which reveals how a company based in China with links to China’s government, has managed a botnet consisting of over 260,000 compromised devices around the world.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simona Flamigni / copyright Shutterstock

The UK and international allies are urging individuals and organisations to take protective action after exposing a global network of compromised internet-connected devices operated by a China-linked company and used for malicious purposes.

Advertisement
ADS S&P RT

A botnet is a network of internet-connected devices that are infected with malware and controlled by a group to conduct co-ordinated cyber attacks without the owners’ knowledge.

The compromised devices include routers, firewalls, and Internet of Things (IoT) devices – including webcams and CCTV cameras – which can then be used by the actors for a variety of malicious purposes, such as anonymous malware delivery and distributed denial of service (DDoS) attacks.

The advisory names Integrity Technology Group as responsible for controlling and managing the botnet, which has been active since mid-2021, and has been utilised by the malicious cyber actor commonly known as Flax Typhoon.

The advisory shares technical details and mitigation advice to help defend against malicious activity delivered through this botnet. It also highlights the risk to owners of how unpatched and end-of-life equipment can be exploited by malicious cyber actors.

Paul Chichester, NCSC Director of Operations, said: “Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks.

“Whilst the majority of botnets are used to conduct coordinated DDoS attacks, we know that some also have the ability to steal sensitive information.

Advertisement
ADS S&P RT

“That’s why the NCSC, along with our partners in Five Eyes countries, is strongly encouraging organisations and individuals to act on the guidance set out in this advisory – which includes applying updates to internet-connected devices – to help prevent their devices from joining a botnet.”

As with similar botnets, the botnet described in this advisory is composed of a network of devices, known as bots, which are infected with a type of malware that provides threat actors with unauthorised remote access.

To recruit a new ‘bot’, the botnet system first compromised an internet-connected device using a known vulnerability exploit which then provides access to establish a remote command and control execution.

This advisory has been co-sealed by the NCSC and agencies in the United States, Australia, Canada and New Zealand.

Read the advisory in full

Advertisement
PTC PTC
HMP Highpoint expanded to create UK

Security

HMP Highpoint expanded to create UK's largest public sector jail

10 March 2025

More dangerous criminals will be taken off the streets thanks to a 700-place expansion which will turn a Suffolk jail into the UK’s largest public sector prison.

AAUK relaunches APPGAA for Air Ambulances

Aerospace Security

AAUK relaunches APPGAA for Air Ambulances

7 March 2025

Air Ambulances UK (AAUK) has relaunched the All-Party Parliamentary Group on Air Ambulances (APPGAA), reaffirming its commitment to advocating for the lifesaving work of air ambulance charities across the UK.

Blighter hosting overseas delegations at Security & Policing

Security Events

Blighter hosting overseas delegations at Security & Policing

7 March 2025

Blighter will be hosting delegations from Estonia, Iraq, Latvia and Lithuania at this year’s Security & Policing (S&P) exhibition - the global security event organised by the UK Government - taking place at the Farnborough International Exhibition and Conference Centre, 11th to 13th March 2025.

Schiebel selected for UK police trials

Security

Schiebel selected for UK police trials

6 March 2025

The National Police Air Service (NPAS) has selected global manufacturer Schiebel to support its most ambitious trial so far of ‘Beyond the Visual Line of Sight’ (BVLOS) uncrewed aircraft operations.

Advertisement
ADS S&P RT
D-Fend Solutions opens London office

Security

D-Fend Solutions opens London office

6 March 2025

D-Fend Solutions today announced the expansion of its global operations with the launch of a new UK entity, D-Fend Solutions AD UK Ltd. and the opening of a new office in London.

SPX Communication Technologies showcasing capabilities at Security & Policing 2025

Defence Security Events

SPX Communication Technologies showcasing capabilities at Security & Policing 2025

6 March 2025

SPX Communication Technologies, formed by TCI and ECS, will be showcasing its Data Links, COMINT and Counter-UAS capabilities and solutions at this year's Home Office Security & Policing Global Security Event, being held at the Farnborough International Exhibition and Conference Centre, 11th-13th March 2025.

Advertisement
ODU RT