Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners issue advice to counter campaign targeting devices

Security

NCSC and partners issue advice to counter campaign targeting devices

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued a new advisory alongside partners in the US, Australia, Canada and New Zealand, which reveals how a company based in China with links to China’s government, has managed a botnet consisting of over 260,000 compromised devices around the world.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simona Flamigni / copyright Shutterstock

The UK and international allies are urging individuals and organisations to take protective action after exposing a global network of compromised internet-connected devices operated by a China-linked company and used for malicious purposes.

Advertisement
ODU RT

A botnet is a network of internet-connected devices that are infected with malware and controlled by a group to conduct co-ordinated cyber attacks without the owners’ knowledge.

The compromised devices include routers, firewalls, and Internet of Things (IoT) devices – including webcams and CCTV cameras – which can then be used by the actors for a variety of malicious purposes, such as anonymous malware delivery and distributed denial of service (DDoS) attacks.

The advisory names Integrity Technology Group as responsible for controlling and managing the botnet, which has been active since mid-2021, and has been utilised by the malicious cyber actor commonly known as Flax Typhoon.

The advisory shares technical details and mitigation advice to help defend against malicious activity delivered through this botnet. It also highlights the risk to owners of how unpatched and end-of-life equipment can be exploited by malicious cyber actors.

Paul Chichester, NCSC Director of Operations, said: “Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks.

“Whilst the majority of botnets are used to conduct coordinated DDoS attacks, we know that some also have the ability to steal sensitive information.

Advertisement
ODU RT 2

“That’s why the NCSC, along with our partners in Five Eyes countries, is strongly encouraging organisations and individuals to act on the guidance set out in this advisory – which includes applying updates to internet-connected devices – to help prevent their devices from joining a botnet.”

As with similar botnets, the botnet described in this advisory is composed of a network of devices, known as bots, which are infected with a type of malware that provides threat actors with unauthorised remote access.

To recruit a new ‘bot’, the botnet system first compromised an internet-connected device using a known vulnerability exploit which then provides access to establish a remote command and control execution.

This advisory has been co-sealed by the NCSC and agencies in the United States, Australia, Canada and New Zealand.

Read the advisory in full

Advertisement
General Atomics LB General Atomics LB
Engineering Centre of Excellence named STEM Ambassador of the Year

Aerospace Security Events

Engineering Centre of Excellence named STEM Ambassador of the Year

20 September 2024

Sellafield Ltd’s Engineering Centre of Excellence in Cleator Moor won the STEM Ambassador of the Year at the Engineering and Manufacturing Awards 2024.

Dionach extends partnership with UK Space Agency

Security Space

Dionach extends partnership with UK Space Agency

19 September 2024

Cyber security consultancy Dionach have signed a contract extension with the UK Space Agency to accelerate cyber security within UK Space companies.

NL EASP AIR confirms SDG as Satcom solutions provider

Aerospace Security Space

NL EASP AIR confirms SDG as Satcom solutions provider

18 September 2024

Satellite communications provider SD Government (SDG), has been named by NL EASP Air, the Dutch service provider for aerial maritime surveillance, coast guard, search and rescue (SAR) and intelligence, surveillance and reconnaissance (ISR) operations, as its preferred provider of satcom connectivity solutions.

UK convenes global coalition to boost cyber skills and tackle threats

Security

UK convenes global coalition to boost cyber skills and tackle threats

16 September 2024

The UK will convene leading nations including the US and EU for talks on how to tackle the growing threat of cyber-attacks, as new figures show nearly half of British businesses do not have the skills needed to protect against cyber-crime.

Advertisement
ODU RT
Improving cyber security together

Security

Improving cyber security together

16 September 2024

The National Crime Agency (NCA), Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC) have linked up to help UK companies tackle cyber crime, with the NCA and ICO signing a Memorandum of Understanding, to recommit to giving guidance on - and proactively assist victims of - cyber crime.

Kromek awarded £2m contract by UK MoD

Defence Security

Kromek awarded £2m contract by UK MoD

16 September 2024

Developer of radiation and bio-detection technology solutions for the advanced imaging and CBRN detection segments, Kromek, has been awarded a contract worth £2 million by the UK Ministry of Defence (MoD) for the supply of nuclear radiation detectors and ancillary products.

Advertisement
Marshall RT 2