China-nexus hackers increasingly hide behind hijacked consumer-device proxy networks

THE BRIEF
The UK National Cyber Security Centre and international partners warned that China-nexus threat actors are increasingly routing operations through large covert proxy networks built from compromised consumer and small-office devices. The advisory said these networks commonly include SOHO routers, internet-connected cameras, video recorders and network-attached storage appliances. By chaining traffic through many compromised systems and exiting close to the target, attackers can make malicious activity appear to originate from ordinary residential or business networks and reduce the effectiveness of static IP blocking. The advisory was supported by agencies from the United States, Australia, Canada, Germany, Japan, the Netherlands, New Zealand, Spain and Sweden. Western agencies have previously disrupted large botnets used by groups such as Flax Typhoon and Volt Typhoon, but the new guidance emphasizes that covert networks are continuously refreshed and may be shared across multiple actors. Defenders were urged to rely on stronger identity, device and behavioral controls rather than simple geographic assumptions.
WHY IT MATTERS
This changes how organizations should interpret network reputation. An IP address from a familiar country or consumer ISP is not evidence that a connection is benign when attackers can proxy through compromised routers near the target. Static blocklists also age quickly as covert networks replace nodes. The practical response is to make access decisions using multiple signals: identity strength, device trust, expected behavior, application context and dynamic threat intelligence. The same warning is relevant to households and small businesses because poorly maintained edge devices can become infrastructure for operations targeting entirely different victims.
WHO SHOULD CARE
Enterprise network defenders, critical-infrastructure operators, telecoms, small businesses, router owners and teams that rely heavily on IP reputation or geolocation should care. Managed-service providers and defenders of distributed branch networks should also care.
WHAT TO DO NOW
- Patch or replace unsupported routers, cameras and NAS devices exposed to the internet.
- Use MFA, device certificates and zero-trust controls rather than relying on source IP reputation alone.
- Map internet-facing edge devices and monitor them for unexpected outbound proxy behavior.
- Consume dynamic threat intelligence for known covert-network nodes and investigate unusual residential-source access.