Defending Against China-Nexus Covert Networks of Compromised Devices

Published: 28/04/2026 08:41 PM Category: Alert CVE: N/A
CRITICAL SEVERITY

All Critical Infrastructure operators, Government agencies, and private sector organisations to strengthen monitoring and defensive measures against covert networks of compromised devices linked to advanced China-nexus threat actors.

These actors are known to exploit vulnerable internet-facing devices such as routers, firewalls, IoT systems, and edge appliances to build hidden operational networks used for persistence, espionage, and potential disruption of critical services. Their tactics focus on “living off the land,” blending into normal network traffic, and avoiding detection for long periods.

Key Risks Include:

1 Unauthorized access to critical systems
2 Credential theft and lateral movement
3 Long-term persistence inside networks
4 Disruption of national critical infrastructure
5 Abuse of trusted devices as covert relay points


Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices.

The NCSC believes that the majority of China-nexus threat actors are using these networks (hereafter “covert networks”), that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors. These networks are mainly made up of compromised Small Office Home Office (SOHO) routers, as well as Internet of Things (IoT) and smart devices.

Anyone who is a target of China-nexus cyber actors may be impacted by the use of covert networks. They have been used by Chinese state-sponsored actors Volt Typhoon to pre-position offensive cyber capabilities on critical national infrastructure. The group Flax Typhoon used a different covert network of compromised infrastructure to conduct cyber espionage.

The use of covert networks of compromised devices - also known as botnets - to facilitate malicious cyber activity is not new, but China-nexus cyber actors are now using them strategically, and at scale.

This advisory describes the typical makeup of a covert network and what they are being used for. It also includes protective advice for organisations being targeted by cyber activity using a covert network as an access vector.

Read more; https://www.cyber.gov.au/about-us/view-all-content/alerts-and-advisories/defending-against-china-nexus-covert-networks-of-compromised-devices