Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners issue advice to counter campaign targeting devices

Security

NCSC and partners issue advice to counter campaign targeting devices

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued a new advisory alongside partners in the US, Australia, Canada and New Zealand, which reveals how a company based in China with links to China’s government, has managed a botnet consisting of over 260,000 compromised devices around the world.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simona Flamigni / copyright Shutterstock

The UK and international allies are urging individuals and organisations to take protective action after exposing a global network of compromised internet-connected devices operated by a China-linked company and used for malicious purposes.

Advertisement
Security & Policing Rectangle

A botnet is a network of internet-connected devices that are infected with malware and controlled by a group to conduct co-ordinated cyber attacks without the owners’ knowledge.

The compromised devices include routers, firewalls, and Internet of Things (IoT) devices – including webcams and CCTV cameras – which can then be used by the actors for a variety of malicious purposes, such as anonymous malware delivery and distributed denial of service (DDoS) attacks.

The advisory names Integrity Technology Group as responsible for controlling and managing the botnet, which has been active since mid-2021, and has been utilised by the malicious cyber actor commonly known as Flax Typhoon.

The advisory shares technical details and mitigation advice to help defend against malicious activity delivered through this botnet. It also highlights the risk to owners of how unpatched and end-of-life equipment can be exploited by malicious cyber actors.

Paul Chichester, NCSC Director of Operations, said: “Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks.

“Whilst the majority of botnets are used to conduct coordinated DDoS attacks, we know that some also have the ability to steal sensitive information.

Advertisement
ODU RT

“That’s why the NCSC, along with our partners in Five Eyes countries, is strongly encouraging organisations and individuals to act on the guidance set out in this advisory – which includes applying updates to internet-connected devices – to help prevent their devices from joining a botnet.”

As with similar botnets, the botnet described in this advisory is composed of a network of devices, known as bots, which are infected with a type of malware that provides threat actors with unauthorised remote access.

To recruit a new ‘bot’, the botnet system first compromised an internet-connected device using a known vulnerability exploit which then provides access to establish a remote command and control execution.

This advisory has been co-sealed by the NCSC and agencies in the United States, Australia, Canada and New Zealand.

Read the advisory in full

Advertisement
General Atomics LB
Tech challenge launched to counter drone threats in prisons

Aerospace Security

Tech challenge launched to counter drone threats in prisons

4 November 2025

A new innovation challenge aimed at combatting the growing threat of drones to prisons has been launched by the Ministry of Justice through His Majesty's Government Communications Centre Co-Creation.

Met report reveals LFR making capital safer

Security

Met report reveals LFR making capital safer

4 November 2025

The Metropolitan Police Service’s use of Live Facial Recognition (LFR) technology is making London safer, according to a new annual report published by the force.

Seafarer cadets first to follow futureproofed maritime syllabus

Security

Seafarer cadets first to follow futureproofed maritime syllabus

4 November 2025

This year's cohort of seafarer trainees have become the first in the UK to learn under a new syllabus developed through an industry-wide initiative, led by the Maritime and Coastguard Agency (MCA), to ensure skills keep pace with modern technology and practices.

Smiths Detection’s iCMORE APIDS is certified by German FPTC

Security

Smiths Detection’s iCMORE APIDS is certified by German FPTC

3 November 2025

Smiths Detection today announced that its proprietary iCMORE Automated Prohibited Items Detection System (APIDS) has been certified by the German Federal Police Technology Centre (FPTC) for use at airport security checkpoints in Germany.

Advertisement
ODU RT
Sigma Advanced Systems acquires Nasmyth

Aerospace Defence Security

Sigma Advanced Systems acquires Nasmyth

3 November 2025

Nasmyth Group, a provider of specialist precision engineering services to the aerospace, defence and related industries, today announced its acquisition by Sigma Advanced Systems UK Ltd.

Prof William Webster appointed Biometrics and Surveillance Camera Commissioner

Security

Prof William Webster appointed Biometrics and Surveillance Camera Commissioner

3 November 2025

Professor William Webster has been appointed as the new Biometrics and Surveillance Camera Commissioner, following an open competition and in line with the Governance Code on Public Appointments.

Advertisement
Security & Policing Rectangle