Advancing UK Aerospace, Defence, Security & Space Solutions Worldwide
  • Home
  • /
  • Security
  • /
  • NCSC and partners issue advice to counter campaign targeting devices

Security

NCSC and partners issue advice to counter campaign targeting devices

The National Cyber Security Centre (NCSC) – a part of GCHQ – has issued a new advisory alongside partners in the US, Australia, Canada and New Zealand, which reveals how a company based in China with links to China’s government, has managed a botnet consisting of over 260,000 compromised devices around the world.

Above: The National Cyber Security Centre (NCSC), Nova South, London.
Image by Simona Flamigni / copyright Shutterstock

The UK and international allies are urging individuals and organisations to take protective action after exposing a global network of compromised internet-connected devices operated by a China-linked company and used for malicious purposes.

Advertisement
ODU RT

A botnet is a network of internet-connected devices that are infected with malware and controlled by a group to conduct co-ordinated cyber attacks without the owners’ knowledge.

The compromised devices include routers, firewalls, and Internet of Things (IoT) devices – including webcams and CCTV cameras – which can then be used by the actors for a variety of malicious purposes, such as anonymous malware delivery and distributed denial of service (DDoS) attacks.

The advisory names Integrity Technology Group as responsible for controlling and managing the botnet, which has been active since mid-2021, and has been utilised by the malicious cyber actor commonly known as Flax Typhoon.

The advisory shares technical details and mitigation advice to help defend against malicious activity delivered through this botnet. It also highlights the risk to owners of how unpatched and end-of-life equipment can be exploited by malicious cyber actors.

Paul Chichester, NCSC Director of Operations, said: “Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks.

“Whilst the majority of botnets are used to conduct coordinated DDoS attacks, we know that some also have the ability to steal sensitive information.

Advertisement
PTC rectangle

“That’s why the NCSC, along with our partners in Five Eyes countries, is strongly encouraging organisations and individuals to act on the guidance set out in this advisory – which includes applying updates to internet-connected devices – to help prevent their devices from joining a botnet.”

As with similar botnets, the botnet described in this advisory is composed of a network of devices, known as bots, which are infected with a type of malware that provides threat actors with unauthorised remote access.

To recruit a new ‘bot’, the botnet system first compromised an internet-connected device using a known vulnerability exploit which then provides access to establish a remote command and control execution.

This advisory has been co-sealed by the NCSC and agencies in the United States, Australia, Canada and New Zealand.

Read the advisory in full

Advertisement
Gulfstream banner
DroneShield and OpenWorks Engineering expand C2 interoperability

Defence Security

DroneShield and OpenWorks Engineering expand C2 interoperability

24 March 2026

Counter-unmanned systems (C-UxS) solutions provider, DroneShield, today announced interoperability between DroneSentry-C2 command-and-control software and optical sensing technologies from OpenWorks Engineering.

Fiona Walters takes over as Serco’s UK & Europe CEO

Defence Security Space

Fiona Walters takes over as Serco’s UK & Europe CEO

24 March 2026

Fiona Walters has taken up her role as CEO of the UK & Europe division of Serco, having joined Serco in September 2025 from G4S, where she was Regional CEO for the UK & Ireland, leading a team of more than 30,000 people.

Marshall Land Systems partners with Tecnove

Defence Security

Marshall Land Systems partners with Tecnove

23 March 2026

Marshall Land Systems and the Tecnove Business Group have signed a Memorandum of Understanding (MoU) to explore and develop collaborative opportunities across the defence, medical and industrial sectors.

Airbus to acquire Ultra Cyber in the UK

Security

Airbus to acquire Ultra Cyber in the UK

23 March 2026

Airbus has entered into a definitive agreement with the Cobham Ultra group, a portfolio company of Advent, for the acquisition of Ultra Cyber Ltd.

Advertisement
ODU RT
Global Innovation Centre opened by ePropelled in Coventry

Aerospace Defence Security

Global Innovation Centre opened by ePropelled in Coventry

23 March 2026

Provider of smart propulsion solutions and energy management systems for uncrewed vehicles, ePropelled, has opened its new Global Innovation Centre in Coventry, expanding the UK’s sovereign capability in electric and hybrid propulsion as the company scales toward producing more than one million propulsion systems annually by 2027.

Anti-drone tech patents surge

Aerospace Defence Security

Anti-drone tech patents surge

19 March 2026

The number of patent applications for anti-drone (counter-UAV) technologies filed globally increased by 27% to 126 last year*, up from 99 the year before, according to new research from intellectual property (IP) law firm Mathys & Squire.

Advertisement
PTC rectangle
Advertisement
Gulfstream banner