FBI Dismantles Chinese-Linked Botnet of 260,000 IoT Devices

FBI Dismantles Chinese-Linked Botnet of 260,000 IoT Devices

The FBI, in collaboration with U.S. government agencies, dismantled a Chinese state-backed botnet known as Flax Typhoon, comprising 260,000 compromised IoT devices. This operation neutralized a major cyber threat to U.S. infrastructure.

In a major blow to state-sponsored cyber malicious activity, the FBI, in cooperation with other U.S. government agencies, has successfully dismantled a massive botnet linked to Chinese government-backed hackers.

Known as Flax Typhoon or Raptor Train, the botnet comprised around 260,000 compromised Internet of Things (IoT) devices globally. The network was reportedly designed to steal sensitive information and disrupt critical services in the U.S. and other nations.

The compromised devices included a widespread network of IoT hardware such as cameras, routers, storage units, and video recorders. According to the joint advisory issued by the Federal Bureau of Investigation (FBI), Cyber National Mission Force (CNMF), and National Security Agency (NSA), the operation not only removed malware from these devices but also severed their links to the larger botnet, making the network powerless.

The takedown came just seven months after, in February 2024, the agency dismantled the KV Botnet, which was used by Volt Typhoon, another Chinese state-sponsored threat actor group.

Scope of the Botnet

The FBI operation reveals the global reach of the botnet. The United States accounted for nearly half of the compromised devices, reflecting the strategic focus on U.S. infrastructure. Other nations, including Vietnam, Germany, and Canada, also faced significant exposure, showing the worldwide threat posed by the botnet.

CountryNode CountPercentage
United States126,00047.9%
Vietnam21,1008.0%
Germany18,9007.2%
Romania9,6003.7%
Hong Kong9,4003.6%
Canada9,2003.5%
South Africa9,0003.4%
United Kingdom8,5003.2%
India5,8002.2%
France5,6002.1%
Bangladesh4,1001.6%
Italy4,0001.5%
Lithuania3,3001.3%
Albania2,8001.1%
Netherlands2,7001.0%
China2,6001.0%
Australia2,4000.9%
Poland2,1000.8%
Spain2,0000.8%
The table shows Botnet Devices per Country

Global Reach and Architecture

The botnet’s impact extended across multiple continents, with North America being the most affected region. Europe and Asia also experienced significant infection rates, while Africa and Oceania had smaller shares. This geographical spread shows the global vulnerability of IoT devices and the strategic use of botnets in cyber warfare.

ContinentNode CountPercentage
North America135,30051.3%
Europe65,60024.9%
Asia50,40019.1%
Africa9,2003.5%
Oceania2,4000.9%
South America8000.3%
The table shows Botnet Devices per Continent

The operation also exposed the types of processors used by the infected devices. The majority were based on the x86 architecture, followed by MIPS and ARM systems, highlighting how a wide array of devices, often lacking sufficient security protocols, can be easily hijacked and integrated into malicious networks.

The full list of vulnerabilities exploited by the botnet, Indicators of Compromise (IoC), and compromised vendors is available here (PDF).

Implications for Global Cybersecurity

The successful dismantling of the botnet not only neutralizes a major threat to U.S. infrastructure but also sends a strong message to other nation-state actors. Additionally, as IoT devices become an integral part of our daily lives, they will increasingly become lucrative targets for cybercriminals. To protect your IoT devices, follow these simple yet vital guidelines:

  • Change Default Passwords: Always update default usernames and passwords on IoT devices to strong, unique credentials.
  • Regularly Update Firmware: Ensure your IoT devices are running the latest firmware to patch any security vulnerabilities.
  • Disable Unnecessary Features: Turn off features or services you don’t need, such as remote access, to reduce potential entry points for attackers.
  • Use a Separate Network: Set up a dedicated network for IoT devices to isolate them from more sensitive devices like computers and smartphones.
  • Enable Encryption: If available, activate encryption settings to protect data transmitted by your IoT devices from being intercepted.
  1. Mozi Botnet Takedown: Who Killed the IoT Zombie Botnet?
  2. Qakbot Botnet Disrupted, Infected 700,000 Computers Globally
  3. 4 Arrested as Operation Endgame Disrupts Ransomware Botnets
  4. Operator of Proxy Botnet ‘IPStorm’ Arrested, Pleads Guilty in US
  5. Google Removes Swing VPN Android App Exposed as DDoS Botnet
Total
0
Shares
Related Posts