Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

China-linked threat actors have compromised thousands of internet-connected devices—including SOHO routers, firewalls, network-attached storage (NAS) systems and other IoT equipment—to create infrastructure they can use for concealment, command-and-control routing and access to other networks. These devices may belong to people or businesses that are not the attackers’ ultimate intelligence or disruption targets.

Two publicly documented operations illustrate different uses of this infrastructure. A 2024 joint advisory from the FBI, Cyber National Mission Force (CNMF) and NSA describes a botnet managed by Integrity Technology Group that had been active since mid-2021. Separately, the U.S. Department of Justice (DOJ) says Volt Typhoon used the KV Botnet, made largely of end-of-life Cisco and Netgear SOHO routers, to hide the origin of further intrusions.

Why routers and other edge devices are valuable

Routers sit between the internet and the networks behind them. After compromise, an edge device can relay traffic so that activity appears to come from an ordinary household or small-business connection rather than from infrastructure associated with the operator. It can also carry command-and-control traffic, provide a stepping stone into a connected network, or participate in a larger botnet.

That role is different from persistent access inside a victim’s enterprise. A compromised router can be an intermediary or disposable node even when its owner is not the intended target. The FBI, CNMF and NSA advisory’s device list extends beyond routers to firewalls, NAS systems and IoT devices, reflecting a broad exposed-device problem rather than proof that every device in any category is compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SonicWall TZ270W Wireless Gen7 Firewall | SMB Wi-Fi Security Appliance with 2 Gbps Firewall Speed, Integrated Wireless Radios, Threat Protection, and Cloud Management (02-SSC-2823)
  • SonicWall TZ270W Appliance Only - No Service Subscription (02-SSC-2823) - Combines enterprise-grade firewalling with integrated 802.11ac Wave 2 Wi-Fi to deliver secure wired and wireless connectivity in one compact device for small offices and clinics.
  • Blocks zero-day threats and ransomware with Capture ATP sandboxing enhanced by RTDMI, plus IPS and anti-malware scanning for layered protection.
  • Eliminates the need for separate access points in smaller spaces thanks to built-in high-speed wireless that is simple to deploy and manage.
  • Supports VPN, SD-WAN, and TLS 1.3 decryption to secure hybrid cloud access and remote workers while maintaining usability and performance.
  • Delivers gigabit performance with up to 750,000 concurrent connections to handle growth in users, devices, and SaaS applications.

What the official cases establish

Operation What agencies reported Scope and limits
Integrity Technology Group-managed botnet The FBI, CNMF and NSA assessed that PRC-linked actors compromised “thousands” of internet-connected devices, including SOHO routers, firewalls, NAS and IoT devices. The advisory dates the botnet’s activity to mid-2021. The published figure is “thousands,” not an exact count. The advisory attributes management to Integrity Technology Group; it does not establish that this botnet is the same operation as KV Botnet.
Volt Typhoon’s KV Botnet DOJ says Volt Typhoon used privately owned SOHO routers infected with KV Botnet malware to conceal the PRC origin of later hacking activity against U.S. and foreign victims. DOJ describes “hundreds” of U.S.-based routers disrupted in a court-authorized operation in December 2023. The vast majority were end-of-life Cisco and Netgear devices, but DOJ gives no precise percentage.

These accounts should not be merged into one campaign. They involve different named actors, infrastructure and official descriptions, even though both show why exposed networking equipment can be useful to a state-linked operator.

How the KV Botnet disruption worked—and why replacement still mattered

In January 2024, DOJ announced that the U.S. government had disrupted the KV Botnet on hundreds of U.S.-based SOHO routers through a court-authorized operation conducted in December 2023. DOJ warned that the mitigation could be reversed by restarting a router. Without additional mitigation, a restarted device could therefore be exposed to reinfection.

The routers in that case were predominantly Cisco and Netgear models that had reached end-of-life. End-of-life equipment no longer receives the manufacturer’s security patches or other software updates, leaving newly discovered flaws without a supported fix. The finding applies to the KV Botnet case; it is not evidence that those brands dominate every China-linked campaign or that a current, supported model is immune.

Rank #2
Sale
FortiGate-60F Firewall Appliance - 10 Gigabit Ethernet RJ45 Ports, Includes DMZ, WAN & Internal Ports (Appliance Only, No Subscription) (FG-60F)
  • Extensive Connectivity Options: The FortiGate 60F is designed with 10 GE RJ45 ports, including 2 WAN ports, 1 DMZ port, and 7 internal ports, offering broad flexibility and high-density connections for diverse enterprise networking needs.
  • Superior Performance for Secure Networks: Features powerful system-on-a-chip acceleration to deliver top-tier security with 1.4 Gbps IPS throughput and 700 Mbps threat protection throughput, ensuring effective defense against advanced threats.
  • Enhanced SSL Inspection and SD-WAN Capabilities: Utilizes purpose-built security processor technology to provide the industry's highest SSL inspection performance and robust SD-WAN functionality for secure, high-speed network operations.
  • Simple and Effective Management: Comes equipped with a user-friendly management console that supports comprehensive network automation and visibility, alongside Zero Touch Integration with Fortinet's Security Fabric for streamlined deployment.
  • Advanced Security Features: Leverages continuous threat intelligence from AI-powered FortiGuard Labs, identifying and mitigating both known and unknown threats, enhancing security across all network traffic, whether encrypted or not.

What “widespread attack infrastructure” means in practice

Concealing origin

Traffic routed through compromised residential or small-business equipment can make a later intrusion appear to originate from an unrelated local connection. This complicates attribution and can help an operator blend into normal internet traffic.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Relaying command and control

A distributed set of devices can forward instructions and data between an operator and other compromised systems. Losing one node does not necessarily remove the rest of the network.

Reaching connected networks

An edge device may expose management services, trusted relationships or routes into the network it serves. That does not mean every compromised router gives an attacker full access to every device behind it; the resulting access depends on configuration, vulnerabilities and the operator’s objectives.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Providing disposable infrastructure

Large pools of third-party devices give an operator alternatives when a node is identified, blocked or taken offline. Owners can therefore be affected as infrastructure providers without being the campaign’s primary intelligence target.

How to tell whether a home or small-business router is end of life

  1. Find the exact model and hardware revision on the device label or its administration page.
  2. Open the manufacturer’s support, download or security-advisory page and search for that exact model and revision.
  3. Check the published end-of-sale or end-of-support date and the date of the newest firmware release.
  4. Confirm whether the manufacturer still provides security fixes for newly disclosed vulnerabilities and whether the model can receive them.
  5. If support has ended, replace the device rather than relying on a one-time reset or a consumer antivirus product.

DOJ specifically encourages owners to replace end-of-life SOHO routers. A replacement lowers exposure to known unsupported-device flaws only if it remains updated and is configured securely.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What households should do now

  • Install the manufacturer’s current firmware according to its instructions.
  • Use a long, unique administrator password and change any default credentials.
  • Keep the router’s management interface off the public internet unless remote administration is genuinely required; restrict it to trusted networks or an approved secure access method.
  • Disable unnecessary remote-management, Universal Plug and Play or other exposed services when they are not needed.
  • Choose a supported replacement with an explicit, ongoing security-update commitment if the existing unit is end of life.
  • After a suspected compromise, preserve relevant logs if available, update or replace the device, and review connected accounts and devices for unauthorized changes.

Ordinary endpoint antivirus software generally cannot inspect or clean the router itself, so do not treat an apparently healthy laptop or phone as proof that the network device is clean.

Rank #4
Sale
FortiGate-40F Network Security Appliance Plus 3 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-40F-BDL-950-36)
  • INTEGRATED FIREWALL APPLIANCE AND SECURITY SERVICES: Comes with FortiGate-40F Firewall Appliance, 3 years of FortiCare Premium, and FortiGuard Unified Threat Protection.
  • UTP SECURITY FEATURES: Offers protection from advanced threats with DNS filtering, URL filtering, video filtering, and controls against botnets.
  • IDEAL FOR SMALLER SETTINGS: Best suited for small to mid-sized businesses needing reliable security without the complexity of larger systems.
  • CONTINUOUS SUPPORT AND MAINTENANCE: FortiCare Premium ensures that technical help is readily available to manage and troubleshoot issues.
  • COMPACT AND EFFECTIVE: Provides a powerful, yet compact security solution that effectively protects against a wide range of cyber threats.

What organizations should monitor

CISA’s September 2025 advisory recommends regularly reviewing network-device logs and configurations—especially routers—for unexpected or unusual activity. Security teams should baseline normal administrative access, firmware versions, DNS and routing settings, and management-interface exposure, then investigate unexplained changes.

  • Alert on administrator logins from unusual locations, times or source addresses.
  • Look for unexpected firmware changes, new accounts, altered DNS servers, modified port-forwarding rules or unexplained configuration resets.
  • Review outbound connections and router logs for anomalous destinations or persistent traffic patterns.
  • Segment management networks and limit who can administer edge devices.
  • Use the multi-agency Enhanced Visibility and Hardening Guidance for Communications Infrastructure for communications-infrastructure-specific controls.

These checks help identify misuse of a device as a relay or botnet node; they do not by themselves prove which actor operated it.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose a replacement router

No agency cited here endorses a particular brand or model. Compare products on security-support characteristics rather than assuming any manufacturer is immune to compromise.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Selection question What a stronger answer looks like
Is the exact model still supported? The manufacturer publishes a current support lifecycle and security advisories for the model and hardware revision.
How are updates delivered? Firmware updates are signed and can be applied automatically or with a clear, reliable update process.
What are the defaults? The device ships with secure defaults, forces or encourages unique administrator credentials, and does not expose management to the public internet by default.
Does it fit the network? Its capacity and features match the household or small-business network, without adding unnecessary internet-facing services.

Keeping the replacement updated and limiting administrative exposure are as important as buying a newer model.

Why secure-by-design requirements matter

CISA and the FBI define “Secure by Design” as manufacturers designing and building products in a way that reasonably protects against malicious cyber actors successfully exploiting product defects. Their guidance calls for secure defaults, automated signed updates and protections for management interfaces.

Those features address the conditions that make edge-device botnets scalable: forgotten equipment, difficult update processes and administration interfaces exposed to the internet. They do not eliminate risk, but they reduce the number of devices that remain easy to compromise and hard to repair.

The broader warning for critical infrastructure

FBI Director Christopher Wray said on January 31, 2024: “China’s hackers are targeting American civilian critical infrastructure, pre-positioning to cause real-world harm to American citizens and communities in the event of conflict.” The botnet cases show one way that pre-positioning can be supported: compromise ordinary network equipment first, then use a distributed layer of third-party devices to conceal or facilitate later operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The practical implication is straightforward. Treat routers, firewalls, NAS systems and other internet-facing devices as security-critical computers, not as appliances that can be installed once and forgotten.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.