iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A China-linked botnet contained more than 260,000 compromised devices as of June 2024, according to a joint advisory from the FBI, Cyber National Mission Force (CNMF) and National Security Agency (NSA). The agencies linked its management infrastructure to China-based company Integrity Technology Group. The figure is a dated estimate—not a count of devices known to remain infected today.
What was the botnet?
The September 18, 2024 FBI, CNMF and NSA advisory describes a network of compromised small office/home office (SOHO) routers, firewalls, network-attached storage (NAS) systems and other Internet of Things (IoT) devices. Active since mid-2021, the botnet gave operators compromised devices they could use to route activity and conceal their identities, support distributed denial-of-service attacks, or help compromise targeted networks.
The agencies associated its management infrastructure with Integrity Technology Group, a company based in China. They said related intrusions against U.S. victims were consistent with activity publicly tracked as Flax Typhoon, RedJuliett and Ethereal Panda. Those names come from different tracking and attribution systems; the advisory cautions that cybersecurity companies’ labels and methods do not always map one-to-one to the government’s assessment.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat devices and how many were affected?
The advisory says the customized Mirai-family malware targeted Linux-based devices, including webcams, DVRs, IP cameras and routers. The reported infection chain used known vulnerability exploits to compromise devices, deliver a Mirai-based payload and connect devices to command-and-control infrastructure. Some payloads were self-deleting.
#1 Best Overall
- Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
- Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
- Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
- Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
- Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks
That does not mean every router, Chinese-made product or Linux device was affected. The advisory describes specific compromised systems and a botnet estimate, not a universal vulnerability across those device categories.
| Measure | Agency estimate as of June 2024 |
|---|---|
| Devices in the botnet | More than 260,000 |
| Nodes in the United States | 126,000 (47.9% of the botnet estimate) |
| Nodes in North America | 135,300 (51.3% of the estimate) |
| Regional estimates elsewhere | Europe: 65,600; Asia: 50,400; Africa: 9,200; Oceania: 2,400; South America: 800 |
| Management-database records | More than 1.2 million records, including more than 385,000 unique U.S. victim devices previously and actively exploited |
All figures in the table are from the FBI, CNMF and NSA advisory and refer to its June 2024 snapshot. The management-database totals are not another count of devices simultaneously in the botnet: records and unique devices previously or actively exploited measure something different from the estimate of more than 260,000 compromised devices.
Rank #2
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Could a home router have been affected?
Yes. SOHO routers were among the device types described, alongside firewalls, NAS systems and other IoT equipment. But the advisory does not provide a consumer self-test that can confirm whether an individual router was compromised, nor does it establish a current infection count. An unusual slowdown or a change in connectivity alone cannot confirm this specific botnet.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →How to reduce the risk on your network
The agencies recommend practical steps for device owners and network administrators. Apply those that fit your equipment and network:
Quick Recap
Best Value
- Beyond-fast WiFi 7 (802.11be) - WiFi 7 (802.11be) dual-band extendable router boosts speeds up to 3600 Mbps, with 4096-QAM increasing a single frequency band’s transmission speed by 1.2 times
- Unleashing Multi-link operation (MLO) for Ultra-Smooth Connectivity - Link to multiple bands at the same time to ensure stable internet connections and efficient data transfers
- Versatile WAN configuration options - Establish always-on internet through AI WAN detection and a convenient USB port ready for 4G LTE and 5G Mobile tethering.
- Smart Home Master - Easily establish up to three SSIDs with Smart Home Master for easy IoT device setup and management, instant VPN connections, and convenient parental controls.
- Commercial-Grade network security - Network security with commercial-grade AiProtection Pro powered by Trend Micro, plus a one-tap security scan and Safe Browsing.
Rank #4
- New-Gen WiFi Standard – WiFi 6(802.11ax) standard supporting MU-MIMO and OFDMA technology for better efficiency and throughput.Antenna : External antenna x 4. Processor : Dual-core (4 VPE). Power Supply : AC Input : 110V~240V(50~60Hz), DC Output : 12 V with max. 1.5A current.
- Ultra-fast WiFi Speed – RT-AX1800S supports 1024-QAM for dramatically faster wireless connections
- Increase Capacity and Efficiency – Supporting not only MU-MIMO but also OFDMA technique to efficiently allocate channels, communicate with multiple devices simultaneously
- 5 Gigabit ports – One Gigabit WAN port and four Gigabit LAN ports, 10X faster than 100–Base T Ethernet.
- Commercial-grade Security Anywhere – Protect your home network with AiProtection Classic, powered by Trend Micro. And when away from home, ASUS Instant Guard gives you a one-click secure VPN.
Rank #3
- 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
- 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
- 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
- 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
- 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.
- Install vendor firmware and software updates. Use trusted update channels and keep network devices current.
- Change default passwords. Use strong, unique credentials for each device.
- Turn off services you do not need. Disable unused ports and services, including remote management or UPnP when unnecessary.
- Separate IoT devices from sensitive systems. Segment them and limit their network access to what they need to function.
- Watch for unusual traffic volumes. Unexpectedly high network traffic can merit investigation, though it is not by itself proof of infection.
- Plan reboots where appropriate. A reboot can interrupt service and is not a guaranteed cleanup for every compromise.
- Replace equipment that has reached end of life. Choose devices that remain covered by the vendor’s support plan and receive security updates.
Is this the same as the 2026 QTFY seizure?
No. The FBI, CNMF and NSA advisory concerns the Integrity Tech-associated botnet and was published in September 2024. The Department of Justice’s August 26, 2026 announcement describes a separate disruption involving the QTFY, QScan and QTRouter platforms. It mentions the 2024 Flax Typhoon botnet disruption as a prior operation; it does not make QTFY part of the 260,000-device estimate.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

