Chinese Botnet “Raptor Train” Infects 260,000 Devices Worldwide

September 18, 2024 A massive Chinese botnet dubbed “Raptor Train” has been disrupted by the FBI and cybersecurity researchers. This sophisticated network infected over 260,000 networking devices, primarily targeting critical infrastructure in the United States and other countries. According to FBI reports almost half the infected nodes were in the US and Canada with 126,000 in the US and 9,600 in Canada.

The botnet, active since May 2020, targeted entities in military, government, higher education, telecommunications, defense, and IT sectors.  The FBI has linked the botnet to the Chinese state-sponsored hacker group Flax Typhoon

Raptor Train infected a wide range of devices, including SOHO routers, IP cameras, and network-attached storage servers. At its peak in June 2023, the botnet controlled over 60,000 devices simultaneously.

The primary payload is a variant of the Mirai malware, which researchers call Nosedive, designed for DDoS attacks. The botnet’s sophisticated architecture includes three tiers of activity for specific operations, making it highly adaptable and resilient.

FBI Director Christopher Wray confirmed that the bureau executed court-authorized operations to take control of the botnet infrastructure and remove malware from infected devices.

This discovery highlights the ongoing cybersecurity threats posed by state-sponsored actors and the vulnerability of consumer and small business networking devices.

Users are advised to regularly reboot their routers, ensure that they have installed the latest updates, and replace any end-of-life devices to protect against such threats. This advice should apply to corporate equipment and any work from home or home offices.

 

Top Stories

Related Articles

March 19, 2026 The FBI has gone back to purchasing commercially available data, including Americans’ location histories, to support federal more...

March 12, 2026 A cyber attack has disrupted global operations at medical technology company Stryker after hackers reportedly wiped corporate more...

March 10, 2026 Microsoft is introducing a new top-tier Microsoft 365 subscription called E7 that bundles its Copilot artificial intelligence more...

March 10, 2026 Dutch intelligence agencies say Russian state-linked hackers are conducting a global campaign to compromise Signal and WhatsApp more...

Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com
Picture of Jim Love

Jim Love

Jim Love's career in technology spans more that four decades. He's been a CIO and headed a world wide Management Consulting practice. As an entrepreneur he built his own tech business. Today he is a podcast host with the popular tech podcasts Hashtag Trending and Cybersecurity Today with over 14 million downloads. As a novelist, his latest book "Elisa: A Tale of Quantum Kisses" is an Audible best seller. In addition, Jim is a songwriter and recording artist with a Juno nomination and a gold album to his credit. His music can be found at music.jimlove.com

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn