Published Aug 17, 2026 by Xiph
There is a small plastic box somewhere in your office. Under a desk, on a storeroom shelf, or bolted to the wall near the meter box. Someone installed it years ago. Nobody has logged into it since. It has no screen, no alerts, and it appears on no asset register you have ever seen.
It is also, by some distance, one of the most attacked devices you own.
The uncomfortable part is not that routers get compromised — that has been true for a decade. It is what compromise looks like from the inside. A hijacked router does not slow down. It does not pop up a warning. Video calls do not stutter and nobody rings the help desk. The box keeps doing its day job perfectly while, in the background, it quietly works a second shift for someone else.
What a botnet actually does with your router
Ask most business owners what a botnet is and you get an answer from about 2016: thousands of hacked devices firing junk traffic at a website until it falls over. That still happens. But the campaigns that matter most in 2026 have moved on to something quieter and far more useful.
In June 2026, Lumen's Black Lotus Labs documented the resurgence of the JDY botnet — a covert network linked to China-nexus state actors, including Volt Typhoon. JDY began as a scanning cluster inside the KV-botnet, which the FBI disrupted in early 2024. The takedown killed the parent. JDY survived, adapted, and has since roughly doubled: from around 650 compromised devices in January 2024 to more than 1,500 small-office, home-office and IoT devices by mid-2026, spanning hardware from Cisco, Ubiquiti, DrayTek, Linksys, Hikvision, Araknis and Mimosa Networks.
What those devices do is the interesting part. JDY is not a wrecking ball; it is a survey crew. It runs TCP, SSL, UDP and ICMP probes across the internet, grabs service banners, collects TLS certificates and fingerprints exactly which software is running on which exposed system — then feeds that structured intelligence back for triage and exploitation by human operators. Its command-and-control routes through Tor, making a repeat takedown considerably harder.
And it is fast. Black Lotus Labs observed JDY's scanning of Fortinet equipment spike within hours of the April 2026 disclosure of CVE-2026-35616, a flaw rated 9.1. Not days. Hours. Someone read the advisory, pushed new fingerprinting rules to the botnet, and had 1,500 residential-looking devices hunting vulnerable Fortinet boxes before most organisations had finished reading the vendor email.
That is the model: the noisy, attributable stage of an attack — finding out who is vulnerable — outsourced to other people's hardware, never touching infrastructure the attacker owns.
JDY is also small by the standards of this problem. The botnet operated by Beijing-based Integrity Technology Group and used by Flax Typhoon held more than 260,000 compromised routers, cameras, video recorders and NAS devices as of June 2024 before the FBI disrupted it. When the UK's NCSC and its international partners published joint guidance in April 2026 on China-nexus covert networks, their central assessment was blunt: the majority of China-nexus threat actors now work this way, across multiple networks that are constantly refreshed and shared between groups.
Why small-office gear is the favourite recruit
None of this is because routers are uniquely fragile. It is because of who owns them, and how.
Nobody is responsible for them. Servers have owners. Laptops have owners. The router was set up by a technician who left in 2021, or by the internet provider, or by the office manager's nephew. Ask who is accountable for its firmware and you usually get a pause.
They are invisible to your security tools. You cannot install an endpoint agent on a modem. If your monitoring stops at the workstation, the device between you and the internet is a blind spot — and it is the first thing an attacker reaches.
They outlive their support. Small-business networking gear typically receives updates for a few years, then quietly stops. The device keeps working, so nobody replaces it. Both the KV-botnet and the Integrity Tech botnet were built substantially on end-of-life equipment: hardware still passing traffic and no longer receiving a single security patch.
They ship with defaults and exposed interfaces. Default admin passwords, remote management enabled on the internet-facing side, UPnP left on, port-forwarding rules added years ago for a purpose nobody remembers. Mirai-family malware — the code behind Flax Typhoon's network — needs nothing clever. It needs a known flaw or a weak credential, and finds both at scale.
And there is no symptom. As we wrote on living-off-the-land attacks, the intrusions worth worrying about are built to be missed. A scanning payload is measured in kilobytes. It is not saturating your NBN connection. You will not notice.

Why this is an Australian problem, not an overseas headline
The heaviest concentrations of JDY nodes sit in the United States and Brazil, so it would be easy to file this under someone else's news. That would be a mistake, for four reasons.
We are already in these numbers. When ASD's ACSC co-sealed the 2024 advisory on the Integrity Tech botnet, roughly 2,400 of the compromised nodes were in Australia. The affected hardware list included known-vulnerable devices from Fortinet, QNAP, Ivanti, DrayTek and Netgear — and older Telstra Smart Modem Gen 2 units. This is not exotic equipment. It is what is actually installed in Australian offices.
Our agencies treat it as a domestic threat. ASD's ACSC co-sealed the April 2026 covert networks advisory alongside the UK, US, Canada, Germany, Japan, the Netherlands, New Zealand, Spain and Sweden. That coalition is how Canberra signals a shared operational problem rather than a foreign one.
The strategic logic points at us. Volt Typhoon's purpose, as we covered in nation-state hackers inside critical infrastructure, is pre-positioning — quiet access held for a future crisis. Reconnaissance botnets are the front end of that work, and Australia sits squarely inside the scenarios that access is built for.
And the new rules do not cover the box you already own. On 4 March 2026, the Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced under the Cyber Security Act 2024 — Australia's first enforceable baseline for consumer connectable products. Three obligations: no universal default passwords, a published vulnerability disclosure channel, and transparency about how long security updates will run, including an end date.
It is a genuinely good reform. It also applies only to devices manufactured on or after 4 March 2026. Every router already sitting in an Australian office is out of scope. The law fixes future supply; it does nothing about the installed base — and the installed base is what the botnets are built from.
The part that should worry a business owner
The first consequence is that your internet connection becomes attack infrastructure aimed at everyone else. Scans, password-spraying and proxied intrusions leave your IP address in someone's logs — and attackers want small-business addresses precisely because they look trustworthy.
The second is closer to home. A device an attacker fully controls sits between your staff and everything they do: it can watch traffic, redirect DNS, and serve as a foothold into the flat network behind it. If you hold client data, that is a potential notifiable breach under the OAIC scheme. The ASD's Annual Cyber Threat Report 2024–25 put the average self-reported cost of cybercrime for an Australian small business at $56,600 per report, up 14 per cent in a year. A forgotten $200 modem is a poor place to start that story.
What this means for your business
The fixes here are unglamorous, cheap and genuinely effective. Attackers are working at machine speed against a target set defined entirely by neglect.
-
Know what is actually on your perimeter. Every router, modem, firewall, VPN appliance, NVR, camera and NAS with an internet-facing interface — list them, with model, firmware version and vendor end-of-support date. Usually a one-afternoon job, and everything else depends on it.
-
Retire unsupported gear, and mean it. If the vendor has stopped shipping firmware, the device is not "still working" — it is permanently vulnerable. Budget replacement on the end-of-service date, not on failure.
-
Kill the defaults. Change the admin credentials, disable remote management from the WAN side, turn off UPnP, and delete port-forwarding rules nobody can justify. This alone puts you out of reach of most commodity botnet malware.
-
Patch the edge first. As we argued in patch speed is your new security score, exposure beats severity. A moderate flaw on an internet-facing box outranks a critical one on an isolated internal system, because attackers scan what they can reach.
-
Segment the untrustworthy things. Cameras, printers, smart TVs and building systems belong on their own VLAN or guest network with client isolation on, not on the same flat LAN as your finance PC.
-
Watch what leaves. A compromised router is quiet inbound and chatty outbound. Baselining normal edge traffic — particularly VPN and remote-access connections — is exactly what the April 2026 advisory asks of smaller organisations, because static indicator lists now expire faster than defenders can use them.
-
Give the box an owner. The most common root cause we find is that no named person is accountable for edge hardware. Assign it internally, or hand it to someone whose job it is.
A final word
Rebooting a router clears some memory-resident malware and is worth doing — but it does nothing about the flaw that let the malware in, and reinfection is often a matter of hours.
SOHO botnets punish inattention rather than incompetence. Nobody made a bad decision here. Somebody installed a box in 2019 and never thought about it again — and adversaries with real resources built entire reconnaissance capabilities out of exactly that habit, across hundreds of thousands of devices.
The good news is that this is one of the few problems in cyber security a small business can genuinely solve. It takes an inventory, a replacement budget and someone paying attention. If you would like help finding out what is sitting on your perimeter and getting it under control, explore our network configuration and management services, or get in touch at enquiries@xiphcyber.com.
Posted in: Security