Compromised routers and cameras feeding a global botnet
01
Threat Intel

FBI Announces Disruption of Global Botnet: What We Can Learn From This

Speculus Threat Research Team·August 26, 2026·4 min read

The devices that carried this botnet were ordinary: home routers, security cameras, devices that can belong to any person or company.

What the FBI announced

On August 26, the FBI and the Department of Justice announced the disruption of a global botnet used by a Chinese state-sponsored group known as QTFY to target U.S. critical infrastructure. Brett Leatherman, Assistant Director of the FBI’s Cyber Division, described a group that has operated for nearly a decade, exploiting software vulnerabilities against government agencies, power companies, telcos, and major hospital systems.

The Bureau links QTFY to Nanjing Xinjiuwei Network Technology, a company that sells stolen data and hacking services to Chinese military and intelligence agencies. Among those services was a scanning platform that, in Leatherman’s words, “scours the internet for vulnerable smart devices like home routers and security cameras, infects thousands of them, and feeds them into a botnet.”

The FBI seized multiple domains the platforms relied on for communication and authentication, rendering them inoperable, and issued a Joint Cybersecurity Advisory with partners to help defenders protect their networks.

How this affects you

Almost every organization, small or large, runs some sort of IoT devices. Adversaries prefer to not pay or directly rent the infrastructure they conduct attacks with. In many cases they opt to use servers someone else already paid for that sit on their home network or cloud provider and stopped thinking about. Cameras and routers are amongst the devices with the highest botnet malware implantations. As mentioned, state actors leverage tools that allow them to rapidly query millions of IoT devices across the globe that have vulnerable versions of software.

Two issues directly arise from this, and they are different problems. The first is that your own devices become someone else’s relay, or as many know it, a Botnet Zombie. The second is subtler and more dangerous: because the traffic hitting your perimeter now originates from consumer broadband ranges geographically near you, the geolocation and ASN attribution most teams lean on no longer work. An authentication attempt from a residential IP two towns over does not look like a nation-state. That is the entire point of the design; their objective is to mask themselves as IPs with known good reputation.

FBI Botnet Takedown Timeline

2024Botnets tied to Volt Typhoon and Flax Typhoon disrupted. Both assembled from compromised routers and edge devices.
2025FBI removes surveillance malware from thousands of U.S. systems.
2026QTFY botnet and scanning platform disrupted; core domains seized; Joint Cybersecurity Advisory issued.

What Speculus Sees

Infrastructure like this is observable before it is attributed. As one of our extensive intelligence pipelines, Speculus operates sensor nodes distributed across the globe, positioned to receive exactly the traffic the FBI described: untargeted scanning, credential spraying against default logins, and the implantation attempts that turn a camera into a node. We accept the implantation and allow the botnet to communicate directly with us, extracting key data to attribute botnet campaigns to a specific IP.

The nodes extract behavioral telemetry rather than matching signatures. LLMs then triage what arrives, separating false positives from genuinely bad behavior, and correlating an address’s activity across every node that has seen it. The output is an instant classification on the IP: what it did, where else it has appeared, and a plain-English verdict an analyst can act on without opening five different tools.

Observe

Global sensor nodes absorb scanning, spraying, and implantation attempts as they happen.

Correlate

Behavior is stitched across nodes so one address becomes one story, not fifty alerts.

Classify

LLM triage separates noise from real intent and returns a verdict with the reasoning attached.

What to do this week

  1. Ensure your edge and IoT devices are patched. This means your team needs to run asset inventory on devices to validate they are running on the latest versions of their respective software.
  2. Inventory what you do not manage. Cameras, routers, NVRs, printers, building systems, vendor-installed sensors.
  3. Hunt outbound, not just inbound. An infected device beacons. Look for edge and IoT devices initiating long-lived connections.
  4. Query IPs against Speculus. Ensure your IPs aren’t already in a botnet or display suspicious behavior by querying them against our platform for free.