UK WARNS OF CHINESE HACKERS USING PROXY NETWORKS
SECURITY DESK■ 2 MIN READ
THU, APR 23, 2026■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE
The UK's National Cyber Security Centre and international partners have issued a warning about China-nexus hackers increasingly using large-scale proxy networks built from hijacked consumer devices to mask their malicious activity and evade detection.
The NCSC-UK identified a significant shift in tactics employed by Chinese threat actors, who are leveraging compromised consumer devices to create distributed proxy networks. These hijacked devices serve as intermediaries, routing malicious traffic through multiple layers to obscure the true origin of cyberattacks.
By funneling their operations through consumer-grade hardware rather than traditional infrastructure, the hackers reduce their digital footprint and complicate attribution efforts. This approach allows threat actors to conduct espionage, data theft, and other malicious operations while remaining difficult to track and identify.
The warning reflects growing concerns among Western cybersecurity agencies about the sophistication and scale of Chinese state-sponsored hacking operations. The use of proxy networks demonstrates an evolution in tradecraft designed specifically to counter established detection methods used by security researchers and law enforcement.
Consumer devices targeted by these operations likely include routers, IoT devices, and other internet-connected hardware with inadequate security protections. Once compromised, these devices become part of a botnet infrastructure that can be activated at scale to support hacking campaigns.
The NCSC-UK and its international partners recommend organizations implement stronger network monitoring to detect unusual outbound traffic patterns. They also advise updating device firmware, enforcing strong password policies, and conducting regular security audits to identify compromised systems within their networks.
This warning underscores the ongoing cyber espionage threat from state-sponsored actors and the importance of maintaining robust cybersecurity practices across both organizational and consumer-level devices. The NCSC-UK continues to share threat intelligence with allies and the private sector to improve collective defenses against these tactics.
■ MORE FROM THE SECURITY DESK
Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.
MAY 29— Industry Desk
Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.
MAY 29— Security Desk
Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.
MAY 29— Industry Desk
Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.
MAY 29— Security Desk