Raptor Train is a large China-linked botnet associated with the threat actor Flax Typhoon and attributed by U.S. authorities and private-sector researchers to Integrity Technology Group. Active since at least 2020, it compromised more than 200,000 internet-connected devices worldwide, including SOHO routers, modems, IP cameras, video recorders, firewalls, and network-attached storage systems, with a peak of more than 60,000 active bots observed in 2023. The botnet has been described as a sophisticated multi-tiered operation with enterprise-grade management infrastructure and a primary payload identified as Nosedive, a Mirai-derived malware variant.
Raptor Train functioned as covert operational infrastructure for follow-on intrusion activity rather than as a conventional mass-disruption botnet. It was used to support targeting of sectors including government, military, telecommunications, higher education, information technology, and the defense industrial base, with particular focus on organizations in the United States and Taiwan. Reported activity included scanning and exploitation attempts against externally exposed enterprise systems, and the botnet was also characterized by government agencies as part of a broader pattern in which China-nexus actors use compromised edge and IoT devices as proxy networks to conceal origin, relay traffic, and enable further intrusions.
The botnet exploited numerous device types through both known and previously unknown vulnerabilities. Infected edge devices generally did not retain the payload for long because the malware lacked persistence, but the broader infrastructure remained resilient through layered command-and-control and manually operated management nodes. Law enforcement disruption actions in 2024 targeted this infrastructure and removed malware from infected devices. Raptor Train is notable as an example of state-aligned use of large-scale compromised consumer and small-enterprise networking equipment to provide stealthy, distributed infrastructure for espionage-oriented cyber operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The FBI and cybersecurity researchers have disrupted a massive Chinese botnet called “Raptor Train” that infected over 260,000 networking devices to target critical infrastructure in the US and in other countries.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model. It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
Since May 2020, over 200,000 devices, including SOHO routers, NVR/DVR devices, NAS servers, and IP cameras, have been compromised and added to the Raptor Train botnet.
For example, China's Integrity Technology Group controlled and managed the so-called Raptor Train network, which in 2024 infected more than 200,000 devices worldwide, including small office home office (SOHO) routers, internet-connected web cameras and video recorders, plus firewalls and network-attached storage (NAS) devices.
The Raptor Train botnet, disrupted by the United States, offers a clear illustration of this contractor model. It was attributed to Chengdu-based Integrity Technology Group, found responsible for developing the botnet and therefore held partly accountable for intrusion activities attributed to Flax Typhoon.
The malware connected these thousands of infected devices into a botnet, controlled by Integrity Technology Group, which was used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices.
A majority of China-linked threat actors are using compromised routers and IoT devices worldwide, turning this gear into proxy networks to carry out further intrusions, steal sensitive data, and disrupt victim organizations’ operations.
...used to conduct malicious cyber activity disguised as routine internet traffic from the infected consumer devices... For the second time this year, we have disrupted a botnet used by PRC proxies to conceal their efforts to hack into networks in the U.S. and around the world...
20 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only in related content as another botnet.
A botnet developed by Integrity Technology Group and linked to intrusion activity attributed to Flax Typhoon, illustrating the role of private contractors in Chinese cyber operations.
A large covert network/botnet of compromised routers, cameras, recorders, firewalls, and NAS devices used to provide proxy infrastructure for China-linked intrusion activity.
Long-running botnet campaign built over several years, with large numbers of compromised devices and an expanding multi-tier C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.