Skip to main content

Defending against China-nexus covert networks of compromised devices

Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it

Logos of the international partners who are jointly releasing the Advisory





This guidance should be considered alongside all applicable laws and regulations of the UK and co-sealing countries relating to the security of networks and data. It will be each organisation’s responsibility to ensure compliance with any such laws and regulations. Organisations should note that following the recommended actions set out below will not remove all risks.

All organisations

The NCSC recommends the following steps for all affected organisations to either take themselves, or ask their managed service and/or security providers to investigate for them:

  • Map and understand network edge devices, developing a clear understanding of organisational assets and what should be connecting to them.
  • Baseline normal connections, especially to corporate virtual private networks (VPNs) or other similar services.
    • Would you expect connections from consumer broadband ranges?
  • Leverage available dynamic threat feeds which include covert network infrastructure.
  • Implement multi-factor authentication for remote connections.

Smaller organisations should consider creating and actioning a free NCSC Cyber Action Toolkit.

Larger or more at-risk organisations

Some more comprehensive measures may be appropriate if the risk to an organisation is high enough, to be conducted either in-house or through a security provider:

  • Apply IP address allow lists rather than deny lists for connections to corporate VPNs for remote workers.
  • Use geographic allow lists or profile incoming connections based on operating system, time zones, and/or organisation specific system configuration settings.
  • Implement zero trust policies for connections.
  • Enforce machine certificates for Secure Sockets Layer (SSL) connections.
  • Reduce the internet-facing presence of the IT estate.
  • Investigate machine learning techniques to profile normal network edge activity to detect and block anomalies.

The NCSC's Cyber Essentials can help protect organisations of all sizes.

Largest or most at-risk organisations

If Advanced Persistent Threat (APT) tracking is part of an organisation’s in-house capability, or if it is part of the service provided by a security vendor, consider tracking China-nexus covert networks as APTs in their own right.

  • Active hunting – look for connections from IP addresses likely to be part of a covert network of compromised devices, for instance those hosting SOHO routers or IoT devices.
  • Track and map covert networks reported by industry or government by looking at banners and certificates.
  • Use threat reporting and threat feeds to create and implement dynamic blocklists and create alert rules to detect incoming threats.
  • Consider using NetFlow feeds to look upstream and map covert networks to find new nodes.

The NCSC Cyber Assessment Framework provides guidance for organisations under the highest levels of threat, including those operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government. 




Published

News type

Alert