:

UK WARNS OF CHINESE HACKERS USING PROXY NETWORKS

SECURITY DESK2 MIN READ
THU, APR 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The UK's National Cyber Security Centre and international partners have issued a warning about China-nexus hackers increasingly using large-scale proxy networks built from hijacked consumer devices to mask their malicious activity and evade detection.

The NCSC-UK identified a significant shift in tactics employed by Chinese threat actors, who are leveraging compromised consumer devices to create distributed proxy networks. These hijacked devices serve as intermediaries, routing malicious traffic through multiple layers to obscure the true origin of cyberattacks. By funneling their operations through consumer-grade hardware rather than traditional infrastructure, the hackers reduce their digital footprint and complicate attribution efforts. This approach allows threat actors to conduct espionage, data theft, and other malicious operations while remaining difficult to track and identify. The warning reflects growing concerns among Western cybersecurity agencies about the sophistication and scale of Chinese state-sponsored hacking operations. The use of proxy networks demonstrates an evolution in tradecraft designed specifically to counter established detection methods used by security researchers and law enforcement. Consumer devices targeted by these operations likely include routers, IoT devices, and other internet-connected hardware with inadequate security protections. Once compromised, these devices become part of a botnet infrastructure that can be activated at scale to support hacking campaigns. The NCSC-UK and its international partners recommend organizations implement stronger network monitoring to detect unusual outbound traffic patterns. They also advise updating device firmware, enforcing strong password policies, and conducting regular security audits to identify compromised systems within their networks. This warning underscores the ongoing cyber espionage threat from state-sponsored actors and the importance of maintaining robust cybersecurity practices across both organizational and consumer-level devices. The NCSC-UK continues to share threat intelligence with allies and the private sector to improve collective defenses against these tactics.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Berlin's city administration has confirmed that the Rhysida ransomware gang stole data and is attempting extortion after listing the city on their data leak site.

JUST NOWAI Desk

A security researcher discovered nine vulnerabilities in ATM encryption and authentication software. The findings highlight systemic weaknesses affecting critical infrastructure beyond banking.

3H AGOAI Desk

Anthropic has signed out some Claude users and removed saved payment methods after infostealer malware on their computers hijacked active sessions to drain API usage credits. The company is issuing refunds for unauthorized charges.

13H AGOAI Desk

Former NYC Traffic Commissioner Sam Schwartz warns that autonomous vehicle expansion creates significant cybersecurity risks, including the potential for bad actors to seize control of connected cars and weaponize them.

13H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.