Security1 distinct publisher2 min readPublished
Black Lotus Labs assesses the botnet as Chinese state work under Flax Typhoon, assembled from SOHO routers, NVRs, NAS boxes and IP cameras whose 17-day average lifespan makes the infrastructure disposable by design.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The arithmetic on the bottom tier decides how defenders should treat this. Black Lotus Labs puts the average life of a compromised device at 17 days, partly because of what the physical devices are and how they get used [12]. Holding the June 2023 peak of just over 60,000 live bots [2] therefore requires on the order of 3,500 fresh compromises per day [13]. Recruitment at that rate is a standing operation with a staffing line, not a campaign with an end date. The cumulative figure follows from it: the 200,000-plus routers, NVR/DVR units, NAS servers and IP cameras conscripted since that peak [3] is more than three times the largest concurrent population ever measured [14].
The bots never see the people driving them. Tasks start at Tier 3 "Sparrow" management nodes, route through Tier 2 command-and-control servers, and land on Tier 1 [12]. Sparrow is a Node.js backend with a cross-platform Electron front end, sitting over upwards of 60 C2 servers at any given time [5], and it ships with exploit and vulnerability management, file transfer, remote command execution and DDoS tasking [6]. Lumen's read is that the automation frees hands for exploitation and lets more operators contribute [6], which puts the ceiling on this network at headcount rather than skill.
Reputation filtering does not help. A C2 domain in the most recent campaign appeared on both the Cloudflare Radar and Cisco Umbrella top 1 million popularity lists [10]. Anything that passes traffic to popular domains passes that.
Downstream, nodes on this network made possible exploitation attempts against Atlassian Confluence servers and Ivanti Connect Secure appliances [9], while the targeting Black Lotus Labs observed covers U.S. and Taiwanese military, government, higher education, telecommunications, defense industrial base and IT organisations [8]. The camera in a branch office is upstream of somebody else's incident response.
Two limits on the evidence. No DDoS attack has been seen from Raptor Train, and the claim that the operators are holding that capability in reserve is Lumen's assessment rather than an observation [7]. And this account is the high-level one, with malware analysis and per-campaign detail held in a separate downloadable report [15], so the initial-access flaws for each device class are not in it. Lumen has null-routed traffic to the known management, C2, payload and exploitation infrastructure and warned U.S. government agencies [11]. That removes the servers. It does not remove the pool of devices that can be re-recruited at 3,500 a day.
Ranked by verification strength, evidence, and original report placement.
In mid-2023 Lumen's Black Lotus Labs began investigating compromised routers, leading to the discovery of a large multi-tiered botnet of SOHO and IoT devices, named Raptor Train, that it assesses is likely operated by the Chinese nation-state threat actors known as Flax Typhoon; the botnet has been over four years in the making.
At its peak in June 2023 the Raptor Train botnet consisted of over 60,000 actively compromised devices.
Since the June 2023 peak, more than 200,000 SOHO routers, NVR/DVR devices, network attached storage servers and IP cameras have been conscripted into Raptor Train, making it one of the largest Chinese state-sponsored IoT botnets discovered to date.
Operators manage the network through distributed payload and C2 servers, a centralized Node.js backend and a cross-platform Electron application front end the actors call "Sparrow", controlling upwards of 60 C2 servers and their infected nodes at any given time.
The Sparrow control system enables scalable exploitation of bots, vulnerability and exploit management, remote management of C2 infrastructure, file uploads and downloads, remote command execution and the ability to tailor IoT-based DDoS attacks at scale; Black Lotus Labs says the automation frees time for hands-on exploitation and allows more threat actors to contribute to operations.
Black Lotus Labs has not seen any DDoS attacks originating from Raptor Train and suspects this is an ability the China-based operators preserve for future use.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A Chinese state contractor rented its concealment from a commercial consumer proxy service1 distinct publisher
security
The espionage quartermaster: China-nexus operators were buying scan and relay as a service1 distinct publisher
security
Volt Typhoon-linked JDY botnet climbed back to 1,500 devices after the KV takedown1 distinct publisher
product
DOJ names China's proxy quartermaster; the seizure took domains, not devices1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Deep telemetry, one vantage point
The detail is the kind you only get from inside a backbone: tier lifecycles, a named actor tool, implant behaviour per architecture, a C2 domain surfacing in public popularity rankings. It is also entirely Lumen's, with the malware analysis moved into a separate download and no second party confirming a single figure. The strongest points are the counted ones; the four-year cumulative total is a stated suspicion, and the Confluence and Ivanti activity is described as possible rather than established.
Real footprint, self-reported
Adoption in this story means devices actually taken, and the numbers are concrete: 60,000 concurrent at peak, 200,000-plus since, upwards of 60 C2 servers, probes reaching Confluence and Ivanti estates. One data point comes from outside Lumen's own telemetry — a campaign C2 domain ranking in the Cloudflare Radar and Cisco Umbrella top million — which is the closest thing here to external corroboration of scale. What is missing is the other side of the ledger: no named victims, no confirmed intrusions, no count of how many operators or campaigns the infrastructure served.
Superlative runs slightly ahead of the proof
Lumen's counted figures are sober; the framing around them leans. 'One of the largest Chinese state-sponsored IoT botnets discovered to-date' is the discoverer grading its own find, the DDoS capability is presented as withheld for future use on the strength of never having been seen, and the four-year total is a suspicion carried in the same paragraph as hard counts. Against that, the story understates one thing badly: it reports a 17-day bot lifetime without noting that sustaining 60,000 devices at that rate means thousands of new compromises daily, which is a harsher finding than any of the superlatives.
The investigator sells the remedy
Black Lotus Labs is Lumen's research arm, and the post that names the threat also reports Lumen null-routing it on Lumen's network, commends the FBI and DOJ, and routes the technical substance into a downloadable report. None of that makes the findings wrong — a tier-3 backbone is exactly where this telemetry lives — but every incentive here points one way: the party defining the threat's severity also owns the visibility and the mitigation being praised.
Firm on mechanics, unaccompanied on the rest
We would defend the architecture, the device classes and the lifecycle numbers as reported — they are internally consistent and specific to the point of falsifiability. Confidence drops on attribution, on the four-year cumulative total, and on victim impact, all of which rest on assessment language from a single lab with nobody standing beside it. The churn figure in our own headline is arithmetic, and it is only as good as the two inputs Lumen supplied.