Twelve nations signed it. CISA and NCSC published it in April. Most coverage it received was proportional to a quiet news week rather than to what the document actually says: the geographic and reputation-based controls at the core of most Western network defences have a structural failure mode when applied to Chinese state-sponsored actors, and that this failure mode is deliberate.
The advisory is worth reading in full. Here’s the part that matters most.
Why your IP blocklists aren’t seeing this
The foundational assumption behind geographic filtering is that attacks come from somewhere identifiable. Block the Chinese address ranges, flag the known-bad IPs, maintain the reputation databases. This logic holds reasonably well against commodity threats. Against Volt Typhoon and Flax Typhoon, it fails in a way that’s hard to fix.
These actors have moved away from dedicated offensive infrastructure entirely. What the advisory calls “covert networks” are large, rotating pools of compromised devices (predominantly end-of-life SOHO routers, consumer IoT hardware, NAS boxes) configured as multi-hop relay infrastructure. Traffic from a Chinese APT operation gets bounced through a broadband router in Manchester, a NAS device in Lyon, and a CCTV camera in Rotterdam before it touches a UK target. What shows up in your logs is three European IP addresses. Not suspicious. Certainly not attributable to Beijing.
The advisory specifically names Volt Typhoon and Flax Typhoon, and notes a further complication: a single covert network is likely used by multiple distinct actor groups simultaneously. Observing traffic through a given relay infrastructure doesn’t tell you which specific group is operating, or what the operation’s purpose is. The infrastructure is shared. Espionage collection, pre-positioning, and active intrusion preparation can run through the same compromised router.
Building the network, and why you can’t simply disrupt it
The construction methodology is straightforward and operationally resilient. Actors identify vulnerable edge devices (routers past end-of-life, IoT kit running default credentials, NAS systems with unpatched remote access) and compromise them at scale. The compromised devices get configured as relays. When devices drop off because they’re rebooted, patched, or replaced, they’re replaced with newly compromised ones. The network is continuously replenished.
The FBI learned this the hard way. In September 2023, they disrupted a Volt Typhoon botnet built largely on compromised Cisco and Netgear routers at end of life. Technically successful. Volt Typhoon rebuilt and continued operations. The advisory is direct about this: the networks are “constantly updated,” and the pool of vulnerable edge devices available for compromise is not shrinking.
This is why law enforcement’s track record against RaaS platforms doesn’t translate here. Ransomware infrastructure has chokepoints (payment portals, leak sites, admin panels) that can be seized and held. A botnet composed of an ever-rotating pool of consumer routers has no equivalent structure to attack. You can disrupt a specific instance. You cannot disrupt the approach.
Three things this changes for network defenders
The advisory doesn’t say the threat is undetectable. It says standard detection approaches are insufficient. That distinction matters.
Geographic filtering remains worth doing, but don’t mistake it for a nation-state control. Blocking high-risk geographies reduces your attack surface from commodity actors. It removes the low-sophistication traffic that generates noise. For state-sponsored actors routing through domestic European infrastructure, it provides no meaningful barrier. Know what it’s doing and what it isn’t.
Edge device behaviour needs baselining, not just perimeter monitoring. The advisory’s recommendation is to map and baseline normal traffic patterns from VPN endpoints and remote access infrastructure, then watch for anomalies. For OT operators with distributed field sites (energy, utilities, transport), this extends to the industrial networking hardware connecting those sites to operational networks. Devices like Siemens RUGGEDCOM sit precisely at this boundary. What’s normal outbound traffic for a substation router?
Some of your own devices are the problem. The covert networks are built from end-of-life SOHO routers and IoT equipment with default credentials or known unpatched vulnerabilities. If your organisation has that hardware on internet-facing segments, it’s a recruitment candidate for Chinese relay infrastructure. This isn’t a theoretical risk. Patching end-of-life devices often isn’t feasible, which means replacing them isn’t a capital expenditure request; it’s a security remediation.
What the advisory cadence is telling you
This is the third major public document from Five Eyes and allied partners on Chinese pre-positioning in critical infrastructure since 2023. The progression runs from advisories on specific Volt Typhoon techniques, to CISA emergency directives on actively exploited vulnerabilities, to this advisory describing the broader infrastructure methodology used across multiple actors.
Intelligence communities don’t publish technically detailed twelve-nation joint advisories unless they’ve concluded the threat picture requires broad public awareness rather than quiet bilateral notifications to affected operators. The cadence implies they’ve reached a threshold.
For those briefing boards: the framing matters. These aren’t collection operations against data. The consensus assessment of Volt Typhoon’s purpose is pre-positioning: ensuring that options exist to cause disruption to Western critical infrastructure at a moment of geopolitical escalation. Not operational now. Positioned for later.
That’s a different risk management problem than the one on most board agendas. The threat isn’t a breach you detect and remediate. It’s latent capability, already in place, waiting for a decision to be made elsewhere.
The joint advisory AA26-113A is available in full from CISA and the NCSC.