Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ORB Networks Leverages Compromised IoT Devices and SOHO Routers to Mask Cyberattacks

Operational Relay Box (ORB) networks represent a covert, mesh-based infrastructure utilized by advanced threat actors to obscure the true origins of their cyberattacks.

Operational Relay Box (ORB) networks represent a covert, mesh-based infrastructure utilized by advanced threat actors to obscure the true origins of their cyberattacks.

These networks are constructed using compromised Internet-of-Things (IoT) devices, Small Office/Home Office (SOHO) routers, and rented Virtual Private Servers (VPS). They function as private residential proxy systems, blending malicious traffic with legitimate user activity.

Within an ORB network, traffic is relayed across multiple nodes before reaching its target, with the majority of connections occurring between the relay boxes themselves. This setup enhances the anonymity of the attackers and complicates efforts to trace or block malicious traffic without inadvertently affecting legitimate users and businesses.

ORB networks demonstrate high resilience; if a node is exposed or blocked, it can be rapidly replaced by another compromised device, sustaining campaigns for extended periods.

Recent analysis by Team Cymru in Singapore's telecommunications sector revealed the operationalization of these networks. Using the Pure Signal Scout platform, Team Cymru identified up to 12 unique ORB-tagged IPs on major Singaporean ISPs over the last 90 days and up to 44 ORB-tagged IPs overall in the region during the same period.

They function as private residential proxy systems, blending malicious traffic with legitimate user activity.
Jonathan Pierce · Thehackingpost

Many ORB nodes were hosted on infrastructure belonging to cloud and hosting providers, such as AWS and Vultr, demonstrating how attackers integrate compromised SOHO routers with VPS-based relays. NetFlow-based telemetry indicated that 42 unique ORB IPs communicated with the four telcos in the last 30 days, while 62 unique IPs from these ISPs interacted with ORB nodes, primarily tagged as D-Link and Asus routers.

This ORB activity aligns with a broader espionage campaign by the Chinese-linked group UNC3886, which was disrupted in Singapore through Operation CYBER GUARDIAN, the country's largest multi-agency cyber operation to date.

The Cyber Security Agency of Singapore (CSA) and the Infocomm Media Development Authority (IMDA) reported that UNC3886 exploited a zero-day vulnerability to bypass perimeter firewalls at all four major telcos, accessing parts of their networks and exfiltrating limited technical data. Previously, Mandiant tied UNC3886 to custom TINYSHELL-based backdoors on Juniper routers and other edge devices, highlighting the group's focus on maintaining prolonged, stealthy access to telecom and critical infrastructure.

Advertisement

In response, Singapore has implemented stringent national countermeasures, emphasizing router and consumer device security. The Infocomm Media Development Authority’s TS RG-SEC specification mandates that residential gateways sold locally be "secure by default," including automatic security updates throughout the warranty period or until declared end of life. The CSA’s Cybersecurity Labelling Scheme (CLS) assigns a visible security "hygiene rating," requiring routers to have at least CLS Level 1 standards, including unique default passwords, a vulnerability disclosure policy, and ongoing software support before they can be sold.

However, a legacy gap persists, as millions of older or imported routers remain outside these protections, presenting a pool of devices vulnerable to being incorporated into ORB networks and repurposed for long-term espionage campaigns.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories