ORB Networks Leverages Compromised IoT Devices and SOHO Routers to Mask Cyberattacks
Operational Relay Box (ORB) networks represent a covert, mesh-based infrastructure utilized by advanced threat actors to obscure the true origins of their cyberattacks.
Operational Relay Box (ORB) networks represent a covert, mesh-based infrastructure utilized by advanced threat actors to obscure the true origins of their cyberattacks.
These networks are constructed using compromised Internet-of-Things (IoT) devices, Small Office/Home Office (SOHO) routers, and rented Virtual Private Servers (VPS). They function as private residential proxy systems, blending malicious traffic with legitimate user activity.
Within an ORB network, traffic is relayed across multiple nodes before reaching its target, with the majority of connections occurring between the relay boxes themselves. This setup enhances the anonymity of the attackers and complicates efforts to trace or block malicious traffic without inadvertently affecting legitimate users and businesses.
ORB networks demonstrate high resilience; if a node is exposed or blocked, it can be rapidly replaced by another compromised device, sustaining campaigns for extended periods.
Recent analysis by Team Cymru in Singapore's telecommunications sector revealed the operationalization of these networks. Using the Pure Signal Scout platform, Team Cymru identified up to 12 unique ORB-tagged IPs on major Singaporean ISPs over the last 90 days and up to 44 ORB-tagged IPs overall in the region during the same period.
They function as private residential proxy systems, blending malicious traffic with legitimate user activity.
Many ORB nodes were hosted on infrastructure belonging to cloud and hosting providers, such as AWS and Vultr, demonstrating how attackers integrate compromised SOHO routers with VPS-based relays. NetFlow-based telemetry indicated that 42 unique ORB IPs communicated with the four telcos in the last 30 days, while 62 unique IPs from these ISPs interacted with ORB nodes, primarily tagged as D-Link and Asus routers.
This ORB activity aligns with a broader espionage campaign by the Chinese-linked group UNC3886, which was disrupted in Singapore through Operation CYBER GUARDIAN, the country's largest multi-agency cyber operation to date.
The Cyber Security Agency of Singapore (CSA) and the Infocomm Media Development Authority (IMDA) reported that UNC3886 exploited a zero-day vulnerability to bypass perimeter firewalls at all four major telcos, accessing parts of their networks and exfiltrating limited technical data. Previously, Mandiant tied UNC3886 to custom TINYSHELL-based backdoors on Juniper routers and other edge devices, highlighting the group's focus on maintaining prolonged, stealthy access to telecom and critical infrastructure.
In response, Singapore has implemented stringent national countermeasures, emphasizing router and consumer device security. The Infocomm Media Development Authority’s TS RG-SEC specification mandates that residential gateways sold locally be "secure by default," including automatic security updates throughout the warranty period or until declared end of life. The CSA’s Cybersecurity Labelling Scheme (CLS) assigns a visible security "hygiene rating," requiring routers to have at least CLS Level 1 standards, including unique default passwords, a vulnerability disclosure policy, and ongoing software support before they can be sold.
However, a legacy gap persists, as millions of older or imported routers remain outside these protections, presenting a pool of devices vulnerable to being incorporated into ORB networks and repurposed for long-term espionage campaigns.
Based on reporting by GBHackers.
