VORANT. Threat Intelligence Sign in Get the full feed

IPA Warns of Router ORB Botnet Attacks

medium vulnerability infrastructuretelecommunications

Japan's IPA warns that flaws and misconfigurations in home and IoT routers are being exploited to hijack devices into ORB relay networks used for DDoS and covert intrusion.

The Information-technology Promotion Agency (IPA) of Japan issued an advisory warning about ongoing exploitation of vulnerabilities and misconfigurations in home and IoT network routers. Attackers are compromising these devices to convert them into Operational Relay Boxes (ORBs), which serve as relay points to disguise the origin of further attacks against third parties. The advisory notes an increase in reconnaissance activity preceding these intrusions and references prior warnings from Western government agencies about botnets composed of compromised routers being used for DDoS attacks and as persistent footholds for internal reconnaissance and follow-on compromise.

IPA highlights that such 'network-penetrating attacks' can result in organizations unwittingly participating in attacks against others, sustained intrusion footholds enabling deeper compromise during crises, and reputational or legal fallout. The agency recommends standard hardening measures: replacing default/weak passwords, promptly applying vendor patches, retiring unsupported end-of-life devices, disabling exposed management interfaces and unnecessary services/ports, and periodically rebooting devices to clear memory-resident malicious processes.

This is a general awareness advisory rather than a report tied to a specific new vulnerability, campaign, or threat actor. It reflects a broader, ongoing trend of router and IoT device compromise for use in relay botnets and DDoS infrastructure, consistent with prior joint advisories from international government agencies on this threat category.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251031_router.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free