# IPA Warns of Router ORB Botnet Attacks

Published: 2025-10-30 · Severity: medium · Sectors: infrastructure, telecommunications
Canonical: https://vorant.io/reports/e583b948-47cc-59d2-8bb8-5d40c8d3d142/ipa-warns-of-router-orb-botnet-attacks

> Japan's IPA warns that flaws and misconfigurations in home and IoT routers are being exploited to hijack devices into ORB relay networks used for DDoS and covert intrusion.

The Information-technology Promotion Agency (IPA) of Japan issued an advisory warning about ongoing exploitation of vulnerabilities and misconfigurations in home and IoT network routers. Attackers are compromising these devices to convert them into Operational Relay Boxes (ORBs), which serve as relay points to disguise the origin of further attacks against third parties. The advisory notes an increase in reconnaissance activity preceding these intrusions and references prior warnings from Western government agencies about botnets composed of compromised routers being used for DDoS attacks and as persistent footholds for internal reconnaissance and follow-on compromise.

IPA highlights that such 'network-penetrating attacks' can result in organizations unwittingly participating in attacks against others, sustained intrusion footholds enabling deeper compromise during crises, and reputational or legal fallout. The agency recommends standard hardening measures: replacing default/weak passwords, promptly applying vendor patches, retiring unsupported end-of-life devices, disabling exposed management interfaces and unnecessary services/ports, and periodically rebooting devices to clear memory-resident malicious processes.

This is a general awareness advisory rather than a report tied to a specific new vulnerability, campaign, or threat actor. It reflects a broader, ongoing trend of router and IoT device compromise for use in relay botnets and DDoS infrastructure, consistent with prior joint advisories from international government agencies on this threat category.

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20251031_router.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e583b948-47cc-59d2-8bb8-5d40c8d3d142/ipa-warns-of-router-orb-botnet-attacks.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
