HackMyIP
← Back to News
2026-06-22 The Hacker News

CSIS Uses First Threat-Reduction Warrant to Clean Canadian Botnet Devices

MalwareRegulationAPT

Canada's Security Intelligence Service (CSIS) executed a first-of-its-kind threat reduction warrant to neutralize two foreign-run botnets operating from infected servers, SOHO routers, and Internet of Things devices inside Canadian borders. Justice Catherine Kane of the Federal Court granted the warrant on May 1, 2024, renewed it in August, and issued confidential reasons in February 2026. The redacted public version, released June 15, authorized CSIS to alter, degrade, and destroy botnet data on the compromised machines and sever their connection to adversary command infrastructure. Without judicial authorization, the operation would have constituted computer mischief under Canada's Criminal Code, since wiping data on third-party devices crosses a legal line even when done in the public interest.

The targets were Canada-based servers and consumer-grade hardware including Ring doorbells, security cameras, smart TVs, and Wi-Fi-enabled appliances. The court found the threat to Canada clearly established and imminent, emphasizing that the operation targeted devices rather than people: no user identities were sought, no communications were intercepted, and any personal data incidentally swept up was destroyed. Investigators noted the botnets followed a standard relay architecture, routing traffic through hijacked Canadian hardware so that a foreign state could masquerade as an ordinary residential connection while probing critical infrastructure, government, and military networks. The court specifically flagged the energy sector as a target, warning that the adversaries could redirect the botnets to disrupt Canadian services. Network administrators worried about similar exposure can audit their own gateway devices with a port scanner or run a DNS leak test to detect traffic being silently relayed through their network.

The timing and tradecraft closely parallel the December 2023 FBI operation that used a botnet's own command channel to purge KV-botnet malware from hundreds of U.S. SOHO routers, predominantly end-of-life Cisco and NetGear hardware exploited by the China-linked Volt Typhoon group. According to The Bureau, which surfaced the Canadian ruling, the redacted reasons do not specify whether both botnets were Chinese, both Russian, or split between the two. The finding that a foreign state was behind the operations is explicit; the identities are blacked out. Security researchers tracking similar infrastructure can pivot on adversary command servers using a WHOIS lookup to trace registration patterns and ownership clusters linked to known state-sponsored activity.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

IP Lookup →IP Blacklist Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a DDoS attack? →What is a proxy server? →Is my IP blacklisted? →