Canada’s spy service, the Canadian Security Intelligence Service (CSIS), obtained a judge’s permission to remotely clean botnet-infected devices on Canadian soil, marking the first use of its threat reduction warrant powers. The Federal Court released a public version of the ruling on June 15, 2026, detailing the operation against two foreign-run botnets targeting Canada-based servers, SOHO routers, and IoT devices like Ring doorbells and security cameras.
Justice Catherine Kane granted the warrant on May 1, 2024, renewed it in August 2024, and issued confidential reasons in February 2026. The warrant remained secret for over two years. CSIS needed the order because cleaning devices without authorization would constitute computer mischief under the Criminal Code. The court found the threat to Canada clearly established and imminent, and the measures necessary, reasonable, and proportional.
The botnets used a standard relay playbook: a command tier issued orders, and infected devices relayed traffic, allowing foreign states to mask their activities as ordinary connections. The court flagged the energy sector among targets and warned of potential disruption to Canadian infrastructure. The public ruling confirms two foreign adversaries but redacts their identities, leaving speculation about Chinese or Russian involvement.
Similar operations occurred in the U.S. in late 2023 and early 2024, where the FBI used court orders to clean botnets linked to China’s Volt Typhoon and Russia’s APT28. However, Canada’s operation is distinct as it involves an intelligence service using threat reduction measures rather than law enforcement search-and-seizure authority.
The article emphasizes that botnets exploit unmaintained devices like end-of-life routers and IoT gear with default credentials. Government cleanups remove malware but do not fix underlying vulnerabilities, leaving devices susceptible to reinfection. The ruling also raises questions about CSIS’s collection of IP addresses without a warrant, following the Supreme Court of Canada’s decision in R. v. Bykovets that IP addresses carry a reasonable expectation of privacy.
CVEs: CVE-2026-11645
Attack groups: APT28, Volt Typhoon
Malware: KV-botnet
Companies: CSIS, FBI, Cisco, NetGear, Ubiquiti, Ring
Products: Ring doorbell, Cisco router, NetGear router, Ubiquiti router
Original source: thehackernews.com