HomeSecurityCSIS: First botnet takedown warrant in Canada

CSIS: First botnet takedown warrant in Canada

The CSIS ) has used its threat reduction powers under the law for the first time, obtaining a court order to take down two botnets that were infecting devices in Canada. The Federal Court released the ruling on June 15, 2026, revealing an operation that had remained secret for more than two years. This is a landmark in the history of Canadian cybersecurity, as CSIS had never before exercised this power in such a way.

See also: Kimwolf Botnet: Its 23-year-old creator arrested

CSIS botnet neutralization of IoT devices Canada

The warrant was issued by Judge Catherine Kane on May 1, 2024 , after CSIS filed an application on April 24, 2024. The court found that the threat to Canada's security was " clearly established and imminent ." The warrant was renewed in August 2024, and confidential reasons were issued in February 2026. The operation involved servers within Canada, SOHO routers , as well as IoT devices such as Ring doorbells , security cameras, televisions, and other Wi-Fi- enabled devices .

The legal basis of the operation is particularly important. Without judicial authorization, accessing third-party devices and deleting data would constitute a criminal offence (“computer mischief”) under the Criminal Code of Canada. CSIS has threat reduction powers under the CSIS Act, as revised by the National Security Act of 2017 (effective 2019), which allow it to act against threats rather than simply collecting information. This was the first time CSIS has used this power for a botnet.

CSIS botnet: How the infrastructure of foreign adversaries operated

The two botnets operated in a typical command-and-control relay fashion. A command layer issued instructions, while a layer of infected devices relayed traffic. By routing communication through compromised Canadian hardware, a foreign state could pose as a simple home connection, telecommuter, or ISPwhile simultaneously scanning critical infrastructure, government, and military networks. The owner of an infected camera or doorbell would appear to be responsible for traffic it never generated.

The court specifically singled out the energy sector as a target and warned that adversaries could direct botnets to sabotage Canadian infrastructure. The public decision does not reveal the identities of the foreign actors, but the timing and technical method are consistent with assessments that likely implicate China or Russia or both. The court emphasized that the operation targeted devices, not individuals: no user identities were sought, no content was intercepted, and any personal data accidentally collected was destroyed.

See also: xlabs_v1 Botnet: ADB Exploit for DDoS Attacks on IoT

CSIS: First botnet takedown warrant in Canada

In a similar context, the US had led a series of court-authorized botnet. In December 2023, the FBI used the KV-botnet to remove malware from hundreds of US SOHO routers — mostly old Cisco and NetGear — that the Chinese Volt Typhoon was using to hide its access to communications, energy, water, and transportation networks. Shortly thereafter, the FBI conducted a similar operation against a network of Ubiquiti routers that the Russian GRU, specifically the APT28, had turned into a spying tool.

The multinational operation against the SocGholish botnet is also mentioned in the same timeframe , in which authorities from Europol , Canada , the US , Germany and the Netherlands seized 106 servers and domains , while Dutch police removed the backdoor from almost 15,000 WordPress sites . The trend is clear: governments are moving from passive attribution of responsibility to active botnet neutralization , through court-approved operations.

How to protect yourself from botnets exploiting IoT devices

The key lesson for defenders remains simple: botnets thrive on neglected, unmaintained equipment. Organizations and individuals should inventory all devices exposed to the internet — SOHO routers , cameras, IoT devices — and replace hardware that no longer receives security updates. Firmware and software updates should be done promptly, and default passwords should be changed to strong, unique credentials.

Additionally, segmenting IoT devices and guest networks away from critical business systems is recommended so that a compromised camera cannot be used as an entry point into internal infrastructure. Monitoring for botnet indications — unusual outbound traffic, unexplained DNS behavior , repeated connections to unknown proxy infrastructure — is critical. Finally, collaboration with ISPs , managed security providers, and national cybersecurity agencies is essential, as the CSIS case demonstrates that authorities have legal mechanisms in place to disrupt botnets at the network level.

See also: Masjesu Botnet: DDoS-for-Hire Service Targets IoT Devices

CSIS: First botnet takedown warrant in Canada

CSIS set an important precedent that is expected to influence how other countries — including European ones — will deal with similar threats in the future .

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS