Back to Feed
IoT/OTJun 22, 2026

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

Canada's CSIS used first court-ordered warrant to remotely disinfect botnet-infected IoT devices and routers from

Summary

Canada's Security Intelligence Service obtained a Federal Court warrant to remotely access and neutralize two foreign-operated botnets running on Canadian servers, routers, and IoT devices including Ring doorbells and security cameras. This marks the first use of CSIS's threat reduction warrant powers for such an operation, comparable to FBI botnet cleanup operations against Volt Typhoon and APT28 in late 2023. The court found the foreign threat imminent and the measures necessary to protect critical infrastructure targets including the energy sector.

Full text

Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices Swati KhandelwalJun 22, 2026Cyber Espionage / IoT Security Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way. The warrant let CSIS alter, degrade, and destroy botnet data on the infected machines and cut the devices loose from the networks. The targets were Canada-based servers, small office and home office (SOHO) routers, and Internet of Things devices: Ring doorbells, security cameras, TVs, and other Wi-Fi-enabled appliances. Justice Catherine Kane granted the warrant on May 1, 2024, renewed it that August, and issued the confidential reasons in February 2026. The warrant stayed out of public view for more than two years, until this month's redacted release. CSIS needed the order because the cleanup would likely have been a crime without it. Reaching into someone else's device and wiping data is computer mischief under the Criminal Code, so the Service needed a judge's sign-off before touching the machines. The court found the threat to Canada clearly established and imminent, and the measures necessary, reasonable, and proportional. It stressed the operation went after devices, not people: no user identities sought, no content intercepted, any personal data swept up incidentally destroyed. The two botnets ran the standard relay playbook. A command tier issued the orders; a layer of infected devices relayed the traffic. By routing through hijacked Canadian hardware, a foreign state can look like an ordinary connection, a home worker, or an ISP customer, while it probes critical infrastructure, government, and military networks. The owner of the infected doorbell gets left looking responsible for traffic they never sent. The court flagged the energy sector among the targets and warned that the adversaries could direct the botnets to probe and potentially disrupt Canadian infrastructure. The public ruling settles the what: two foreign adversaries, a threat to Canada's security, the court found clearly made out. What it strips is the who. The timing and the technique match a specific moment in early 2024, but The Bureau, which surfaced the ruling, says it cannot tell from the redacted reasons whether Canada's two botnets were both Chinese, both Russian, or one of each. The foreign-state hand is a finding. The flag is the redaction. Same Tactic, a Different Authority That moment was a run of court-ordered botnet cleanups in the United States. In a December 2023 operation, the FBI used the botnet's own command channel to delete the KV-botnet malware from hundreds of U.S. SOHO routers, mostly end-of-life Cisco and NetGear boxes that the China-linked Volt Typhoon was using to hide access it had planted ahead of a possible crisis inside American communications, energy, water, and transportation systems. Weeks later, it ran a near-identical operation against a separate network of Ubiquiti routers that Russia's GRU, the APT28 group, had turned into an espionage relay. Canada's cyber centre had joined the allied warnings about state actors abusing SOHO and IoT gear. Same court-ordered shape both times: neglected consumer gear, a state operator, a judge signing off on remote disinfection. The difference is who holds the warrant. The U.S. operations were law enforcement, FBI, and DOJ acting under search-and-seizure authority. Canada's is an intelligence service using threat reduction measures, the CSIS's power to actively disrupt a threat rather than just collect intelligence on it, written into the CSIS Act years ago and reworked in the National Security Act, 2017, which took effect in 2019. CSIS had never reached for it like this until now. It Still Comes Down to Old Routers The lesson for defenders is the boring one. The botnets feed on the gear nobody maintains: end-of-life routers still wired into the network, IoT kits that never took their last firmware update, anything sitting on default credentials with a management panel facing the internet. A government cleanup does not touch that. In the U.S. operations, the malware came off, but the weaknesses stayed, and a reboot or factory reset could undo the fix and reopen the door to reinfection. Retiring the dead hardware and locking down what stays is on the owner, not the agency that cleaned up after them. One loose end the public ruling does not close: the application, by The Bureau's account, leaned on IP addresses CSIS had collected without a warrant, weeks after the Supreme Court of Canada held in R. v. Bykovets that an IP address carries a reasonable expectation of privacy. Whether that squares with CSIS's collection authorities, and whether the owners of the disinfected devices were ever told, stay open. Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  APT28, botnet, critical infrastructure, CSIS, cyber espionage, iot security, SOHO Router, Volt Typhoon ⚡ Top Stories This Week Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild - Patch Now Researchers Build Self-Replicating AI Worm That Operates Entirely on Local, Open-Weight Models Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows Anthropic Releases Claude Fable 5, Its Most Powerful AI Yet, With Cyber Safeguards Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities Cybersecurity Stars Awards 2026: Winners Announced Across 95 Categories ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories New GreatXML Exploit Bypasses Windows BitLocker via Recovery Partition XML Files Agentjacking Attack Tricks AI Coding Agents Into Running Malicious Code China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More ⭐ Featured Resources Get the 2026 Guide to Govern and Secure Enterprise AI Agents at Scale [Watch Demo] See Which Security Gaps Attackers Could Exploit First AI Can’t Stop Every Attack. Learn How Zero Trust Can Block What’s Unknown Have You Outgrown Your MDR? 7 Warning Signs Every CISO Should Check

Indicators of Compromise

  • malware — KV-botnet

Entities

Canadian Security Intelligence Service (CSIS) (vendor)Volt Typhoon (threat_actor)APT28 (threat_actor)Ring doorbell (product)Cisco routers (product)NetGear routers (product)