A Spy Agency Just Cleaned Your Neighbour's Router. The Bots Will Be Back.

Canada's CSIS used a first-of-its-kind threat reduction warrant to access and shut down two foreign botnets running on infected Canadian home routers and IoT devices, and here is what it means for anyone defending a product.

Canada's Security Intelligence Service went to the Federal Court, got a warrant, and reached into infected home routers and IoT devices sitting in Canadian living rooms to evict two foreign-run botnets. The public version of the ruling landed on June 15, 2026, and it is the first time CSIS has used its authority for anything like this.
Botnets on consumer hardware have been ordinary for a decade, and so has the fact that nobody owns the problem. What's new is the warrant: an intelligence service treating the cleanup of privately owned, compromised devices as a national security operation that a judge has to sign.
Operation Scope
2
foreign-operated botnets neutralized on Canadian devices

The router under the TV is now infrastructure

The security industry has quietly accepted for years that the long tail of compromised home routers, IP cameras and DVRs is effectively unowned. The manufacturer shipped it and moved on, the ISP doesn't want the liability, and the owner has no idea the thing was ever breached, let alone how to fix it. So it sits there, enrolled in someone else's army.
A built on that hardware is cheap and hard to kill. The machines have real residential IP addresses, which is the entire reason they are worth stealing. Traffic from a hijacked home connection in Toronto looks like a person, and it sails through the reputation checks that would flag a datacenter IP on sight.
When a government decides that cleaning those devices is worth a court fight, it has conceded that the consumer device layer is national infrastructure with no defender. Vendors and owners structurally cannot do it, so the state did.

A judge had to sign off on removing malware

Reaching into a device you don't own is an intrusion even when all you remove is malware. CSIS could not log into thousands of Canadian routers on the strength of a good cause. It needed judicial authorization, and releasing the ruling publicly puts this kind of operation on the record where it can be bounded and argued with.
The same technical capability that lets a defender clean a device lets whoever holds it reconfigure that device, surveil through it, or brick it. Oversight draws that line, not the code. A warrant is how a democracy says it will touch private property to reduce a threat, with a judge seeing why.
Legal Precedent
First
use of a CSIS threat reduction warrant for botnet cleanup
The way we see it, the precedent cuts both ways. It legitimises active defense at national scale, which can dent the supply of abusable residential devices. It also normalises authorities operating inside endpoints they don't own, and that deserves exactly the public ruling and the public debate it is now getting.

A cleaned router is a re-infectable router

Even a flawless takedown only removes the malware. Default credentials, dead firmware, exposed management interfaces, hardware that will never see another patch: all of it is still there the morning after. Botnet operators rebuild. They always rebuild, which rules out filing any of this under "the government will handle it."
They rebuild out of the same pool of devices that hits your login page, your signup flow and your checkout. Those are the residential proxies behind credential stuffing and fake account creation, and the address on the request belongs to a real household in a quiet suburb.
You can't block a residential ISP range without blocking customers, and the bots know it. IP reputation alone was always going to lose that race, and an operation at this scale is the clearest evidence yet of why.

Judge the session, not the address

So the decision has to move off the network layer and onto behaviour. Does this session act like a human filling a form, or like a script replaying one? Is the timing, the interaction pattern and the device signal consistent with a person, whatever the IP claims to be? Those questions survive a clean residential address.
That is the bet behind how we build TrustSig: assume the IP is lying, assume the device might be borrowed, and decide on what the traffic actually does. A government can clean two botnets. It can't clean the next two before they form, which is why the protection that holds is the one that never depended on the source looking suspicious. Build as if every request comes from a compromised home, because plenty of them already do.

This article is based on reporting by The Hacker News. Read the original for the full story.