Project ORBITAL is a useful reminder that edge devices are no longer just “network gear.” In modern espionage operations, compromised SOHO routers, VPN appliances, firewalls, and IoT devices are increasingly functioning as relay infrastructure that lets threat actors hide in normal-looking regional traffic.
BushidoToken’s Project ORBITAL — short for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon — aggregates public reporting on Operational Relay Box (ORB) networks used heavily by China-nexus threat actors. The project maps ORB infrastructure, targeted devices, adversary overlaps, malware components, exploit usage, fingerprints, and takedowns into a structured OSINT resource defenders can use for hunting and exposure review.
Read the original research here: Project ORBITAL by @BushidoToken. The companion repository is also available on GitHub: BushidoUK/Project-ORBITAL.
What Project ORBITAL Highlights
The key finding is not simply that attackers compromise routers. Defenders already know that. The more important point is that relay-box infrastructure has become an operational layer for advanced threat actors. Instead of reaching targets from obvious command-and-control servers, adversaries route activity through chains of compromised edge devices to make traffic look local, residential, or otherwise low-risk.
Project ORBITAL pulls together public reporting from major research teams and government sources to show how these networks connect to named activity clusters, device families, exploits, and malware. The project also points to a practical reality: ORB usage is not limited to one narrow mission set. Espionage-focused groups, intellectual-property theft operators, and critical-infrastructure pre-positioning actors have all adopted relay networks as standard tradecraft.
Why This Matters for SMBs and Gov Contractors
Small businesses and government contractors often treat edge equipment as “set and forget” infrastructure. That is exactly what makes it valuable to adversaries. A forgotten router, unmanaged VPN appliance, old camera gateway, or exposed remote-management interface can become part of someone else’s attack infrastructure even if the organization itself is not the final target.
That creates three business risks. First, compromised infrastructure can be abused as a relay for espionage, phishing, credential theft, scanning, or intrusion attempts against third parties. Second, the same exposure that lets an actor conscript a device can become an initial access path into the internal network. Third, for contractors handling sensitive work, suspicious traffic from owned infrastructure can create reputational, compliance, and incident-response headaches even when the compromise began with neglected hardware.
Defensive Takeaways
- Inventory every edge device. Include routers, firewalls, VPN appliances, modems, wireless controllers, NAS devices, cameras, NVRs, and remote-management gateways.
- Replace end-of-life hardware. If a vendor no longer ships security fixes, compensating controls are temporary. Treat replacement as risk reduction, not an IT refresh luxury.
- Remove direct internet exposure where possible. Management interfaces should not be reachable from the public internet. Use VPN, allowlisting, or private management paths.
- Patch edge gear with the same urgency as servers. ORB operators thrive on old firmware and exposed services. Make network appliances part of the vulnerability-management cycle.
- Hunt for abnormal egress. Look for unexpected outbound connections from routers, firewalls, and appliances, especially to VPS providers, unfamiliar residential networks, or unusual geographic destinations.
- Preserve logs centrally. Many edge devices have limited local logging. Forward logs to a SIEM or syslog collector before an attacker can erase the short-lived local record.
- Review procurement standards. Cheap unmanaged devices often become expensive incident-response problems. Buy equipment with clear patch lifecycles, MFA-capable management, logging, and vendor security advisories.
Bulwark Black Assessment
Project ORBITAL is valuable because it reframes ORB networks as an ecosystem rather than a collection of isolated router compromises. For defenders, that means edge-device security needs to move from the “network closet” into the broader threat-intelligence and risk-management conversation.
The practical move is straightforward: know what sits at the edge, know whether it is still supported, know what is exposed, and know what traffic it produces. Organizations that cannot answer those four questions are leaving blind spots that modern APT operators are already built to exploit.