Allied Intelligence — 2026-06-22

Canada CSIS Uses First-of-Its-Kind Threat Reduction Warrant to Neutralize Foreign-Run Botnets on Canadian Soil

BLUFCanada's tested judicial framework for domestic botnet remediation gives Five Eyes partners a ready-made legal template as allied services pursue similar network-level authorities.

On June 15, the Federal Court of Canada released public reasons for a cyber threat reduction measures warrant it issued to CSIS on May 1, 2024, the first ever under the CSIS Act 12. Justice Catherine Kane authorized CSIS to disinfect Canada-based servers, SOHO routers, and IoT devices compromised by two unnamed foreign adversaries, finding the threat clearly established and imminent 1. The court renewed the warrant August 29, 2024 for a second 120-day period, noting measures targeted devices only and collected no personal information 1. Risky Business Media reported the botnet was being used to "advance their financial, political, ideological and economic interests," with the threat actor's identity redacted from the ruling and disinfection status unconfirmed 3.

Analysis
The Federal Court's public release of its May 2024 TRM warrant establishes a tested judicial framework for domestic active cyber-remediation that allied services lacking equivalent statutory authority will benchmark against. Both adversary identities remain redacted and disinfection status unconfirmed across coverage derived entirely from the court filing, constraining confidence on both points. Simultaneous Dutch-US botnet interdiction signals a coordinated Western shift toward network-level remediation, elevating the CSIS framework's reference value for allied services. The two named adversaries may represent a single state actor operating through segmented infrastructure clusters, which would narrow the attribution picture but complicate remediation coordination.
4 sources
  1. File C-6-24 - Federal Court - Federal Court of Canada
  2. Canadas Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices - The Hacker News
  3. Risky Bulletin: Canada's spy agency allowed to remove a botnet from Canadian devices - Risky Business Media
  4. Federal Court discloses first decision on cyber 'threat reduction measures' in malware botnet case - Law360 Canada

View in full brief →

UNCLASSIFIED // OPEN SOURCE