#botnet — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #botnet, aggregated by home.social.
-
Dysphoria Botnet Campaign Targeting IoT Devices for DDoS Attacks
Pulse ID: 6a7f750c25e71ea88a305576
Pulse Link: https://otx.alienvault.com/pulse/6a7f750c25e71ea88a305576
Pulse Author: cryptocti
Created: 2026-08-14 20:05:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DDoS #DoS #InfoSec #IoT #OTX #OpenThreatExchange #bot #botnet #cryptocti
-
Dysphoria Botnet Campaign Targeting IoT Devices for DDoS Attacks
Pulse ID: 6a7f750c25e71ea88a305576
Pulse Link: https://otx.alienvault.com/pulse/6a7f750c25e71ea88a305576
Pulse Author: cryptocti
Created: 2026-08-14 20:05:32Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DDoS #DoS #InfoSec #IoT #OTX #OpenThreatExchange #bot #botnet #cryptocti
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Multi-Functional Linux Botnet "Evooo1Bot"
A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.
Pulse ID: 6a7e2be6ba37cc87ae552659
Pulse Link: https://otx.alienvault.com/pulse/6a7e2be6ba37cc87ae552659
Pulse Author: AlienVault
Created: 2026-08-13 20:41:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault
-
Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Pulse ID: 6a7eca0c254771760ee44515
Pulse Link: https://otx.alienvault.com/pulse/6a7eca0c254771760ee44515
Pulse Author: CyberHunter_NL
Created: 2026-08-14 07:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
Pulse ID: 6a7eca0c254771760ee44515
Pulse Link: https://otx.alienvault.com/pulse/6a7eca0c254771760ee44515
Pulse Author: CyberHunter_NL
Created: 2026-08-14 07:55:56Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
New.
Fortinet: Multi-Functional Linux Botnet “Evooo1Bot” https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot @fortinet #infosec #threatresearch #botnet #malware
-
New.
Fortinet: Multi-Functional Linux Botnet “Evooo1Bot” https://www.fortinet.com/blog/threat-research/multi-functional-linux-botnet-evooo1bot @fortinet #infosec #threatresearch #botnet #malware
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7da2b72179e3a4cb0c1d31
Pulse Link: https://otx.alienvault.com/pulse/6a7da2b72179e3a4cb0c1d31
Pulse Author: CyberHunter_NL
Created: 2026-08-13 10:55:51Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
"Smart" cars are just rolling, unpatched IoT botnets. The OEM drops OTA updates after year 3, but the rustbucket keeps driving for 15 years and more. Millions of them.
Does anyone actually know how this works? -
StealC C2 domains dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️
🌐 cloud-flare-authenticator .link
🌐 cloud-flare-authenticator .click
🌐 update-microsoft-data .services
📡 89.34.90.45:443OverlordRAT #botnet C2 server ⤵️
🌐 download-windows-update .live
📡 151.243.113.94:5173Both hosted at AS207043 DEDIK-IO in Germany🇩🇪
📄 Malware sample:
https://bazaar.abuse.ch/sample/5c61c977440dd7e870c1a63037558dd3fc2c41c8fd9d6ab67acff1c7d35abe01/🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.stealc/
https://threatfox.abuse.ch/browse/tag/OverlordRAT/ -
StealC C2 domains dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️
🌐 cloud-flare-authenticator .link
🌐 cloud-flare-authenticator .click
🌐 update-microsoft-data .services
📡 89.34.90.45:443OverlordRAT #botnet C2 server ⤵️
🌐 download-windows-update .live
📡 151.243.113.94:5173Both hosted at AS207043 DEDIK-IO in Germany🇩🇪
📄 Malware sample:
https://bazaar.abuse.ch/sample/5c61c977440dd7e870c1a63037558dd3fc2c41c8fd9d6ab67acff1c7d35abe01/🦊 IOCs on ThreatFox:
https://threatfox.abuse.ch/browse/malware/win.stealc/
https://threatfox.abuse.ch/browse/tag/OverlordRAT/ -
An Evolution of the Botnet
Pulse ID: 6a7bf8a320deffc5bdc1c33a
Pulse Link: https://otx.alienvault.com/pulse/6a7bf8a320deffc5bdc1c33a
Pulse Author: Tr1sa111
Created: 2026-08-12 04:37:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
-
An Evolution of the Botnet
Pulse ID: 6a7bf8a320deffc5bdc1c33a
Pulse Link: https://otx.alienvault.com/pulse/6a7bf8a320deffc5bdc1c33a
Pulse Author: Tr1sa111
Created: 2026-08-12 04:37:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
-
An Evolution of the Botnet
Pulse ID: 6a7bf8f57f942af8b9b49faa
Pulse Link: https://otx.alienvault.com/pulse/6a7bf8f57f942af8b9b49faa
Pulse Author: Tr1sa111
Created: 2026-08-12 04:39:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
-
An Evolution of the Botnet
Pulse ID: 6a7bf8f57f942af8b9b49faa
Pulse Link: https://otx.alienvault.com/pulse/6a7bf8f57f942af8b9b49faa
Pulse Author: Tr1sa111
Created: 2026-08-12 04:39:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
-
📰 TuxBot v3: New IoT Botnet Framework Developed with LLM Assistance
Unit 42 details TuxBot v3, a new modular IoT botnet framework. Developed with LLM assistance, it features Telnet brute-forcing, DDoS capabilities, and C2 fallbacks via DGA & Pastebin. Shows evolution of AI in malware creation. #TuxBot #IoT #Botnet #M...
-
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7b8c7ac9f862e53382eab9
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c7ac9f862e53382eab9
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
Indicators extracted from public reporting. Source: https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/
Pulse ID: 6a7b8c7ac9f862e53382eab9
Pulse Link: https://otx.alienvault.com/pulse/6a7b8c7ac9f862e53382eab9
Pulse Author: CyberHunter_NL
Created: 2026-08-11 20:56:26Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
An Evolution of the Botnet
A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.
Pulse ID: 6a7b3ea11dca2e714d4bff8d
Pulse Link: https://otx.alienvault.com/pulse/6a7b3ea11dca2e714d4bff8d
Pulse Author: AlienVault
Created: 2026-08-11 15:24:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault
-
Kimwolf v7: An Evolution of the Kimwolf Botnet
Indicators extracted from public reporting. Source: https://mastodon.social/share?text=Kimwolf%20v7:%20An%20Evolution%20of%20the%20Kimwolf%20Botnet%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimwolf-v7-botnet-malware%2F
Pulse ID: 6a7affd02bfe3b8250af6b91
Pulse Link: https://otx.alienvault.com/pulse/6a7affd02bfe3b8250af6b91
Pulse Author: CyberHunter_NL
Created: 2026-08-11 10:56:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Kimwolf v7: An Evolution of the Kimwolf Botnet
Indicators extracted from public reporting. Source: https://mastodon.social/share?text=Kimwolf%20v7:%20An%20Evolution%20of%20the%20Kimwolf%20Botnet%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fkimwolf-v7-botnet-malware%2F
Pulse ID: 6a7affd02bfe3b8250af6b91
Pulse Link: https://otx.alienvault.com/pulse/6a7affd02bfe3b8250af6b91
Pulse Author: CyberHunter_NL
Created: 2026-08-11 10:56:16Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications
Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.
Pulse ID: 6a7a8be76fe0dfa36d01afa0
Pulse Link: https://otx.alienvault.com/pulse/6a7a8be76fe0dfa36d01afa0
Pulse Author: AlienVault
Created: 2026-08-11 02:41:43Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault
-
Google and FBI dismantle NetNut proxy botnet that hijacked 2 million smart devices
Stay curious — follow @1ban_news.
-
Google and FBI dismantle NetNut proxy botnet that hijacked 2 million smart devices
Stay curious — follow @1ban_news.
-
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands
Indicators extracted from public reporting. Source: https://isc.sans.edu/diary/Botnet+Hunting+for+Vulnerabilities+in+Diagnostic+Tools/33214
Pulse ID: 6a72de857045761cca5a65b5
Pulse Link: https://otx.alienvault.com/pulse/6a72de857045761cca5a65b5
Pulse Author: CyberHunter_NL
Created: 2026-08-05 06:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands
Indicators extracted from public reporting. Source: https://isc.sans.edu/diary/Botnet+Hunting+for+Vulnerabilities+in+Diagnostic+Tools/33214
Pulse ID: 6a72de857045761cca5a65b5
Pulse Link: https://otx.alienvault.com/pulse/6a72de857045761cca5a65b5
Pulse Author: CyberHunter_NL
Created: 2026-08-05 06:56:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
Almost Half of Malware Samples Communicate Direct to IP
Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.
Pulse ID: 6a71e43a0127c62218b7c365
Pulse Link: https://otx.alienvault.com/pulse/6a71e43a0127c62218b7c365
Pulse Author: AlienVault
Created: 2026-08-04 13:08:10Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault
-
Interisle's malware analyses for the April – June 2026 reporting period are now available at the Cybercrime Information Center.
There, you can find rankings of the Top-level Domains (TLDs), Domain Registrars, and Hosting operators (by ASN) with the most malware activity.
We also post aggregate records of all operators that met our minimum criteria for malware reported in CSV format at the Cybercrime Information Center’s records repository.
https://interisle.substack.com/p/malware-trends-april-june-2026
#malware #cybercrime #cybersecurity #botnet #endpointmalware #attackware #iotmalware
-
Interisle's malware analyses for the April – June 2026 reporting period are now available at the Cybercrime Information Center.
There, you can find rankings of the Top-level Domains (TLDs), Domain Registrars, and Hosting operators (by ASN) with the most malware activity.
We also post aggregate records of all operators that met our minimum criteria for malware reported in CSV format at the Cybercrime Information Center’s records repository.
https://interisle.substack.com/p/malware-trends-april-june-2026
#malware #cybercrime #cybersecurity #botnet #endpointmalware #attackware #iotmalware
-
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria
Pulse ID: 6a6ad695edc161364e89824d
Pulse Link: https://otx.alienvault.com/pulse/6a6ad695edc161364e89824d
Pulse Author: Tr1sa111
Created: 2026-07-30 04:44:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
-
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria
Pulse ID: 6a6ad695edc161364e89824d
Pulse Link: https://otx.alienvault.com/pulse/6a6ad695edc161364e89824d
Pulse Author: Tr1sa111
Created: 2026-07-30 04:44:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111
-
"Eine neue Botnetz-Malware namens Tengu hat es auf Linux-Systeme abgesehen. Sie schaltet die Konkurrenz aus und weiß sich selbst zu wehren."
-
"Eine neue Botnetz-Malware namens Tengu hat es auf Linux-Systeme abgesehen. Sie schaltet die Konkurrenz aus und weiß sich selbst zu wehren."
-
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria
Since Q1 2026, an emerging botnet named Dysphoria has amassed over 200,000 compromised hosts through rapid technical iterations spanning jackskid and fbot variants. The botnet employs sophisticated blockchain-based command and control infrastructure using ENS and SNS domains, combined with a novel architecture that converts victim hosts into relay/proxy nodes. Dysphoria propagates primarily through Telnet/SSH credential brute-forcing and exploitation of IoT vulnerabilities. Its commercial operation offers tiered DDoS attack packages claiming up to 4 Tbps capacity, targeting victims globally across multiple industries. The botnet demonstrates advanced evasion techniques including modified RC4 encryption, UPnP NAT traversal, and dynamic C2 resolution mechanisms. Daily monitoring shows peak activity of 239,000 overseas bots and 1,801 domestic bots, with 740,000 daily C2 requests, confirming sustained high-volume malicious operations.
Pulse ID: 6a696c974025043392ff887b
Pulse Link: https://otx.alienvault.com/pulse/6a696c974025043392ff887b
Pulse Author: AlienVault
Created: 2026-07-29 02:59:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APAC #BlockChain #CyberSecurity #DDoS #DoS #Encryption #InfoSec #IoT #OTX #OpenThreatExchange #Proxy #RAT #SMS #SSH #Telnet #bot #botnet #AlienVault
-
Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria
Since Q1 2026, an emerging botnet named Dysphoria has amassed over 200,000 compromised hosts through rapid technical iterations spanning jackskid and fbot variants. The botnet employs sophisticated blockchain-based command and control infrastructure using ENS and SNS domains, combined with a novel architecture that converts victim hosts into relay/proxy nodes. Dysphoria propagates primarily through Telnet/SSH credential brute-forcing and exploitation of IoT vulnerabilities. Its commercial operation offers tiered DDoS attack packages claiming up to 4 Tbps capacity, targeting victims globally across multiple industries. The botnet demonstrates advanced evasion techniques including modified RC4 encryption, UPnP NAT traversal, and dynamic C2 resolution mechanisms. Daily monitoring shows peak activity of 239,000 overseas bots and 1,801 domestic bots, with 740,000 daily C2 requests, confirming sustained high-volume malicious operations.
Pulse ID: 6a696c974025043392ff887b
Pulse Link: https://otx.alienvault.com/pulse/6a696c974025043392ff887b
Pulse Author: AlienVault
Created: 2026-07-29 02:59:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#APAC #BlockChain #CyberSecurity #DDoS #DoS #Encryption #InfoSec #IoT #OTX #OpenThreatExchange #Proxy #RAT #SMS #SSH #Telnet #bot #botnet #AlienVault
-
Botnet Dysphoria infeta 200 mil dispositivos através de falhas em routers e IoT. A rede comprometeu dispositivos a nível mundial, utilizando-os para ataques de negação de serviço (DDoS) e reencaminhar tráfego web. 🚨
-
Botnet Dysphoria infeta 200 mil dispositivos através de falhas em routers e IoT. A rede comprometeu dispositivos a nível mundial, utilizando-os para ataques de negação de serviço (DDoS) e reencaminhar tráfego web. 🚨
-
A botnet with 200,000+ infected devices is now hiding its command servers inside blockchain domains. https://iottechnews.com/news/dysphoria-iot-botnet-uses-blockchain-domains-to-hide-200k-bots/ #dysphoria #iot #botnet #infosec #blockchain #ddos #cybersecurity #technology
-
A botnet with 200,000+ infected devices is now hiding its command servers inside blockchain domains. https://iottechnews.com/news/dysphoria-iot-botnet-uses-blockchain-domains-to-hide-200k-bots/ #dysphoria #iot #botnet #infosec #blockchain #ddos #cybersecurity #technology
-
NadMesh Botnet Targets AI and Cloud Infrastructure
Pulse ID: 6a64a9954c20b3eb7ba237be
Pulse Link: https://otx.alienvault.com/pulse/6a64a9954c20b3eb7ba237be
Pulse Author: cryptocti
Created: 2026-07-25 12:18:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #cryptocti
-
NadMesh Botnet Targets AI and Cloud Infrastructure
Pulse ID: 6a64a9954c20b3eb7ba237be
Pulse Link: https://otx.alienvault.com/pulse/6a64a9954c20b3eb7ba237be
Pulse Author: cryptocti
Created: 2026-07-25 12:18:29Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #cryptocti
-
El lado del mal - Cloudflare Turnstile & Precursor: Cómo detectar Bots y Humanos sin usar Captchas Cognitivos https://www.elladodelmal.com/2026/07/cloudflare-turnstile-precursor-como.html #Cloudflare #precursor #CaptchaCognitivo #Bot #Botnet #Ciberseguridad
-
El lado del mal - Cloudflare Turnstile & Precursor: Cómo detectar Bots y Humanos sin usar Captchas Cognitivos https://www.elladodelmal.com/2026/07/cloudflare-turnstile-precursor-como.html #Cloudflare #precursor #CaptchaCognitivo #Bot #Botnet #Ciberseguridad
-
NadMesh Botnet Analysis: Product-Level Threat in the AI Services Era
In July 2026, a sophisticated Go-based botnet named NadMesh was discovered actively deploying across the internet. Unlike traditional worms, it integrates autonomous scanning, exploitation of 20+ vulnerabilities, and targeted harvesting of AI infrastructure credentials. The botnet specifically targets AI services including ComfyUI, Ollama, and MCP ecosystems using Shodan intelligence to prioritize high-value assets. It features a web-based control panel, multi-stage persistence mechanisms including SSH backdoors and cron watchdogs, and polymorphic builds using Garble obfuscation and UPX compression. The operation demonstrates product-grade engineering with automated feedback loops for task generation, honeypot avoidance, and credential extraction from cloud environments, Kubernetes clusters, and AI model services.
Pulse ID: 6a5e35e2a358640bd14154c8
Pulse Link: https://otx.alienvault.com/pulse/6a5e35e2a358640bd14154c8
Pulse Author: AlienVault
Created: 2026-07-20 14:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #HoneyPot #InfoSec #OTX #OpenThreatExchange #RAT #SMS #SSH #WatchDog #Worm #bot #botnet #AlienVault
-
NadMesh Botnet Analysis: Product-Level Threat in the AI Services Era
In July 2026, a sophisticated Go-based botnet named NadMesh was discovered actively deploying across the internet. Unlike traditional worms, it integrates autonomous scanning, exploitation of 20+ vulnerabilities, and targeted harvesting of AI infrastructure credentials. The botnet specifically targets AI services including ComfyUI, Ollama, and MCP ecosystems using Shodan intelligence to prioritize high-value assets. It features a web-based control panel, multi-stage persistence mechanisms including SSH backdoors and cron watchdogs, and polymorphic builds using Garble obfuscation and UPX compression. The operation demonstrates product-grade engineering with automated feedback loops for task generation, honeypot avoidance, and credential extraction from cloud environments, Kubernetes clusters, and AI model services.
Pulse ID: 6a5e35e2a358640bd14154c8
Pulse Link: https://otx.alienvault.com/pulse/6a5e35e2a358640bd14154c8
Pulse Author: AlienVault
Created: 2026-07-20 14:51:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #Cloud #CyberSecurity #HoneyPot #InfoSec #OTX #OpenThreatExchange #RAT #SMS #SSH #WatchDog #Worm #bot #botnet #AlienVault
-
Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects
VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.
Pulse ID: 6a5f5a54ab92617993537c0b
Pulse Link: https://otx.alienvault.com/pulse/6a5f5a54ab92617993537c0b
Pulse Author: AlienVault
Created: 2026-07-21 11:39:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault
-
Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects
VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.
Pulse ID: 6a5f5a54ab92617993537c0b
Pulse Link: https://otx.alienvault.com/pulse/6a5f5a54ab92617993537c0b
Pulse Author: AlienVault
Created: 2026-07-21 11:39:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault
-
Botnet Analysis: A Product-Grade Threat for the AI Service Era
Pulse ID: 6a5daa0fd86bc37067fdd7ce
Pulse Link: https://otx.alienvault.com/pulse/6a5daa0fd86bc37067fdd7ce
Pulse Author: Tr1sa111
Created: 2026-07-20 04:54:39Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111