home.social

#botnet — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #botnet, aggregated by home.social.

fetched live
  1. Dysphoria Botnet Campaign Targeting IoT Devices for DDoS Attacks

    Pulse ID: 6a7f750c25e71ea88a305576
    Pulse Link: otx.alienvault.com/pulse/6a7f7
    Pulse Author: cryptocti
    Created: 2026-08-14 20:05:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DDoS #DoS #InfoSec #IoT #OTX #OpenThreatExchange #bot #botnet #cryptocti

  2. Dysphoria Botnet Campaign Targeting IoT Devices for DDoS Attacks

    Pulse ID: 6a7f750c25e71ea88a305576
    Pulse Link: otx.alienvault.com/pulse/6a7f7
    Pulse Author: cryptocti
    Created: 2026-08-14 20:05:32

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DDoS #DoS #InfoSec #IoT #OTX #OpenThreatExchange #bot #botnet #cryptocti

  3. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  4. Multi-Functional Linux Botnet "Evooo1Bot"

    A previously undocumented Linux botnet named Evooo1Bot has been discovered, actively targeting Internet-facing devices since July 2026. Built upon Mirai's DDoS engine, it extends functionality with encrypted C2 communications, SSH brute-force scanning, SOCKS relay capabilities, credential sniffing, and an integrated exploit arsenal. The malware employs multi-layer string encryption using AES-256-CTR, ChaCha20, and XOR-based key derivation. It exploits numerous vulnerabilities across edge devices, routers, and enterprise applications. The reverse SOCKS relay module transforms compromised devices into persistent proxies, enabling attackers to conceal their origin and pivot into internal networks. The botnet features 28 remote commands organized into modules for persistence, self-update, file transfer, interactive shell, sniffing, proxy relay, SSH scanning, DDoS attacks, and CVE exploitation. Multiple persistence mechanisms ensure continued operation across systemd, SysV init, cron, and shell profiles.

    Pulse ID: 6a7e2be6ba37cc87ae552659
    Pulse Link: otx.alienvault.com/pulse/6a7e2
    Pulse Author: AlienVault
    Created: 2026-08-13 20:41:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ChaCha20 #CyberSecurity #DDoS #DoS #ELF #Edge #Encryption #InfoSec #Linux #Malware #Mirai #OTX #OpenThreatExchange #Proxy #RAT #RCE #SMS #SSH #bot #botnet #AlienVault

  5. Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ae

    Pulse ID: 6a7eca0c254771760ee44515
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 07:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  6. Aeternum Botnet Uses Polygon Smart Contracts for Takedown-Resistant Malware C2

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ae

    Pulse ID: 6a7eca0c254771760ee44515
    Pulse Link: otx.alienvault.com/pulse/6a7ec
    Pulse Author: CyberHunter_NL
    Created: 2026-08-14 07:55:56

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  7. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  8. Kimwolf v7 Botnet Uses Chrome Browser Fingerprints to Hide HTTP/2 DDoS Attacks

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7da2b72179e3a4cb0c1d31
    Pulse Link: otx.alienvault.com/pulse/6a7da
    Pulse Author: CyberHunter_NL
    Created: 2026-08-13 10:55:51

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #Chrome #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  9. "Smart" cars are just rolling, unpatched IoT botnets. The OEM drops OTA updates after year 3, but the rustbucket keeps driving for 15 years and more. Millions of them.
    Does anyone actually know how this works?

    #ConnectedCar #Security #IoT #InfoSec #Botnet #Automotive

  10. StealC C2 domains dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️
    🌐 cloud-flare-authenticator .link
    🌐 cloud-flare-authenticator .click
    🌐 update-microsoft-data .services
    📡 89.34.90.45:443

    OverlordRAT #botnet C2 server ⤵️
    🌐 download-windows-update .live
    📡 151.243.113.94:5173

    Both hosted at AS207043 DEDIK-IO in Germany🇩🇪

    📄 Malware sample:
    bazaar.abuse.ch/sample/5c61c97

    🦊 IOCs on ThreatFox:
    threatfox.abuse.ch/browse/malw
    threatfox.abuse.ch/browse/tag/

  11. StealC C2 domains dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️
    🌐 cloud-flare-authenticator .link
    🌐 cloud-flare-authenticator .click
    🌐 update-microsoft-data .services
    📡 89.34.90.45:443

    OverlordRAT #botnet C2 server ⤵️
    🌐 download-windows-update .live
    📡 151.243.113.94:5173

    Both hosted at AS207043 DEDIK-IO in Germany🇩🇪

    📄 Malware sample:
    bazaar.abuse.ch/sample/5c61c97

    🦊 IOCs on ThreatFox:
    threatfox.abuse.ch/browse/malw
    threatfox.abuse.ch/browse/tag/

  12. An Evolution of the Botnet

    Pulse ID: 6a7bf8a320deffc5bdc1c33a
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:37:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111

  13. An Evolution of the Botnet

    Pulse ID: 6a7bf8a320deffc5bdc1c33a
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:37:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111

  14. An Evolution of the Botnet

    Pulse ID: 6a7bf8f57f942af8b9b49faa
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:39:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111

  15. An Evolution of the Botnet

    Pulse ID: 6a7bf8f57f942af8b9b49faa
    Pulse Link: otx.alienvault.com/pulse/6a7bf
    Pulse Author: Tr1sa111
    Created: 2026-08-12 04:39:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111

  16. 📰 TuxBot v3: New IoT Botnet Framework Developed with LLM Assistance

    Unit 42 details TuxBot v3, a new modular IoT botnet framework. Developed with LLM assistance, it features Telnet brute-forcing, DDoS capabilities, and C2 fallbacks via DGA & Pastebin. Shows evolution of AI in malware creation. #TuxBot #IoT #Botnet #M...

    🔗 cyber.netsecops.io/articles/tu

  17. 📰 Aeternum Botnet Uses Polygon Blockchain for Resilient C2

    Aeternum C++ botnet loader uses Polygon blockchain for decentralized C2, issuing commands via smart contracts. This resilient architecture complicates takedowns. #Aeternum #Botnet #Blockchain #C2 #Malware #Polygon

    🔗 cyber.netsecops.io/articles/ae

  18. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7b8c7ac9f862e53382eab9
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  19. Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

    Indicators extracted from public reporting. Source: unit42.paloaltonetworks.com/ki

    Pulse ID: 6a7b8c7ac9f862e53382eab9
    Pulse Link: otx.alienvault.com/pulse/6a7b8
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 20:56:26

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #CyberSecurity #DDoS #DoS #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  20. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  21. An Evolution of the Botnet

    A new version of the Kimwolf Android/IoT botnet has been identified, targeting Android TV boxes and set-top boxes. The version 7 variant introduces enhanced DDoS capabilities including HTTP/2-based floods with complete browser fingerprinting to mimic legitimate traffic. It employs a resilient three-tier command-and-control infrastructure using Ethereum Name Service resolution through five hard-coded public endpoints, a Tor hidden service backup, and local proxy architecture. The malware spreads by exploiting unauthenticated Android Debug Bridge instances via residential proxy services. The botnet implements 15 DDoS attack methods and utilizes ARM NEON SIMD optimization for high-performance UDP floods. Operators removed scanning and exploitation modules, separating propagation from DDoS functionality. The infrastructure is hosted primarily in Russia, with evidence of operator-controlled Ethereum RPC endpoints.

    Pulse ID: 6a7b3ea11dca2e714d4bff8d
    Pulse Link: otx.alienvault.com/pulse/6a7b3
    Pulse Author: AlienVault
    Created: 2026-08-11 15:24:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Android #Browser #CyberSecurity #DDoS #DoS #Endpoint #HTTP #InfoSec #IoT #Malware #Mimic #OTX #OpenThreatExchange #Proxy #RAT #RPC #Russia #Troll #UDP #bot #botnet #AlienVault

  22. Kimwolf v7: An Evolution of the Kimwolf Botnet

    Indicators extracted from public reporting. Source: mastodon.social/share?text=Kim

    Pulse ID: 6a7affd02bfe3b8250af6b91
    Pulse Link: otx.alienvault.com/pulse/6a7af
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 10:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  23. Kimwolf v7: An Evolution of the Kimwolf Botnet

    Indicators extracted from public reporting. Source: mastodon.social/share?text=Kim

    Pulse ID: 6a7affd02bfe3b8250af6b91
    Pulse Link: otx.alienvault.com/pulse/6a7af
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 10:56:16

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Malware #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  24. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault

  25. The Permanent Threat: Analyzing Blockchain-Based C2 Operations and Communications

    Aeternum is a C++ botnet loader utilizing the Polygon blockchain for command-and-control infrastructure instead of traditional centralized servers. Threat actors write encrypted and plaintext instructions directly to smart contracts, which infected devices query via public RPC endpoints. The malware implements weak PBKDF2HMAC/AES-GCM encryption with self-salting passwords, allowing payload decryption using only the smart contract address. Analysis reveals three related samples: the core Aeternum loader with Telegram-based exfiltration, a blended threat combining XWorm RAT with XMRig cryptocurrency miner, and Python source code revealing anti-analysis checks and cryptocurrency wallet targeting. The botnet demonstrates resilience through decentralized infrastructure, making traditional law enforcement takedowns significantly more challenging while maintaining low operational costs for attackers.

    Pulse ID: 6a7a8be76fe0dfa36d01afa0
    Pulse Link: otx.alienvault.com/pulse/6a7a8
    Pulse Author: AlienVault
    Created: 2026-08-11 02:41:43

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BlockChain #CyberSecurity #ELF #Encryption #Endpoint #InfoSec #LawEnforcement #Mac #Malware #OTX #OpenThreatExchange #Password #Passwords #Python #RAT #RCE #RPC #Telegram #Word #Worm #XWorm #bot #botnet #cryptocurrency #AlienVault

  26. Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

    Indicators extracted from public reporting. Source: isc.sans.edu/diary/Botnet+Hunt

    Pulse ID: 6a72de857045761cca5a65b5
    Pulse Link: otx.alienvault.com/pulse/6a72d
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 06:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  27. Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

    Indicators extracted from public reporting. Source: isc.sans.edu/diary/Botnet+Hunt

    Pulse ID: 6a72de857045761cca5a65b5
    Pulse Link: otx.alienvault.com/pulse/6a72d
    Pulse Author: CyberHunter_NL
    Created: 2026-08-05 06:56:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #OTX #OpenThreatExchange #RCE #bot #botnet #CyberHunter_NL

  28. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  29. Almost Half of Malware Samples Communicate Direct to IP

    Analysis of 4 million dynamic malware reports reveals that 45.32% of malware samples with command-and-control activity establish direct-to-IP (D2IP) connections, bypassing DNS entirely and evading DNS-based security defenses. D2IP traffic accounts for 23.17% of all C2 connection attempts. This behavior is observed across diverse threats including Phorpiex ransomware droppers using hard-coded IP addresses, persistent data exfiltration campaigns employing obfuscated HTTP GET requests, SectopRAT targeting educational institutions with in-browser proxy capabilities, and IoT botnets like Mozi and Boatnet propagating through P2P networks. The research introduces zero trust IP (ZT-IP), a network-level enforcement approach that verifies whether outbound connection destinations were previously sanctioned by DNS responses, effectively blocking malicious D2IP communications that traditional DNS-based security controls cannot detect.

    Pulse ID: 6a71e43a0127c62218b7c365
    Pulse Link: otx.alienvault.com/pulse/6a71e
    Pulse Author: AlienVault
    Created: 2026-08-04 13:08:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Browser #CyberSecurity #DNS #Education #HTTP #InfoSec #IoT #Malware #OTX #OpenThreatExchange #Phorpiex #Proxy #RAT #RCE #RansomWare #Rust #ZeroTrust #bot #botnet #AlienVault

  30. Interisle's malware analyses for the April – June 2026 reporting period are now available at the Cybercrime Information Center.

    There, you can find rankings of the Top-level Domains (TLDs), Domain Registrars, and Hosting operators (by ASN) with the most malware activity.

    We also post aggregate records of all operators that met our minimum criteria for malware reported in CSV format at the Cybercrime Information Center’s records repository.

    interisle.substack.com/p/malwa

    #malware #cybercrime #cybersecurity #botnet #endpointmalware #attackware #iotmalware

  31. Interisle's malware analyses for the April – June 2026 reporting period are now available at the Cybercrime Information Center.

    There, you can find rankings of the Top-level Domains (TLDs), Domain Registrars, and Hosting operators (by ASN) with the most malware activity.

    We also post aggregate records of all operators that met our minimum criteria for malware reported in CSV format at the Cybercrime Information Center’s records repository.

    interisle.substack.com/p/malwa

    #malware #cybercrime #cybersecurity #botnet #endpointmalware #attackware #iotmalware

  32. Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria

    Pulse ID: 6a6ad695edc161364e89824d
    Pulse Link: otx.alienvault.com/pulse/6a6ad
    Pulse Author: Tr1sa111
    Created: 2026-07-30 04:44:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111

  33. Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria

    Pulse ID: 6a6ad695edc161364e89824d
    Pulse Link: otx.alienvault.com/pulse/6a6ad
    Pulse Author: Tr1sa111
    Created: 2026-07-30 04:44:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111

  34. "Eine neue Botnetz-Malware namens Tengu hat es auf Linux-Systeme abgesehen. Sie schaltet die Konkurrenz aus und weiß sich selbst zu wehren."

    golem.de/news/botnetz-malware-

    #cybersecurity #linux #botnet

  35. "Eine neue Botnetz-Malware namens Tengu hat es auf Linux-Systeme abgesehen. Sie schaltet die Konkurrenz aus und weiß sich selbst zu wehren."

    golem.de/news/botnetz-malware-

    #cybersecurity #linux #botnet

  36. Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria

    Since Q1 2026, an emerging botnet named Dysphoria has amassed over 200,000 compromised hosts through rapid technical iterations spanning jackskid and fbot variants. The botnet employs sophisticated blockchain-based command and control infrastructure using ENS and SNS domains, combined with a novel architecture that converts victim hosts into relay/proxy nodes. Dysphoria propagates primarily through Telnet/SSH credential brute-forcing and exploitation of IoT vulnerabilities. Its commercial operation offers tiered DDoS attack packages claiming up to 4 Tbps capacity, targeting victims globally across multiple industries. The botnet demonstrates advanced evasion techniques including modified RC4 encryption, UPnP NAT traversal, and dynamic C2 resolution mechanisms. Daily monitoring shows peak activity of 239,000 overseas bots and 1,801 domestic bots, with 740,000 daily C2 requests, confirming sustained high-volume malicious operations.

    Pulse ID: 6a696c974025043392ff887b
    Pulse Link: otx.alienvault.com/pulse/6a696
    Pulse Author: AlienVault
    Created: 2026-07-29 02:59:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #BlockChain #CyberSecurity #DDoS #DoS #Encryption #InfoSec #IoT #OTX #OpenThreatExchange #Proxy #RAT #SMS #SSH #Telnet #bot #botnet #AlienVault

  37. Botnet Rising Star: The Evolution and In-Depth Technical Analysis of Dysphoria

    Since Q1 2026, an emerging botnet named Dysphoria has amassed over 200,000 compromised hosts through rapid technical iterations spanning jackskid and fbot variants. The botnet employs sophisticated blockchain-based command and control infrastructure using ENS and SNS domains, combined with a novel architecture that converts victim hosts into relay/proxy nodes. Dysphoria propagates primarily through Telnet/SSH credential brute-forcing and exploitation of IoT vulnerabilities. Its commercial operation offers tiered DDoS attack packages claiming up to 4 Tbps capacity, targeting victims globally across multiple industries. The botnet demonstrates advanced evasion techniques including modified RC4 encryption, UPnP NAT traversal, and dynamic C2 resolution mechanisms. Daily monitoring shows peak activity of 239,000 overseas bots and 1,801 domestic bots, with 740,000 daily C2 requests, confirming sustained high-volume malicious operations.

    Pulse ID: 6a696c974025043392ff887b
    Pulse Link: otx.alienvault.com/pulse/6a696
    Pulse Author: AlienVault
    Created: 2026-07-29 02:59:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #APAC #BlockChain #CyberSecurity #DDoS #DoS #Encryption #InfoSec #IoT #OTX #OpenThreatExchange #Proxy #RAT #SMS #SSH #Telnet #bot #botnet #AlienVault

  38. Botnet Dysphoria infeta 200 mil dispositivos através de falhas em routers e IoT. A rede comprometeu dispositivos a nível mundial, utilizando-os para ataques de negação de serviço (DDoS) e reencaminhar tráfego web. 🚨

    🔗 tugatech.com.pt/t88206-botnet-

    #botnet 

  39. Botnet Dysphoria infeta 200 mil dispositivos através de falhas em routers e IoT. A rede comprometeu dispositivos a nível mundial, utilizando-os para ataques de negação de serviço (DDoS) e reencaminhar tráfego web. 🚨

    🔗 tugatech.com.pt/t88206-botnet-

    #botnet 

  40. NadMesh Botnet Targets AI and Cloud Infrastructure

    Pulse ID: 6a64a9954c20b3eb7ba237be
    Pulse Link: otx.alienvault.com/pulse/6a64a
    Pulse Author: cryptocti
    Created: 2026-07-25 12:18:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #cryptocti

  41. NadMesh Botnet Targets AI and Cloud Infrastructure

    Pulse ID: 6a64a9954c20b3eb7ba237be
    Pulse Link: otx.alienvault.com/pulse/6a64a
    Pulse Author: cryptocti
    Created: 2026-07-25 12:18:29

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Cloud #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #cryptocti

  42. NadMesh Botnet Analysis: Product-Level Threat in the AI Services Era

    In July 2026, a sophisticated Go-based botnet named NadMesh was discovered actively deploying across the internet. Unlike traditional worms, it integrates autonomous scanning, exploitation of 20+ vulnerabilities, and targeted harvesting of AI infrastructure credentials. The botnet specifically targets AI services including ComfyUI, Ollama, and MCP ecosystems using Shodan intelligence to prioritize high-value assets. It features a web-based control panel, multi-stage persistence mechanisms including SSH backdoors and cron watchdogs, and polymorphic builds using Garble obfuscation and UPX compression. The operation demonstrates product-grade engineering with automated feedback loops for task generation, honeypot avoidance, and credential extraction from cloud environments, Kubernetes clusters, and AI model services.

    Pulse ID: 6a5e35e2a358640bd14154c8
    Pulse Link: otx.alienvault.com/pulse/6a5e3
    Pulse Author: AlienVault
    Created: 2026-07-20 14:51:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #HoneyPot #InfoSec #OTX #OpenThreatExchange #RAT #SMS #SSH #WatchDog #Worm #bot #botnet #AlienVault

  43. NadMesh Botnet Analysis: Product-Level Threat in the AI Services Era

    In July 2026, a sophisticated Go-based botnet named NadMesh was discovered actively deploying across the internet. Unlike traditional worms, it integrates autonomous scanning, exploitation of 20+ vulnerabilities, and targeted harvesting of AI infrastructure credentials. The botnet specifically targets AI services including ComfyUI, Ollama, and MCP ecosystems using Shodan intelligence to prioritize high-value assets. It features a web-based control panel, multi-stage persistence mechanisms including SSH backdoors and cron watchdogs, and polymorphic builds using Garble obfuscation and UPX compression. The operation demonstrates product-grade engineering with automated feedback loops for task generation, honeypot avoidance, and credential extraction from cloud environments, Kubernetes clusters, and AI model services.

    Pulse ID: 6a5e35e2a358640bd14154c8
    Pulse Link: otx.alienvault.com/pulse/6a5e3
    Pulse Author: AlienVault
    Created: 2026-07-20 14:51:14

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Cloud #CyberSecurity #HoneyPot #InfoSec #OTX #OpenThreatExchange #RAT #SMS #SSH #WatchDog #Worm #bot #botnet #AlienVault

  44. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  45. Operation STANDOFF: A Campaign Hiding C2 Behind GitHub Redirects

    VMRay Labs uncovered a sophisticated Russian-speaking cybercriminal operation combining multiple attack vectors on shared infrastructure. The campaign distributes commodity stealers including Raccoon, RedLine, Amadey, SmokeLoader, Socelars, and Glupteba through a pay-per-install loader while enrolling victims into a proxy-botnet. Command-and-control servers on Russian provider TimeWeb use GitHub domain redirects for concealment. A custom multi-operator console called STANDOFF COORD coordinates hands-on-keyboard intrusions targeting Active Directory environments, storing NTLM hashes, Kerberos tickets, and credentials organized by network segments. Additionally, the infrastructure hosts an AI-driven influence operation using industrial-scale Telegram account farms and automated engagement platforms targeting Russian-speaking mobile gaming communities through a portal called Mobile Arena, driving traffic toward gambling sites and malware distribution.

    Pulse ID: 6a5f5a54ab92617993537c0b
    Pulse Link: otx.alienvault.com/pulse/6a5f5
    Pulse Author: AlienVault
    Created: 2026-07-21 11:39:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amadey #CyberSecurity #GitHub #Glupteba #InfoSec #Malware #OTX #OpenThreatExchange #Proxy #RAT #RedLine #Russia #Telegram #bot #botnet #AlienVault

  46. Botnet Analysis: A Product-Grade Threat for the AI Service Era

    Pulse ID: 6a5daa0fd86bc37067fdd7ce
    Pulse Link: otx.alienvault.com/pulse/6a5da
    Pulse Author: Tr1sa111
    Created: 2026-07-20 04:54:39

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #OTX #OpenThreatExchange #bot #botnet #Tr1sa111