< ciso
brief />
Tag Banner

All news with #botnet tag

142 articles

Cling botnet leverages STUN to hide C2 activity

🔍 Nozomi Networks observed attackers exploiting a patched critical Realtek Jungle SDK RCE (CVE-2021-35394) starting around September 5, 2026, to deploy a botnet named Cling. The malware repurposes ordinary STUN traffic as a covert command-and-control channel, enabling propagation, proxying, tunneling and denial-of-service actions while resembling legitimate NAT-traversal activity. Samples embed multiple exploit payloads targeting routers and DVRs from various vendors and use persistence techniques like replacing wget and modifying init scripts.
read more →

Carbonato botnet exploits exposed Docker daemons

🔍 Cybersecurity researchers disclosed a new botnet named Carbonato that targets unauthenticated Docker daemons to deploy the open-source Hermes Agent AI framework. The malware installs the agent, overwrites its SOUL.md persona to accept Telegram commands, and uses privileged containers, reverse SSH tunnels, cron jobs and watchdogs to maintain persistence and propagate. ThreatDown traced artifacts to an exposed Docker registry and found the campaign includes other malicious operations such as trojanized crypto wallets.
read more →

Carbonato malware hijacks exposed Docker hosts

🛡️ A new botnet named Carbonato targets unsecured Docker daemons to install the Hermes Agent AI framework and seize control. Researchers from Malwarebytes ThreatDown found evidence from October 2024 to August 2026 showing worm-like spreading via unauthenticated Docker APIs on port 2375. The malware launches privileged containers, opens reverse SSH tunnels, installs operator keys, and establishes persistence mechanisms while reporting deployments over Telegram.
read more →

x47.c Botnet Offers AI API Draining and More

🔍 Researchers have uncovered a previously undocumented Windows botnet named x47.c that advertises 18 attack methods, including an "AI API drain" designed to exhaust paid AI credits. Qrator Research Labs analyzed seller materials from WraithTools and found modules for credential theft, SOCKS5 proxying and an AI-assisted persistence feature. The botnet also supports multiple DDoS techniques, fast-flux routing and a stealer targeting browser credentials and tokens.
read more →

Akamai: AI Spurs Major Rise in Bot and API Risk

🔍 Akamai's State of the Internet report, published on September 22, shows AI contributed to a 300% jump in bot traffic and a 113% rise in daily API attacks between 2024 and 2025. The report highlights that 87% of organizations experienced API incidents in 2025 and that AI browser extensions and unmonitored personal accounts increase enterprise data exposure. It warns that AI agents and MCP-style capabilities enable attackers to execute high-impact actions without traditional breaches.
read more →

Smart TV and Set‑Top Box Proxyware Risks

🛡️ A recent analysis shows cheap smart TVs and TV boxes are increasingly recruited into proxyware and botnets, turning household devices into gateways for malicious traffic. Infected devices often run multiple proxy clients concurrently and can expose internal network resources, allowing remote attackers to reach router admin panels and other devices. The study of a popular SuperBox model revealed persistent malware, remote code execution via firmware flaws, and over 1,300 attacks in three weeks. Users are advised to monitor network traffic, avoid dubious apps and devices, disconnect compromised hardware, and protect routers with strong unique passwords and reputable security tools.
read more →

International Operation Disrupts Long‑Running Sality Botnet

🛡️ A coordinated law enforcement action on August 31 disrupted the Sality P2P botnet, active for over 20 years. Authorities from the US, Bulgaria, Hungary and Romania, supported by Europol and private partners CrowdStrike and the Shadowserver Foundation, used sinkholing and protocol manipulation to redirect infected machines and enable remediation. The operation targeted Sality’s decentralized peer lists to remove malicious super peers and insert sinkhole entries, while ISPs and CSIRTs helped identify and notify victims.
read more →

Global takedown dismantles long-running Sality botnet

🔒 International law enforcement and private partners seized and sinkholed infrastructure tied to the Sality P2P botnet to disrupt operations and isolate infected hosts. The DOJ, FBI, and DCIS seized U.S. domains while authorities in Bulgaria, Hungary, and Romania seized European-hosted domains. CrowdStrike coordinated a peer-to-peer sinkhole that blocked Sality's super peers and payload distribution, ending operator control.
read more →

Law enforcement disrupts long‑running Sality botnet

🔒 The U.S. Department of Justice, working with international partners and industry, executed a sinkhole operation on August 31, 2026, to disrupt the Sality P2P botnet. CrowdStrike and Shadowserver collaborated with authorities from the U.S., Bulgaria, Hungary, and Romania to isolate peers and seize Sality-linked domains. The takedown prevents further payload distribution, though already infected machines still require remediation. Agencies advise reviewing network logs for beaconing to a designated sinkhole IP.
read more →

Weekly ThreatsDay: Botnets, Stealers, and RATs

🔍 This week’s ThreatsDay roundup highlights diverse active campaigns and new tooling, from a 296,000‑device IoT botnet to live operator phishing frameworks and AI‑assisted botnet orchestration. Researchers observed trojanized Electron apps, new stealers and RATs, a Rust backdoor tied to ransomware, and a loader using blockchain for C2. Also covered: a social‑engineering incident at ReliaQuest, an Android fraud bot for rent, and an unpatched disk‑encryption bypass in HP ThinPro.
read more →

FBI Disrupts China-Linked QTFY Botnet Operations

🔒 The U.S. Department of Justice and FBI announced the disruption of two hacking platforms, QScan and QTRouter, used by the China-linked group QTFY to target U.S. critical infrastructure and sensitive networks. Lumen Black Lotus Labs, which tracked the group since 2018, collaborated with the FBI after observing extensive targeting of research and public sector organizations. QScan infected IoT devices to build a proxy mesh while QTRouter and associated services obfuscated attack origins using compromised routers, commercial proxy services, and leased VPSs. The court-authorized seizure of hard-coded domains caused the platforms to cease operations.
read more →

Android head-unit malware expands automotive botnets

🔍 In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFun’s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more →

Cloudflare: Massive rise in >1 Tbps DDoS attacks

🛡️ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more →

Dysphoria botnet compromises 200,000 IoT devices

🔍 Researchers report a new botnet named Dysphoria has infected roughly 200,000 devices globally and is being used for DDoS attacks and traffic relay operations. QiAnXin XLab attributes Dysphoria's evolution to earlier malware families and notes it uses Ethereum ENS and Solana SNS domains for covert C2 resolution. The botnet spreads via weak Telnet/SSH credentials and known router and IoT vulnerabilities, and some variants now solely provide proxy services.
read more →

Google Gemini CLI abused to operate malware botnet

🔍 A Russian-speaking actor called "bandcampro" leveraged Google's open-source Gemini CLI as an AI hacking agent and to run a small botnet targeting at least eight systems in a dental clinic. Over 200 sessions between May and April, the AI executed migration, troubleshooting, and operational improvements, storing credentials and following a built-in C2 playbook. Trend Micro found the setup tiny and unsophisticated, with Python HTTP and PowerShell agents and persistence via scheduled tasks, WMI, and registry changes.
read more →

148 npm Packages Masked as Student Proxies Abused

🔍 JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more →

Monday Recap: Proxy Botnets, Browser Ransomware

⚡ Google and partners disrupted the NetNut residential proxy network (aka Popa), which abused smart home devices and preinstalled SDKs to route malicious traffic through an estimated 2 million devices. Other incidents this week include fake PoC repos delivering the ChocoPoC RAT via a dependency, a 19-year-old alleged Scattered Spider suspect extradited to the U.S., and a Brazilian Ousaban banking trojan targeting Spain and Portugal. Check Point flagged AI-generated browser ransomware leveraging the File System Access API, illustrating AI can autonomously devise working attack techniques.
read more →

FBI and Google Disrupt Major NetNut Proxy Network

🛡️ In a coordinated international action, the FBI and Google's Threat Intelligence Group disrupted NetNut, a large commercial residential proxy network built on the Popa botnet. The operation targeted infrastructure, seized domains and worked with partners like Lumen and the IRS to degrade the service. Google disabled accounts, updated Play Protect and removed compromised apps to reduce the pool of infected devices by millions. The takedown exposed ties between the botnet and reseller programs and prompted debate after some NetNut domains remained temporarily active.
read more →

Canada’s Spy Agency Uses Court Warrant to Disrupt Botnets

🛡️ The Federal Court authorized the Canadian Security Intelligence Service to reach into infected servers, SOHO routers, and IoT devices on Canadian soil to neutralize two foreign-run botnets. The public ruling, released June 15, confirms CSIS used its threat reduction warrant powers for the first time to alter, degrade, and destroy botnet data while ensuring the operation targeted devices rather than people. The court found the threat imminent and proportional, but redactions leave the precise foreign actor(s) unidentified.
read more →

AryStinger malware converts legacy routers into relays

🔍 QiAnXin XLab has identified a new malware family named AryStinger that has infected at least 4,300 legacy home routers, turning them into a distributed reconnaissance and proxy network rather than a typical DDoS botnet. The campaign targets routers using Realtek RTL819X chips via old vulnerabilities (CVE-2013-3307, CVE-2016-5681) and favors D-Link DIR-850L units, with infections concentrated in South Korea and China. A second strain targeting QNAP NAS devices via CVE-2025-11837 was also observed; both builds support scanning, tunneling, and remote task execution. Defenders are advised to check for C2 connections, suspicious binaries and processes, retire unsupported devices, and disable remote administration.
read more →