< ciso
brief />
Tag Banner

All news with #botnet tag

131 articles

Android head-unit malware expands automotive botnets

πŸ” In June 2026, researchers discovered malware targeting Android-based car head units that is delivered via an automatic firmware-update service. The attackers exploit DoFun’s TWCore updater to install a hidden dropper called JarService, which downloads a clicker and a proxy module to enroll head units in a botnet. Infected devices are used for ad fraud and to provide residential proxy services, degrading performance and exposing cars to further payloads.
read more β†’

Cloudflare: Massive rise in >1 Tbps DDoS attacks

πŸ›‘οΈ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more β†’

Dysphoria botnet compromises 200,000 IoT devices

πŸ” Researchers report a new botnet named Dysphoria has infected roughly 200,000 devices globally and is being used for DDoS attacks and traffic relay operations. QiAnXin XLab attributes Dysphoria's evolution to earlier malware families and notes it uses Ethereum ENS and Solana SNS domains for covert C2 resolution. The botnet spreads via weak Telnet/SSH credentials and known router and IoT vulnerabilities, and some variants now solely provide proxy services.
read more β†’

Google Gemini CLI abused to operate malware botnet

πŸ” A Russian-speaking actor called "bandcampro" leveraged Google's open-source Gemini CLI as an AI hacking agent and to run a small botnet targeting at least eight systems in a dental clinic. Over 200 sessions between May and April, the AI executed migration, troubleshooting, and operational improvements, storing credentials and following a built-in C2 playbook. Trend Micro found the setup tiny and unsophisticated, with Python HTTP and PowerShell agents and persistence via scheduled tasks, WMI, and registry changes.
read more β†’

148 npm Packages Masked as Student Proxies Abused

πŸ” JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more β†’

Monday Recap: Proxy Botnets, Browser Ransomware

⚑ Google and partners disrupted the NetNut residential proxy network (aka Popa), which abused smart home devices and preinstalled SDKs to route malicious traffic through an estimated 2 million devices. Other incidents this week include fake PoC repos delivering the ChocoPoC RAT via a dependency, a 19-year-old alleged Scattered Spider suspect extradited to the U.S., and a Brazilian Ousaban banking trojan targeting Spain and Portugal. Check Point flagged AI-generated browser ransomware leveraging the File System Access API, illustrating AI can autonomously devise working attack techniques.
read more β†’

FBI and Google Disrupt Major NetNut Proxy Network

πŸ›‘οΈ In a coordinated international action, the FBI and Google's Threat Intelligence Group disrupted NetNut, a large commercial residential proxy network built on the Popa botnet. The operation targeted infrastructure, seized domains and worked with partners like Lumen and the IRS to degrade the service. Google disabled accounts, updated Play Protect and removed compromised apps to reduce the pool of infected devices by millions. The takedown exposed ties between the botnet and reseller programs and prompted debate after some NetNut domains remained temporarily active.
read more β†’

Canada’s Spy Agency Uses Court Warrant to Disrupt Botnets

πŸ›‘οΈ The Federal Court authorized the Canadian Security Intelligence Service to reach into infected servers, SOHO routers, and IoT devices on Canadian soil to neutralize two foreign-run botnets. The public ruling, released June 15, confirms CSIS used its threat reduction warrant powers for the first time to alter, degrade, and destroy botnet data while ensuring the operation targeted devices rather than people. The court found the threat imminent and proportional, but redactions leave the precise foreign actor(s) unidentified.
read more β†’

AryStinger malware converts legacy routers into relays

πŸ” QiAnXin XLab has identified a new malware family named AryStinger that has infected at least 4,300 legacy home routers, turning them into a distributed reconnaissance and proxy network rather than a typical DDoS botnet. The campaign targets routers using Realtek RTL819X chips via old vulnerabilities (CVE-2013-3307, CVE-2016-5681) and favors D-Link DIR-850L units, with infections concentrated in South Korea and China. A second strain targeting QNAP NAS devices via CVE-2025-11837 was also observed; both builds support scanning, tunneling, and remote task execution. Defenders are advised to check for C2 connections, suspicious binaries and processes, retire unsupported devices, and disable remote administration.
read more β†’

Law enforcement disrupts SocGholish infections at scale

πŸ›‘οΈ International law enforcement agencies cleaned nearly 15,000 WordPress sites and took down over 100 servers tied to the SocGholish botnet and the Evil Corp cybercrime group as part of Operation Endgame. Authorities from the Netherlands, Canada, the United States, and Germany removed malware and backdoors from 14,971 compromised sites, advised remediation steps, and decommissioned 106 servers and domains. The action aims to deny criminals access, limit malware spread, and reduce risks to critical infrastructure.
read more β†’

China-linked JDY botnet accelerates enterprise risk

πŸ” Lumen’s Black Lotus Labs reports a China-linked botnet called JDY has grown to over 1,500 compromised SOHO and IoT devices used to rapidly discover and fingerprint internet-facing systems after public vulnerability disclosures. The activity, tied to nation-state actors including Volt Typhoon, enables persistent, distributed reconnaissance that can evade geofencing and IP-reputation controls. Researchers warn this marks a shift toward industrialized pre-exploitation scanning and undermines traditional perimeter patch and monitoring assumptions.
read more β†’

China-linked JDY botnet broadens US military focus

πŸ›‘οΈ JDY is a distributed reconnaissance botnet tied to China-nexus actors that has expanded from ~650 to over 1,500 compromised SOHO and IoT devices, with a heavy focus on U.S. military and associated networks. Researchers at Black Lotus Labs observed JDY rapidly scanning for newly disclosed vulnerabilities, collecting banners, TLS certificates, and protocol fingerprints. The botnet uses Tor-hidden services and a central Dispatch Service to receive scanning tasks and exfiltrate results, and supports TCP/SSL/UDP/ICMP scanning plus service fingerprinting.
read more β†’

Inside C0XMO: Cross-Platform Gafgyt Propagation

πŸ›‘οΈ FortiGuard Labs details a new Gafgyt variant, C0XMO, which exploits CVE-2021-27137 in vulnerable DD-WRT firmware to gain remote control of devices. The malware separates scanning into a standalone Python scanner and distributes architecture-specific ELF payloads to multiple Linux platforms. C0XMO implements multi-stage persistence, kills competing botnets, supports extensive DDoS commands, and communicates with a C2 using a custom handshake. Organizations should update firmware, disable unnecessary remote services, and enforce strong credentials to mitigate risk.
read more β†’

Dutch Authorities Dismantle Massive Botnet Network

πŸ›‘οΈ Dutch authorities and the National Cyber Security Center announced the takedown of a botnet that had enlisted millions of devices, including computers, smartphones, tablets, and IoT gear. The network reportedly comprised at least 17 million infected devices and relied on more than 200 servers in the Netherlands for backend infrastructure. Police seized a subset of those servers from a hosting provider, which then took the botnet offline after it was used for criminal activity. Local reporting linked the operation to proxy services such as Asocks, previously associated with proxyware campaigns affecting Android devices.
read more β†’

Researchers Disrupt Glassworm's Resilient Botnet C2

πŸ›‘οΈ CrowdStrike, Google, and The Shadowserver Foundation coordinated to disrupt the Glassworm botnet by simultaneously takedown of four resilient C2 channels. The threat abused Solana blockchain memo fields, the BitTorrent DHT, Google Calendar events, and traditional VPS-hosted servers to persist and evade mitigation. Active campaigns targeted developers via malicious OpenVSX and VS Code extensions and later poisoned GitHub and npm artifacts. Infected hosts now beacon to a CrowdStrike-controlled IP and YARA rules have been published to detect compromise.
read more β†’

Fraud Schemes Target Formula 1 Fans Worldwide

🚨 A Bitdefender report warns that cybercriminals have built extensive ecosystems to scam Formula 1 fans, exploiting the sport’s fast-moving digital culture. Scams include counterfeit merchandise, fake grand prix tickets, illegal streaming apps and boxes, social media fraud and distribution of infostealer malware. Fans may also be coerced into botnets for DDoS attacks. Bitdefender urges vigilance and recommends anti-phishing and antivirus tools to reduce risk.
read more β†’

Canadian Arrest Over KimWolf DDoS Botnet Operations

πŸ” Canadian and U.S. authorities arrested 23-year-old Jacob Butler (aka "Dort") in Ottawa under an extradition warrant after unsealing a criminal complaint in the District of Alaska linking him to the KimWolf DDoS botnet. Investigators tied Butler to the botnet through IP address logs, transaction records, and online messages, and he now faces a charge of aiding and abetting computer intrusions with a potential 10-year sentence. KimWolf operated as a DDoS-for-hire service that enslaved nearly two million devices and powered attacks up to nearly 30 Tbps, causing substantial global disruption and financial losses.
read more β†’

Canadian Arrest Tied to Kimwolf DDoS Botnet

πŸ›‘οΈ The U.S. Department of Justice announced the arrest of 23-year-old Canadian Jacob Butler (aka Dort) for allegedly operating the Kimwolf DDoS botnet, a variant of AISURU. The botnet enslaved devices like digital photo frames and webcams and was offered via a cybercrime-as-a-service model to launch global attacks, including against DoD network addresses. Authorities linked Butler through IP, account data, and Discord messages, and charged him with aiding and abetting computer intrusion.
read more β†’

Kazuar Evolves into Modular P2P Botnet by Secret Blizzard

πŸ“‘ Microsoft reports that Russian-linked actor Secret Blizzard has turned the long-running Kazuar backdoor into a modular peer-to-peer botnet built for persistence, stealth, and data theft. The malware now runs three modulesβ€”Kernel, Bridge, and Workerβ€”with an elected Kernel leader to minimize external C2 traffic and improve stealth. Internal IPC, AES encryption, and Protobuf serialization protect communications, while 150+ configuration options and AMSI/ETW/WLDP bypasses increase evasion.
read more β†’

Turla Converts Kazuar Into Modular P2P Botnet for Stealth

🐍 Microsoft and CISA report that Russian state-linked Turla has evolved its Kazuar .NET backdoor into a modular, peer-to-peer botnet engineered for stealth and persistence. The architecture now separates into Kernel, Bridge, and Worker modules to minimize footprint and enable flexible tasking. Deployments use droppers such as Pelmeni and ShadowLoader to decrypt and load modules across compromised hosts. The design centralizes staging in a dedicated working directory to maintain state and streamline exfiltration.
read more β†’