Skip to main content
← All Articles

Tag

#Botnet

45 articles

Advertisement

Android Car Head Unit Malware Spreads via Built-In Updaters
MEDIUM
Malware

Android Car Head Unit Malware Spreads via Built-In Updaters

Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.

Runtime Rebel Intel
2 min read · Aug 22, 2026
Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft
HIGH
Malware

Evooo1Bot Linux Botnet: Beyond DDoS with Exploits & Credential Theft

Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.

Runtime Rebel Intel
3 min read · Aug 17, 2026
MEDIUM
Threat Intel

AI-Powered Malware Analysis: Detecting Persistent Threats on Sensors

An analysis using Gemma4 with Ollama reveals high-volume malware downloads on DShield sensors, indicating persistent actor activity and critical compromise risks.

Runtime Rebel Intel
4 min read · Aug 13, 2026
Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience
HIGH
Malware

Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience

Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.

Runtime Rebel Intel
4 min read · Aug 11, 2026
Aeternum Botnet Leverages Polygon Blockchain for Resilient C2
MEDIUM
Malware

Aeternum Botnet Leverages Polygon Blockchain for Resilient C2

Aeternum botnet uses Polygon blockchain smart contracts for C2, making it resilient to takedowns. Security professionals must understand its decentralized operations.

Runtime Rebel Intel
3 min read · Aug 11, 2026
LOW
Vulnerabilities

Botnet Targets Diagnostic Tools: Preventing OS Command Injection

A botnet is actively scanning for vulnerabilities in web-accessible diagnostic tools.

Runtime Rebel Intel
5 min read · Aug 4, 2026

Advertisement

HIGH
Threat Intel

Generic Streaming Sticks: Covert Proxy Networks & Ad Fraud Exposed

Generic TV streaming sticks are being used in a dual-pronged attack: creating a covert proxy network and engaging in extensive ad fraud through spoofed mobile traffic on…

Runtime Rebel Intel
5 min read · Jul 30, 2026
HIGH
Malware

Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay

Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.

Runtime Rebel Intel
4 min read · Jul 27, 2026
Russian-Speaking Hacker Uses Google Gemini CLI for Botnet Control
MEDIUM
Threat Intel

Russian-Speaking Hacker Uses Google Gemini CLI for Botnet Control

Russian-speaking actor bandcampro utilized Google Gemini CLI to automate botnet control and password cracking across compromised dental healthcare systems.

Runtime Rebel Intel
3 min read · Jul 20, 2026
HIGH
Threat Intel

Hikvision ISAPI Scanning Trends: Analysis and Mitigation Guide

Recent honeypot data reveals a surge in probes targeting the Hikvision Intelligent Security API. Learn how to identify and defend against these IoT scans.

Runtime Rebel Intel
3 min read · Jul 19, 2026
MEDIUM
Threat Intel

Google Gemini CLI Abused by 'bandcampro' for Botnet Operations

Russian-speaking threat actor 'bandcampro' is leveraging Google's Gemini CLI as a hacking agent and to command a small-scale botnet.

Runtime Rebel Intel
5 min read · Jul 15, 2026
Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware
HIGH
Supply Chain

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Official AsyncAPI npm packages have been compromised to distribute botnet malware. Learn how to detect and mitigate these supply chain attacks.

Runtime Rebel Intel
4 min read · Jul 15, 2026
HalluSquatting: AI Coding Assistants Tricked into Botnet Malware
HIGH
Threat Intel

HalluSquatting: AI Coding Assistants Tricked into Botnet Malware

New HalluSquatting research reveals how attackers can register fake project names hallucinated by AI coding assistants to deploy botnet malware onto developer systems.

Runtime Rebel Intel
5 min read · Jul 8, 2026
HIGH
Threat Intel

NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off

A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.

Runtime Rebel Intel
5 min read · Jul 4, 2026
MEDIUM
Threat Intel

Google Disrupts NetNut Malicious Residential Proxy Network

Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.

Runtime Rebel Intel
4 min read · Jul 3, 2026
NetNut (Popa) Residential Proxy Disruption: Impact & Defense
MEDIUM
Threat Intel

NetNut (Popa) Residential Proxy Disruption: Impact & Defense

Google, FBI, and Lumen have disrupted NetNut (Popa), a vast residential proxy network, reducing its pool of compromised home devices by millions.

Runtime Rebel Intel
4 min read · Jul 2, 2026
HIGH
Malware

Amadey & StealC Malware C2 Infrastructure Disrupted

Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.

Runtime Rebel Intel
4 min read · Jun 24, 2026
HIGH
Malware

AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies

The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.

Runtime Rebel Intel
3 min read · Jun 21, 2026
JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices
HIGH
Threat Intel

JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices

China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.

Runtime Rebel Intel
4 min read · Jun 10, 2026
HIGH
Malware

C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation

C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.

Runtime Rebel Intel
3 min read · Jun 7, 2026
Dutch Police Seize 200 Servers to Dismantle 17-Million Device Botnet
HIGH
Threat Intel

Dutch Police Seize 200 Servers to Dismantle 17-Million Device Botnet

Dutch authorities and the NCSC dismantled a global botnet affecting 17 million devices. Learn how the seizure of 200 servers impacts global cybercrime operations.

Runtime Rebel Intel
4 min read · May 31, 2026
MEDIUM
Threat Intel

Canadian Man Arrested for Kimwolf Botnet Operations

Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.

Runtime Rebel Intel
4 min read · May 22, 2026
HIGH
Threat Intel

US and Canada Charge Suspected KimWolf Botnet Operator

Authorities dismantle the KimWolf botnet following the arrest of a Canadian national linked to nearly two million global device infections and DDoS attacks.

Runtime Rebel Intel
4 min read · May 22, 2026
MEDIUM
Threat Intel

Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation

Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.

Runtime Rebel Intel
4 min read · May 22, 2026