Advertisement
Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215
Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.
Infolink Anti-DDoS Provider Linked to Brazilian ISP Botnet Attacks
An investigation reveals Brazilian anti-DDoS firm Infolink facilitated massive DDoS attacks against regional ISPs, highlighting critical provider trust risks.
Chinese State-Backed Actors Industrialize Botnets for Covert Ops
Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.
SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware
Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.
PowMix Botnet Targets Czech Workers via Randomized C2 Traffic
Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.
Compromised DVRs: Identifying and Mitigating IoT Botnet Threats
Explore how Digital Video Recorders (DVRs) are compromised and incorporated into IoT botnets.
Advertisement
Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis
Exploration of a resurrected 13-year-old Apache RCE and the operational shifts of a hybrid P2P botnet architecture targeting enterprise infrastructure.
Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy
A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.
ComfyUI Instances Abused by Cryptomining Botnet: Mitigation
Over 1,000 internet-exposed ComfyUI instances are actively targeted by a cryptomining and proxy botnet. Secure your deployments now.
Silnikau Sentenced: BitPaymer Ransomware Botnet Operator Receives 2 Years
Russian national Maksim Silnikau sentenced for managing a botnet used in BitPaymer ransomware attacks targeting 72 U.S. companies and demanding $100 million.
TA551 Botnet Operator Sentenced: Analyzing Shathak Ransomware Tactics
Russian national Ilya Angelov sentenced for managing the TA551 botnet, a major facilitator of ransomware attacks via sophisticated phishing campaigns.
AI-Generated Music Fraud: How Bots Siphoned $10M in Royalties
A North Carolina musician pleaded guilty to a $10M fraud scheme using AI bots and automated streaming accounts to exploit major digital music platforms.
Global Law Enforcement Action Disrupts Major IoT DDoS Botnets
Authorities from the US, Germany, and Canada dismantled C2 infrastructure for the Aisuru, KimWolf, JackSkid, and Mossad botnets used in global DDoS attacks.
SocksEscort Proxy Botnet Disrupted: Law Enforcement Seizes 369,000 IPs
International authorities dismantle the SocksEscort proxy botnet, which hijacked 369,000 residential routers across 163 countries for criminal activities.
KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network
The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.
KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet
KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.
Redis RCE Threats Amidst Broader Cyber Landscape
A new wave of cyber threats emerges, headlined by potential Redis RCE vulnerabilities, sophisticated DDR5 bot scalping operations, and escalating privacy concerns.
Analysis of the Kimwolf Botnet and Threat Actor 'Dort'
An analysis of the Kimwolf botnet operator 'Dort', including retaliatory TTPs like DDoS, swatting, and the exploitation of undisclosed vulnerabilities.
Aeternum Loader Employs Polygon Blockchain for Resilient C2
Analysis of the Aeternum botnet loader, which utilizes Polygon smart contracts to host decentralized command-and-control infrastructure for resilience.
Aeternum C2 Leverages Polygon Blockchain for Command-and-Control
Aeternum C2 loader uses the Polygon blockchain to store encrypted instructions, creating a decentralized infrastructure resilient to traditional takedowns.
Kimwolf Botnet Integration Impairs I2P Network Infrastructure
The Kimwolf IoT botnet has weaponized the Invisible Internet Project (I2P) to harden its C2 infrastructure, leading to widespread peer instability and network-wide…