<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Botnet</title><description>Cybersecurity articles tagged #Botnet on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Android Car Head Unit Malware Spreads via Built-In Updaters</title><link>https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</link><guid isPermaLink="true">https://runtimerebel.com/blog/android-car-head-unit-malware-spreads-via-built-in-updaters</guid><description>Kaspersky discovered a new malware family targeting Android car head units via DoFun firmware updaters to build an ad fraud and proxy botnet.</description><pubDate>Sat, 22 Aug 2026 16:13:11 GMT</pubDate><category>Malware</category><category>Android</category><category>Ad Fraud</category><category>Botnet</category></item><item><title>Evooo1Bot Linux Botnet: Beyond DDoS with Exploits &amp; Credential Theft</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</guid><description>Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.</description><pubDate>Mon, 17 Aug 2026 16:18:57 GMT</pubDate><category>Linux</category><category>Botnet</category><category>DDoS</category><category>Credential Theft</category><category>Evooo1Bot</category></item><item><title>AI-Powered Malware Analysis: Detecting Persistent Threats on Sensors</title><link>https://runtimerebel.com/blog/ai-powered-malware-analysis-detecting-persistent-threats-on-sensors</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-malware-analysis-detecting-persistent-threats-on-sensors</guid><description>An analysis using Gemma4 with Ollama reveals high-volume malware downloads on DShield sensors, indicating persistent actor activity and critical compromise risks.</description><pubDate>Thu, 13 Aug 2026 09:04:55 GMT</pubDate><category>AI</category><category>Malware Analysis</category><category>Threat Hunting</category><category>Botnet</category><category>Cowrie Sensor</category></item><item><title>Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience</title><link>https://runtimerebel.com/blog/kimwolf-v7-botnet-evolves-with-advanced-ddos-and-c2-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-v7-botnet-evolves-with-advanced-ddos-and-c2-resilience</guid><description>Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.</description><pubDate>Tue, 11 Aug 2026 16:52:19 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Android</category><category>DDoS</category><category>IoT</category></item><item><title>Aeternum Botnet Leverages Polygon Blockchain for Resilient C2</title><link>https://runtimerebel.com/blog/aeternum-botnet-leverages-polygon-blockchain-for-resilient-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/aeternum-botnet-leverages-polygon-blockchain-for-resilient-c2</guid><description>Aeternum botnet uses Polygon blockchain smart contracts for C2, making it resilient to takedowns. Security professionals must understand its decentralized operations.</description><pubDate>Tue, 11 Aug 2026 01:00:31 GMT</pubDate><category>Botnet</category><category>Malware</category><category>Aeternum</category><category>Polygon Blockchain</category><category>C2</category></item><item><title>Botnet Targets Diagnostic Tools: Preventing OS Command Injection</title><link>https://runtimerebel.com/blog/botnet-targets-diagnostic-tools-preventing-os-command-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/botnet-targets-diagnostic-tools-preventing-os-command-injection</guid><description>A botnet is actively scanning for vulnerabilities in web-accessible diagnostic tools.</description><pubDate>Tue, 04 Aug 2026 17:32:49 GMT</pubDate><category>Botnet</category><category>Command Injection</category><category>Diagnostic Tools</category><category>OS Command Execution</category><category>Vulnerability Scanning</category></item><item><title>Generic Streaming Sticks: Covert Proxy Networks &amp; Ad Fraud Exposed</title><link>https://runtimerebel.com/blog/generic-streaming-sticks-covert-proxy-networks-ad-fraud-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/generic-streaming-sticks-covert-proxy-networks-ad-fraud-exposed</guid><description>Generic TV streaming sticks are being used in a dual-pronged attack: creating a covert proxy network and engaging in extensive ad fraud through spoofed mobile traffic on…</description><pubDate>Thu, 30 Jul 2026 17:31:49 GMT</pubDate><category>Ad Fraud</category><category>Proxy Network</category><category>Streaming Devices</category><category>Iot Security</category><category>Botnet</category><category>Consumer Devices</category></item><item><title>Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay</title><link>https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</link><guid isPermaLink="true">https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</guid><description>Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.</description><pubDate>Mon, 27 Jul 2026 21:12:36 GMT</pubDate><category>Dysphoria</category><category>Botnet</category><category>DDoS</category><category>Traffic Relay</category><category>Malware</category></item><item><title>Russian-Speaking Hacker Uses Google Gemini CLI for Botnet Control</title><link>https://runtimerebel.com/blog/russian-speaking-hacker-uses-google-gemini-cli-for-botnet-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/russian-speaking-hacker-uses-google-gemini-cli-for-botnet-control</guid><description>Russian-speaking actor bandcampro utilized Google Gemini CLI to automate botnet control and password cracking across compromised dental healthcare systems.</description><pubDate>Mon, 20 Jul 2026 10:55:55 GMT</pubDate><category>Bandcampro</category><category>Google Gemini CLI</category><category>Botnet</category><category>Healthcare Cybersecurity</category><category>AI Threats</category></item><item><title>Hikvision ISAPI Scanning Trends: Analysis and Mitigation Guide</title><link>https://runtimerebel.com/blog/hikvision-isapi-scanning-trends-analysis-and-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/hikvision-isapi-scanning-trends-analysis-and-mitigation-guide</guid><description>Recent honeypot data reveals a surge in probes targeting the Hikvision Intelligent Security API. Learn how to identify and defend against these IoT scans.</description><pubDate>Sun, 19 Jul 2026 17:02:19 GMT</pubDate><category>Hikvision</category><category>ISAPI</category><category>Iot Security</category><category>CVE-2021-36260</category><category>Botnet</category></item><item><title>Google Gemini CLI Abused by &apos;bandcampro&apos; for Botnet Operations</title><link>https://runtimerebel.com/blog/google-gemini-cli-abused-by-bandcampro-for-botnet-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-gemini-cli-abused-by-bandcampro-for-botnet-operations</guid><description>Russian-speaking threat actor &apos;bandcampro&apos; is leveraging Google&apos;s Gemini CLI as a hacking agent and to command a small-scale botnet.</description><pubDate>Wed, 15 Jul 2026 21:05:52 GMT</pubDate><category>Bandcampro</category><category>Google Gemini CLI</category><category>AI Abuse</category><category>Botnet</category><category>Threat Actor</category><category>TTP</category></item><item><title>Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware</title><link>https://runtimerebel.com/blog/compromised-asyncapi-npm-packages-deliver-multi-stage-botnet-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-asyncapi-npm-packages-deliver-multi-stage-botnet-malware</guid><description>Official AsyncAPI npm packages have been compromised to distribute botnet malware. Learn how to detect and mitigate these supply chain attacks.</description><pubDate>Wed, 15 Jul 2026 10:04:34 GMT</pubDate><category>Npm Malware</category><category>Asyncapi</category><category>Supply Chain Attack</category><category>Botnet</category><category>Javascript Security</category></item><item><title>HalluSquatting: AI Coding Assistants Tricked into Botnet Malware</title><link>https://runtimerebel.com/blog/hallusquatting-ai-coding-assistants-tricked-into-botnet-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/hallusquatting-ai-coding-assistants-tricked-into-botnet-malware</guid><description>New HalluSquatting research reveals how attackers can register fake project names hallucinated by AI coding assistants to deploy botnet malware onto developer systems.</description><pubDate>Wed, 08 Jul 2026 17:38:43 GMT</pubDate><category>HalluSquatting</category><category>AI Coding Assistants</category><category>Botnet</category><category>Supply Chain Attack</category><category>Malware</category><category>Developer Tools</category></item><item><title>NetNut Residential Proxy Disrupted: 2M Android Devices Cut Off</title><link>https://runtimerebel.com/blog/netnut-residential-proxy-disrupted-2m-android-devices-cut-off</link><guid isPermaLink="true">https://runtimerebel.com/blog/netnut-residential-proxy-disrupted-2m-android-devices-cut-off</guid><description>A joint operation disrupted NetNut, a residential proxy network leveraging over 2 million compromised Android devices, including smart TVs and streaming boxes.</description><pubDate>Sat, 04 Jul 2026 06:48:52 GMT</pubDate><category>NetNut</category><category>Residential Proxy</category><category>Android Malware</category><category>Botnet</category><category>Proxy Disruption</category><category>Smart TV Security</category></item><item><title>Google Disrupts NetNut Malicious Residential Proxy Network</title><link>https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-disrupts-netnut-malicious-residential-proxy-network</guid><description>Google, in coordination with the FBI and Lumen, has significantly disrupted the NetNut residential proxy network, impacting millions of compromised devices.</description><pubDate>Fri, 03 Jul 2026 07:31:53 GMT</pubDate><category>NetNut</category><category>Residential Proxy</category><category>Botnet</category><category>C2</category><category>Google Play Protect</category><category>Malware</category><category>IPIDEA</category><category>Cybercrime</category><category>Espionage</category></item><item><title>NetNut (Popa) Residential Proxy Disruption: Impact &amp; Defense</title><link>https://runtimerebel.com/blog/netnut-popa-residential-proxy-disruption-impact-defense</link><guid isPermaLink="true">https://runtimerebel.com/blog/netnut-popa-residential-proxy-disruption-impact-defense</guid><description>Google, FBI, and Lumen have disrupted NetNut (Popa), a vast residential proxy network, reducing its pool of compromised home devices by millions.</description><pubDate>Thu, 02 Jul 2026 21:11:17 GMT</pubDate><category>NetNut</category><category>Popa</category><category>Residential Proxy</category><category>Google</category><category>FBI</category><category>Lumen</category><category>Botnet</category><category>Device Compromise</category></item><item><title>Amadey &amp; StealC Malware C2 Infrastructure Disrupted</title><link>https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</link><guid isPermaLink="true">https://runtimerebel.com/blog/amadey-stealc-malware-c2-infrastructure-disrupted</guid><description>Microsoft and global allies dismantle the shared C2 infrastructure of Amadey botnet and StealC info-stealer malware, disrupting ongoing cybercrime operations.</description><pubDate>Wed, 24 Jun 2026 16:52:14 GMT</pubDate><category>Amadey</category><category>StealC</category><category>Malware</category><category>Botnet</category><category>Infostealer</category><category>Cybercrime</category><category>C2 Takedown</category><category>Microsoft</category></item><item><title>AryStinger Botnet: Thousands of D-Link Routers Compromised as Proxies</title><link>https://runtimerebel.com/blog/arystinger-botnet-thousands-of-d-link-routers-compromised-as-proxies</link><guid isPermaLink="true">https://runtimerebel.com/blog/arystinger-botnet-thousands-of-d-link-routers-compromised-as-proxies</guid><description>The AryStinger botnet has compromised over 4,000 D-Link routers, converting them into malicious proxies using automated exploits for end-of-life hardware.</description><pubDate>Sun, 21 Jun 2026 16:38:18 GMT</pubDate><category>AryStinger</category><category>D Link</category><category>Botnet</category><category>Proxy as a Service</category><category>EoL Hardware</category></item><item><title>JDY Botnet Expansion: China-Linked Reconnaissance on SOHO/IoT Devices</title><link>https://runtimerebel.com/blog/jdy-botnet-expansion-china-linked-reconnaissance-on-soho-iot-devices</link><guid isPermaLink="true">https://runtimerebel.com/blog/jdy-botnet-expansion-china-linked-reconnaissance-on-soho-iot-devices</guid><description>China-linked JDY botnet now controls 1,500+ SOHO/IoT devices, actively expanding cyber reconnaissance for state-sponsored operations.</description><pubDate>Wed, 10 Jun 2026 17:13:48 GMT</pubDate><category>JDY</category><category>Botnet</category><category>China</category><category>SOHO</category><category>IoT</category><category>Cyber Reconnaissance</category><category>State Sponsored</category><category>Threat Intelligence</category></item><item><title>C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation</title><link>https://runtimerebel.com/blog/c0xmo-botnet-targets-dd-wrt-router-firmware-analysis-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/c0xmo-botnet-targets-dd-wrt-router-firmware-analysis-and-mitigation</guid><description>C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.</description><pubDate>Sun, 07 Jun 2026 16:34:52 GMT</pubDate><category>C0XMO</category><category>Gafgyt</category><category>DD WRT</category><category>Iot Security</category><category>DDoS</category><category>Botnet</category></item><item><title>Dutch Police Seize 200 Servers to Dismantle 17-Million Device Botnet</title><link>https://runtimerebel.com/blog/dutch-police-seize-200-servers-to-dismantle-17-million-device-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/dutch-police-seize-200-servers-to-dismantle-17-million-device-botnet</guid><description>Dutch authorities and the NCSC dismantled a global botnet affecting 17 million devices. Learn how the seizure of 200 servers impacts global cybercrime operations.</description><pubDate>Sun, 31 May 2026 16:31:15 GMT</pubDate><category>Botnet</category><category>Dutch Politie</category><category>NCSC</category><category>Iot Security</category><category>Infrastructure Takedown</category></item><item><title>Canadian Man Arrested for Kimwolf Botnet Operations</title><link>https://runtimerebel.com/blog/canadian-man-arrested-for-kimwolf-botnet-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/canadian-man-arrested-for-kimwolf-botnet-operations</guid><description>Jacob Butler faces US extradition for operating the Kimwolf botnet. Analysis of the arrest, botnet infrastructure, and its role in the initial access market.</description><pubDate>Fri, 22 May 2026 12:59:57 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Law Enforcement</category><category>Initial Access</category><category>Credential Theft</category></item><item><title>US and Canada Charge Suspected KimWolf Botnet Operator</title><link>https://runtimerebel.com/blog/us-and-canada-charge-suspected-kimwolf-botnet-operator</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-and-canada-charge-suspected-kimwolf-botnet-operator</guid><description>Authorities dismantle the KimWolf botnet following the arrest of a Canadian national linked to nearly two million global device infections and DDoS attacks.</description><pubDate>Fri, 22 May 2026 09:15:50 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>DDoS</category><category>Law Enforcement</category><category>Matthew Filion</category></item><item><title>Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation</title><link>https://runtimerebel.com/blog/kimwolf-botmaster-arrested-impacts-on-iot-botnet-ddos-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botmaster-arrested-impacts-on-iot-botnet-ddos-mitigation</guid><description>Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.</description><pubDate>Fri, 22 May 2026 00:56:39 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Iot Security</category><category>DDoS</category><category>Cyber Arrest</category></item><item><title>Gafgyt and Mirai Variants Target IoT Devices via CVE-2017-17215</title><link>https://runtimerebel.com/blog/gafgyt-and-mirai-variants-target-iot-devices-via-cve-2017-17215</link><guid isPermaLink="true">https://runtimerebel.com/blog/gafgyt-and-mirai-variants-target-iot-devices-via-cve-2017-17215</guid><description>Analysis of Gafgyt and Mirai botnet activity targeting IoT devices through RCE vulnerabilities such as CVE-2017-17215 and CVE-2014-2320.</description><pubDate>Fri, 08 May 2026 08:41:11 GMT</pubDate><category>Gafgyt</category><category>Mirai</category><category>CVE-2017-17215</category><category>Iot Security</category><category>Botnet</category></item><item><title>Infolink Anti-DDoS Provider Linked to Brazilian ISP Botnet Attacks</title><link>https://runtimerebel.com/blog/infolink-anti-ddos-provider-linked-to-brazilian-isp-botnet-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/infolink-anti-ddos-provider-linked-to-brazilian-isp-botnet-attacks</guid><description>An investigation reveals Brazilian anti-DDoS firm Infolink facilitated massive DDoS attacks against regional ISPs, highlighting critical provider trust risks.</description><pubDate>Thu, 30 Apr 2026 16:39:25 GMT</pubDate><category>DDoS</category><category>Brazil</category><category>Infolink</category><category>ISP Security</category><category>Network Abuse</category><category>Botnet</category></item><item><title>Chinese State-Backed Actors Industrialize Botnets for Covert Ops</title><link>https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-state-backed-actors-industrialize-botnets-for-covert-ops</guid><description>Chinese state-backed groups are adopting industrialized botnets, utilizing compromised devices for low-cost, low-risk, and deniable cyber operations.</description><pubDate>Fri, 24 Apr 2026 00:47:01 GMT</pubDate><category>China</category><category>State Backed</category><category>Botnet</category><category>APT</category><category>Cyber Espionage</category><category>Industrialized Botnets</category></item><item><title>SystemBC C2 Analysis: 1,570 Victims of The Gentlemen Ransomware</title><link>https://runtimerebel.com/blog/systembc-c2-analysis-1570-victims-of-the-gentlemen-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/systembc-c2-analysis-1570-victims-of-the-gentlemen-ransomware</guid><description>Analysis of a SystemBC C2 server linked to The Gentlemen ransomware reveals over 1,570 victims and the use of SOCKS5 tunnels for persistent access.</description><pubDate>Tue, 21 Apr 2026 20:22:49 GMT</pubDate><category>SystemBC</category><category>The Gentlemen</category><category>Ransomware</category><category>Botnet</category><category>Check Point</category><category>C2</category></item><item><title>PowMix Botnet Targets Czech Workers via Randomized C2 Traffic</title><link>https://runtimerebel.com/blog/powmix-botnet-targets-czech-workers-via-randomized-c2-traffic</link><guid isPermaLink="true">https://runtimerebel.com/blog/powmix-botnet-targets-czech-workers-via-randomized-c2-traffic</guid><description>Researchers uncover the PowMix botnet targeting the Czech workforce with evasive randomized C2 beaconing to bypass network signature detections.</description><pubDate>Thu, 16 Apr 2026 20:20:25 GMT</pubDate><category>PowMix</category><category>Botnet</category><category>Czech Republic</category><category>Cisco Talos</category><category>C2 Evasion</category><category>PowerShell</category></item><item><title>Compromised DVRs: Identifying and Mitigating IoT Botnet Threats</title><link>https://runtimerebel.com/blog/compromised-dvrs-identifying-and-mitigating-iot-botnet-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-dvrs-identifying-and-mitigating-iot-botnet-threats</guid><description>Explore how Digital Video Recorders (DVRs) are compromised and incorporated into IoT botnets.</description><pubDate>Thu, 16 Apr 2026 00:48:59 GMT</pubDate><category>DVR</category><category>Iot Security</category><category>Botnet</category><category>Shodan</category><category>Compromise</category><category>DDoS</category></item><item><title>Legacy Apache RCE and Hybrid P2P Botnet Resurgence Analysis</title><link>https://runtimerebel.com/blog/legacy-apache-rce-and-hybrid-p2p-botnet-resurgence-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/legacy-apache-rce-and-hybrid-p2p-botnet-resurgence-analysis</guid><description>Exploration of a resurrected 13-year-old Apache RCE and the operational shifts of a hybrid P2P botnet architecture targeting enterprise infrastructure.</description><pubDate>Thu, 09 Apr 2026 16:36:28 GMT</pubDate><category>Apache</category><category>Botnet</category><category>P2P</category><category>Vulnerability Management</category><category>RCE</category></item><item><title>Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy</title><link>https://runtimerebel.com/blog/chaos-malware-variant-targets-cloud-infrastructure-via-socks-proxy</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaos-malware-variant-targets-cloud-infrastructure-via-socks-proxy</guid><description>A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.</description><pubDate>Wed, 08 Apr 2026 20:17:54 GMT</pubDate><category>Chaos Malware</category><category>Cloud Security</category><category>SOCKS Proxy</category><category>Botnet</category><category>Darktrace</category></item><item><title>ComfyUI Instances Abused by Cryptomining Botnet: Mitigation</title><link>https://runtimerebel.com/blog/comfyui-instances-abused-by-cryptomining-botnet-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/comfyui-instances-abused-by-cryptomining-botnet-mitigation</guid><description>Over 1,000 internet-exposed ComfyUI instances are actively targeted by a cryptomining and proxy botnet. Secure your deployments now.</description><pubDate>Tue, 07 Apr 2026 16:28:11 GMT</pubDate><category>ComfyUI</category><category>Cryptomining</category><category>Botnet</category><category>ComfyUI Manager</category><category>Exposed Instances</category><category>Cloud Security</category></item><item><title>Silnikau Sentenced: BitPaymer Ransomware Botnet Operator Receives 2 Years</title><link>https://runtimerebel.com/blog/silnikau-sentenced-bitpaymer-ransomware-botnet-operator-receives-2-years</link><guid isPermaLink="true">https://runtimerebel.com/blog/silnikau-sentenced-bitpaymer-ransomware-botnet-operator-receives-2-years</guid><description>Russian national Maksim Silnikau sentenced for managing a botnet used in BitPaymer ransomware attacks targeting 72 U.S. companies and demanding $100 million.</description><pubDate>Wed, 25 Mar 2026 12:23:52 GMT</pubDate><category>BitPaymer</category><category>Maksim Silnikau</category><category>Ransomware</category><category>Botnet</category><category>Phishing</category></item><item><title>TA551 Botnet Operator Sentenced: Analyzing Shathak Ransomware Tactics</title><link>https://runtimerebel.com/blog/ta551-botnet-operator-sentenced-analyzing-shathak-ransomware-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/ta551-botnet-operator-sentenced-analyzing-shathak-ransomware-tactics</guid><description>Russian national Ilya Angelov sentenced for managing the TA551 botnet, a major facilitator of ransomware attacks via sophisticated phishing campaigns.</description><pubDate>Wed, 25 Mar 2026 12:22:48 GMT</pubDate><category>TA551</category><category>Shathak</category><category>Ransomware</category><category>Botnet</category><category>Ilya Angelov</category></item><item><title>AI-Generated Music Fraud: How Bots Siphoned $10M in Royalties</title><link>https://runtimerebel.com/blog/ai-generated-music-fraud-how-bots-siphoned-10m-in-royalties</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-music-fraud-how-bots-siphoned-10m-in-royalties</guid><description>A North Carolina musician pleaded guilty to a $10M fraud scheme using AI bots and automated streaming accounts to exploit major digital music platforms.</description><pubDate>Fri, 20 Mar 2026 12:18:04 GMT</pubDate><category>Streaming Fraud</category><category>Botnet</category><category>Ai Generated Music</category><category>Platform Abuse</category><category>Michael Smith</category></item><item><title>Global Law Enforcement Action Disrupts Major IoT DDoS Botnets</title><link>https://runtimerebel.com/blog/global-law-enforcement-action-disrupts-major-iot-ddos-botnets</link><guid isPermaLink="true">https://runtimerebel.com/blog/global-law-enforcement-action-disrupts-major-iot-ddos-botnets</guid><description>Authorities from the US, Germany, and Canada dismantled C2 infrastructure for the Aisuru, KimWolf, JackSkid, and Mossad botnets used in global DDoS attacks.</description><pubDate>Fri, 20 Mar 2026 08:17:53 GMT</pubDate><category>AISURU</category><category>Kimwolf</category><category>JackSkid</category><category>Mossad</category><category>IoT</category><category>DDoS</category><category>Botnet</category></item><item><title>SocksEscort Proxy Botnet Disrupted: Law Enforcement Seizes 369,000 IPs</title><link>https://runtimerebel.com/blog/socksescort-proxy-botnet-disrupted-law-enforcement-seizes-369000-ips</link><guid isPermaLink="true">https://runtimerebel.com/blog/socksescort-proxy-botnet-disrupted-law-enforcement-seizes-369000-ips</guid><description>International authorities dismantle the SocksEscort proxy botnet, which hijacked 369,000 residential routers across 163 countries for criminal activities.</description><pubDate>Fri, 13 Mar 2026 08:16:46 GMT</pubDate><category>SocksEscort</category><category>Botnet</category><category>Proxy Service</category><category>DOJ</category><category>Residential Proxies</category></item><item><title>KadNap Botnet: ASUS Routers Hijacked for Faceless Proxy Network</title><link>https://runtimerebel.com/blog/kadnap-botnet-asus-routers-hijacked-for-faceless-proxy-network</link><guid isPermaLink="true">https://runtimerebel.com/blog/kadnap-botnet-asus-routers-hijacked-for-faceless-proxy-network</guid><description>The KadNap botnet hijacks ASUS routers via CVE-2024-3080 to fuel the Faceless proxy service, enabling cybercriminals to mask traffic through residential IPs.</description><pubDate>Tue, 10 Mar 2026 16:28:40 GMT</pubDate><category>KadNap</category><category>ASUS</category><category>CVE-2024-3080</category><category>Botnet</category><category>Proxy as a Service</category></item><item><title>KadNap Malware: 14,000 Asus Routers Enlisted in Stealth Proxy Botnet</title><link>https://runtimerebel.com/blog/kadnap-malware-14000-asus-routers-enlisted-in-stealth-proxy-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/kadnap-malware-14000-asus-routers-enlisted-in-stealth-proxy-botnet</guid><description>KadNap malware has compromised over 14,000 edge devices, primarily Asus routers, to create a massive proxy botnet for anonymizing malicious traffic.</description><pubDate>Tue, 10 Mar 2026 16:26:49 GMT</pubDate><category>KadNap</category><category>ASUS</category><category>Botnet</category><category>Proxy Malware</category><category>Edge Security</category><category>Lumen</category></item><item><title>Redis RCE Threats Amidst Broader Cyber Landscape</title><link>https://runtimerebel.com/blog/redis-rce-threats-amidst-broader-cyber-landscape</link><guid isPermaLink="true">https://runtimerebel.com/blog/redis-rce-threats-amidst-broader-cyber-landscape</guid><description>A new wave of cyber threats emerges, headlined by potential Redis RCE vulnerabilities, sophisticated DDR5 bot scalping operations, and escalating privacy concerns.</description><pubDate>Thu, 05 Mar 2026 16:23:29 GMT</pubDate><category>Redis</category><category>RCE</category><category>Botnet</category><category>DDR5</category><category>Scalping</category><category>Privacy</category><category>Data Tracking</category></item><item><title>Analysis of the Kimwolf Botnet and Threat Actor &apos;Dort&apos;</title><link>https://runtimerebel.com/blog/analysis-of-the-kimwolf-botnet-and-threat-actor-dort</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-the-kimwolf-botnet-and-threat-actor-dort</guid><description>An analysis of the Kimwolf botnet operator &apos;Dort&apos;, including retaliatory TTPs like DDoS, swatting, and the exploitation of undisclosed vulnerabilities.</description><pubDate>Sat, 28 Feb 2026 12:12:58 GMT</pubDate><category>Kimwolf</category><category>Dort</category><category>Botnet</category><category>DDoS</category><category>Swatting</category><category>Threat Actor Profile</category></item><item><title>Aeternum Loader Employs Polygon Blockchain for Resilient C2</title><link>https://runtimerebel.com/blog/aeternum-loader-employs-polygon-blockchain-for-resilient-c2</link><guid isPermaLink="true">https://runtimerebel.com/blog/aeternum-loader-employs-polygon-blockchain-for-resilient-c2</guid><description>Analysis of the Aeternum botnet loader, which utilizes Polygon smart contracts to host decentralized command-and-control infrastructure for resilience.</description><pubDate>Fri, 27 Feb 2026 12:17:37 GMT</pubDate><category>Aeternum</category><category>Polygon</category><category>Blockchain C2</category><category>Botnet</category><category>Stealer</category><category>Smart Contracts</category></item><item><title>Aeternum C2 Leverages Polygon Blockchain for Command-and-Control</title><link>https://runtimerebel.com/blog/aeternum-c2-leverages-polygon-blockchain-for-command-and-control</link><guid isPermaLink="true">https://runtimerebel.com/blog/aeternum-c2-leverages-polygon-blockchain-for-command-and-control</guid><description>Aeternum C2 loader uses the Polygon blockchain to store encrypted instructions, creating a decentralized infrastructure resilient to traditional takedowns.</description><pubDate>Thu, 26 Feb 2026 20:14:47 GMT</pubDate><category>Aeternum C2</category><category>Polygon</category><category>Blockchain Based C2</category><category>Botnet</category><category>Qrator Labs</category></item><item><title>Kimwolf Botnet Integration Impairs I2P Network Infrastructure</title><link>https://runtimerebel.com/blog/kimwolf-botnet-integration-impairs-i2p-network-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botnet-integration-impairs-i2p-network-infrastructure</guid><description>The Kimwolf IoT botnet has weaponized the Invisible Internet Project (I2P) to harden its C2 infrastructure, leading to widespread peer instability and network-wide…</description><pubDate>Mon, 23 Feb 2026 08:21:39 GMT</pubDate><category>IoT</category><category>Botnet</category><category>I2P</category><category>C2</category><category>DDoS</category><category>Anonymization</category></item></channel></rss>