Skip to content
Threat Feed

Tag

Botnet

13 briefs RSS
high threat

Disruption of the Sality Peer-to-Peer Botnet

CrowdStrike and international law enforcement neutralized the long-running Sality P2P botnet, which leveraged polymorphic file infection and decentralized C2 to distribute malicious payloads to over 15,000 infected machines.

SALTY SPIDER botnet p2p malware file-infection counter-adversary-operations
2t 9i
medium advisory

Android Automotive Head Units Compromised for Proxy Botnet Enrollment

Threat actors are actively exploiting vulnerabilities in Android-based automotive head units to install malicious software that enrolls the devices into a residential proxy botnet.

Android Automotive android botnet proxy automotive
2t
medium advisory

Evooo1Bot Modular Linux Botnet

Evooo1Bot is a modular Linux-based botnet that targets internet-facing devices to perform DDoS attacks, SSH brute-forcing, vulnerability exploitation, and SOCKS proxy relay operations.

botnet linux ddos ssh-brute-force proxy
4t
high advisory

Kimwolf v7 Botnet Evolution and Android IoT Targeting

Kimwolf v7 is an evolved Android/IoT botnet that leverages unauthenticated ADB access, Ethereum Name Service (ENS) resolution, and HTTP/2 browser fingerprinting to perform resilient DDoS operations.

Android TV box +1 iot botnet android ddos
5t 5i updated
high advisory

Aeternum Botnet Leverages Polygon Blockchain for Decentralized C2

Aeternum is a C++ botnet loader that utilizes Polygon blockchain smart contracts for resilient, decentralized command-and-control communication and payload delivery.

botnet blockchain C2 malware execution persistence
1r 3t 3i
high threat

Astaroth Botnet Deploys New WhatsApp Web Spambot Component

Operators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.

Windows +5 Astaroth botnet malware spambot latin-america
1r 9t 8i updated
high threat

Russian-Speaking Hacker 'bandcampro' Leverages Google Gemini CLI for Botnet Operations

A Russian-speaking threat actor known as 'bandcampro' is using Google's open-source Gemini CLI to manage and control a botnet of eight compromised dental clinic computers, facilitating activities such as password cracking, C2 infrastructure migration, and planning cryptocurrency fraud.

OpenDental bandcampro ai-assisted botnet cybercrime command-and-control powershell credential-access
1r 5t
high threat

China-Nexus Cyber Actors Using Covert Networks of Compromised Devices

China-nexus cyber actors are increasingly using large-scale networks of compromised devices, including SOHO routers and IoT devices, to obscure the origin of their attacks and conduct various malicious activities, from reconnaissance to data exfiltration.

SOHO Routers +5 China-nexus cyber actors covert-network botnet china-nexus compromised-devices
2r 4t
medium advisory

PowMix Botnet Targeting Czech Workforce

The PowMix botnet campaign targets Czech organizations, particularly HR, legal, and recruitment agencies, using compliance-themed lures delivered via phishing emails, with the attack employing a Windows shortcut file that executes a PowerShell loader to bypass AMSI and deploy the botnet payload in memory.

powmix botnet czech-republic heroku
3r 5t 1i
high advisory

Disruption of Large IoT DDoS Botnets

Law enforcement has disrupted significant IoT botnets responsible for launching record-breaking distributed denial-of-service (DDoS) attacks, impacting the availability of targeted systems.

iot ddos botnet disruption
2r 1t
medium advisory

Iranian Botnet Operation Exposed via Open Directory

An Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.

botnet iran C2
1r 1t 1i
high advisory

KadNap Botnet Targeting Asus Routers

The KadNap botnet is delivering malicious payloads targeting Asus routers, indicated by specific SHA256 hashes of MIPS and ARM binaries.

Routers botnet router kadnap
2r 1t 2i
high advisory

Katana Mirai Variant Targeting Android TV Devices

Katana is a Mirai botnet variant that infects Android TV set-top boxes and compiles its own rootkit for persistence and control.

Android TV mirai botnet android rootkit
2r 7t