Tag
Disruption of the Sality Peer-to-Peer Botnet
2 TTPs 9 IOCsCrowdStrike and international law enforcement neutralized the long-running Sality P2P botnet, which leveraged polymorphic file infection and decentralized C2 to distribute malicious payloads to over 15,000 infected machines.
Android Automotive Head Units Compromised for Proxy Botnet Enrollment
2 TTPsThreat actors are actively exploiting vulnerabilities in Android-based automotive head units to install malicious software that enrolls the devices into a residential proxy botnet.
Evooo1Bot Modular Linux Botnet
4 TTPsEvooo1Bot is a modular Linux-based botnet that targets internet-facing devices to perform DDoS attacks, SSH brute-forcing, vulnerability exploitation, and SOCKS proxy relay operations.
Kimwolf v7 Botnet Evolution and Android IoT Targeting
5 TTPs 5 IOCsKimwolf v7 is an evolved Android/IoT botnet that leverages unauthenticated ADB access, Ethereum Name Service (ENS) resolution, and HTTP/2 browser fingerprinting to perform resilient DDoS operations.
Aeternum Botnet Leverages Polygon Blockchain for Decentralized C2
1 rule 3 TTPs 3 IOCsAeternum is a C++ botnet loader that utilizes Polygon blockchain smart contracts for resilient, decentralized command-and-control communication and payload delivery.
Astaroth Botnet Deploys New WhatsApp Web Spambot Component
1 rule 9 TTPs 8 IOCsOperators of the Astaroth (aka Guildma) botnet, which targets Brazil-based users, introduced a new spambot component in Q4 2025 that leverages WhatsApp Web in headless browser mode for malware distribution, exhibiting evasion techniques like payload encryption and WebDriver automation indicator stripping.
Russian-Speaking Hacker 'bandcampro' Leverages Google Gemini CLI for Botnet Operations
1 rule 5 TTPsA Russian-speaking threat actor known as 'bandcampro' is using Google's open-source Gemini CLI to manage and control a botnet of eight compromised dental clinic computers, facilitating activities such as password cracking, C2 infrastructure migration, and planning cryptocurrency fraud.
China-Nexus Cyber Actors Using Covert Networks of Compromised Devices
2 rules 4 TTPsChina-nexus cyber actors are increasingly using large-scale networks of compromised devices, including SOHO routers and IoT devices, to obscure the origin of their attacks and conduct various malicious activities, from reconnaissance to data exfiltration.
PowMix Botnet Targeting Czech Workforce
3 rules 5 TTPs 1 IOCThe PowMix botnet campaign targets Czech organizations, particularly HR, legal, and recruitment agencies, using compliance-themed lures delivered via phishing emails, with the attack employing a Windows shortcut file that executes a PowerShell loader to bypass AMSI and deploy the botnet payload in memory.
Disruption of Large IoT DDoS Botnets
2 rules 1 TTPLaw enforcement has disrupted significant IoT botnets responsible for launching record-breaking distributed denial-of-service (DDoS) attacks, impacting the availability of targeted systems.
Iranian Botnet Operation Exposed via Open Directory
1 rule 1 TTP 1 IOCAn Iranian botnet operation utilizing a 15-node relay network and active C2 infrastructure was exposed through an open directory.
KadNap Botnet Targeting Asus Routers
2 rules 1 TTP 2 IOCsThe KadNap botnet is delivering malicious payloads targeting Asus routers, indicated by specific SHA256 hashes of MIPS and ARM binaries.
Katana Mirai Variant Targeting Android TV Devices
2 rules 7 TTPsKatana is a Mirai botnet variant that infects Android TV set-top boxes and compiles its own rootkit for persistence and control.