Tag: botnet
-
‘Sandworm’ Chains Cisco Vulnerabilities to Deploy Cyclops Blink
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink
-
Ermittlungen seit 2017 Botnetz nach mehr als zwei Jahrzehnten
Tags: botnetFirst seen on security-insider.de Jump to article: www.security-insider.de/sality-botnetz-p2p-sinkholing-steuerungskanal-lahmgelegt-a-36e8ccaf8837740ebee3c1aad65e699c/
-
Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks
A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash…
-
CrowdStrike Disrupts Sality Botnet After More Than 20 Years
Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know. The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-crowdstrike-sality-botnet-disruption/
-
Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026
Frankfurt am Main, Germany, September 3rd, 2026, CyberNewswire Super-botnets and hijacked cloud servers drive new bandwidth and packet-rate records as international law-enforcement pressure pushes attack counts down Link11 has released its European Cyber Report for the first half of 2026, providing an overview of DDoS attack activity targeting European companies. Although the number of DDoS…
-
Government, industry partner to shut down long-running Sality botnet
A nonprofit group is now working to contact the botnet’s victims. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/doj-crowdstrike-botnet-sality-takedown/829512/
-
International Operation Disrupts Sality P2P Botnet
US-led action sinkholes machines caught up in Sality botnet First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/international-operation-disrupts/
-
Sality P2P Botnet’s Remarkable 23-Year Run Has Come to an End
The Sality P2P botnet, which was first detected in 2003, was finally shut down after a 23-year run, with CrowdStrike using isolation and sinkholes to keep infected systems from communicating with the botnet’s operator. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/sality-p2p-botnets-remarkable-23-year-run-has-come-to-an-end/
-
Global Public-Private Action Disrupts Russia-Linked Sality Botnet
US, European Law Enforcement, Cyber Firms Target Two-Decade-Old P2P Malware Network. U.S. and European authorities, CrowdStrike and Shadowserver disrupted the Russia-linked Sality botnet by exploiting its trusted-peer protocol to isolate roughly 15,000 infected machines and sever a malware network that had operated since 2003. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/global-public-private-action-disrupts-russia-linked-sality-botnet-a-32732
-
CrowdStrike Disrupts Sality Botnet After More Than 20 Years
CrowdStrike and international partners disrupted the 20-year-old Sality botnet, cutting off its operator. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/crowdstrike-disrupts-sality-botnet-after-more-than-20-years/
-
Dogged Russia-based botnet dismantled after 23-year run
Sality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down. First seen on cyberscoop.com Jump to article: cyberscoop.com/sality-botnet-dismantled/
-
Sality, one of the longest-running botnets, finally gets disrupted
U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators. First seen on therecord.media Jump to article: therecord.media/sality-botnet-cyber-doj
-
Tausende Systeme infiziert: Behörden zerschlagen 23 Jahre altes Botnetz
Tags: botnetÜber 15.000 PCs waren zuletzt Teil des seit 2003 aktiven Sality-Botnetzes – darunter auch solche aus Deutschland. Damit ist jetzt Schluss. First seen on golem.de Jump to article: www.golem.de/news/tausende-systeme-infiziert-behoerden-zerschlagen-23-jahre-altes-botnetz-2609-212539.html
-
Global sinkhole operation ends Sality botnet’s 23-year run
Tags: botnetSality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/sality-botnet-disruption-crowdstrike-law-enforcement/
-
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/
-
Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation.The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation.…
-
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Tags: ai, botnet, data-breach, exploit, infrastructure, iot, login, malicious, rce, remote-code-execution, tool, windowsA fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine.The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and…
-
US seizes domains of Chinese botnet used to target NASA, Justice Department, and the Senate
The Justice Department said that the domain seizures made the botnet and its command and control servers “inoperable,” as the domains were hardcoded into the botnet’s code and were critical for the botnet’s communication and essential operations. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
-
Android Malware Hijacks Update System for Car Head Units
Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units
-
US seizes domains of Chinese botnet used to hack NASA, Justice Department, and the Senate
The FBI has seized domains associated with a botnet that allowed Chinese-backed hackers to breach several U.S. government departments. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/26/us-seizes-domains-of-chinese-botnet-used-to-hack-nasa-justice-department-and-the-senate/
-
Car Infotainment Malware Builds Criminal Proxy Botnet
DoFun Software Updates Exploited to Infect Android Head Units. Attackers are exploiting legitimate software updates to infect Android-based car infotainment systems, or head units, turning them into reverse proxies. Kaspersky linked the malware campaign to the MoYu Group, a threat actor linked to BADBOX and BADBOX 2.0. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/car-infotainment-malware-builds-criminal-proxy-botnet-a-32652
-
AI-Assisted ToxNetV2 Linux Botnet Uses LLM to Generate Shell and SSH Commands
ToxNetV2, an AArch64 Linux peer-to-peer botnet, integrates a large language model into its controller workflow to turn botnet and host telemetry into proposed operational actions. The implementation connects NVIDIA NIM-hosted z-ai/glm-5.2 model output to controller-side functions including local shell execution, file writes, remote SSH commands, persistent state changes, and cross-compilation. Analysis published by Joe Reverser…
-
Hackers infecting Android car systems to build proxy botnet
A new strain of malware is being used to infect Android-based car systems, turning the devices into part of a botnet. First seen on therecord.media Jump to article: therecord.media/android-botnet-china-hackers
-
Android car head units infected with proxy botnet malware through built-in software updaters
A newly discovered Android malware, distributed through the built-in updaters in affected Android-based car head units, turns infected devices into ad-fraud tools and nodes in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/24/android-malware-car-head-unit-badbox/
-
Botnetz aus Autos: Fahrzeug-Infotainmentsysteme mit Malware infiziert
Forscher haben eine Android-Malware entdeckt, die über eine Firmware-Updatefunktion in Infotainmentsysteme von Fahrzeugen eingeschleust wurde. First seen on golem.de Jump to article: www.golem.de/news/botnetz-aus-autos-fahrzeug-infotainmentsysteme-mit-malware-infiziert-2608-212212.html
-
First Android Malware Targeting Car Head Units Uses Firmware Updates to Build Proxy Botnet
A multi-stage Android malware campaign that abuses the firmware-update mechanism of Android-based automotive head units to deploy ad-fraud tooling and enroll vehicles into a residential proxy botnet. The activity, discovered in June 2026, is the first documented malware infection chain purpose-built for automotive head units and has been attributed with high confidence to the MoYu…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 111
Tags: banking, botnet, edr, infrastructure, international, linux, malware, ransomware, spyware, windowsSecurity Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Akira Hits Safe Mode: Ransomware Rebooting Around EDR Multi-Functional Linux Botnet “Evooo1Bot” StubMaker RubyGems Campaign Delivers a Windows Infostealer Hunting MacSync Stealer infrastructure through behavioral pivots Manic: Blend between Banking Malware & Spyware […]…
-
New malware targets Android car head units for ad fraud and botnet creation
First seen on scworld.com Jump to article: www.scworld.com/brief/new-malware-targets-android-car-head-units-for-ad-fraud-and-botnet-creation
-
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-with-proxy-botnet-malware/
-
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that’s specifically designed to infect Android-based vehicle head unit firmware developed by DoFun.Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fraud and creation of a proxy botnet.”The malware spread through the…

