Tag: botnet
-
Dysphoria Botnet Uses Blockchain Domains to Hide C2 Infrastructure
Researchers uncovered the 200,000-device Dysphoria botnet, which uses Ethereum and Solana domains to hide its command servers. QiAnXin XLab, jointly with China’s CNCERT, disclosed Dysphoria, a botnet that has compromised roughly 200,000 devices worldwide and uses Ethereum and Solana blockchain domain names to hide its command infrastructure. The botnet evolved from jackskid and fbot malware…
-
Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process
A new Mirai-derived botnet called Tengu can use a compromised Linux device’s hardware watchdog to trigger a reboot when defenders kill its main process.If that happens, Tengu’s other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dropper reaching its honeypots through Telnet credential brute force.Tengu supports 25 distributed denial-of-service (…
-
Tengu Mirai Botnet Uses Watchdog Reboots and Binary Bricking to Resist Removal
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while…
-
Dysphoria IoT Botnet Uses Blockchain Domains and 200,000 Devices for DDoS Attacks
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) operations. Dysphoria’s evolution has been unusually aggressive, transitioning from early jackskid-derived variants to more sophisticated fbot-based implementations within weeks. Initial samples observed in March 2026…
-
Botnets powered by residential proxy networks are growing
First seen on scworld.com Jump to article: www.scworld.com/brief/botnets-powered-by-residential-proxy-networks-are-growing
-
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/
-
Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption
Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement operation against JackSkid infrastructure. The researchers say the design makes the botnet harder to disrupt.CNCERT, China’s national computer emergency response team, and XLab, the threat-intelligence lab of Chinese First seen…
-
Despite multiple takedowns, botnets continue to grow
Tags: botnetRoughly 1 in 4 of those compromised IPs are based in the United States, Lumen’s Black Lotus Labs said. Botnets like IPIDEA have also rebounded quickly, surpassing their pre-disruption footprint. First seen on cyberscoop.com Jump to article: cyberscoop.com/botnets-residential-proxy-networks-proliferate-lumen-black-lotus-labs/
-
Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps…
-
NadMesh-Botnetz stiehlt Cloud-Zugänge über KI-Dienste
Das neue Go-Botnetz NadMesh sucht nach ungeschützten KI-Diensten, um AWS-Zugangsdaten und Kubernetes-Token aus den Systemen zu entwenden. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/nadmesh-botnetz-cloud-zugaenge
-
KI-generierter Quellcode bei neuem Botnetz TuxBot v3 entdeckt
Sicherheitsforscher haben das IoT-Botnetz-Framework TuxBot v3 Evolution entdeckt. Es wurde nachweislich unter Einsatz von künstlicher Intelligenz entwickelt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/ki-generierter-quellcode-botnetz
-
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things,…
-
Gemini CLI missbraucht: KI baut Botnetz in nur sechs Minuten
Trend Micro zeigt, wie ein Hacker Gemini CLI missbrauchte und mit KI ein Botnetz in nur sechs Minuten migrierte. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/kuenstliche-intelligenz/gemini-cli-missbraucht-ki-baut-botnetz-in-sechs-minuten-331606.html
-
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys.A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and…
-
New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure
NadMesh is a new, industrial”‘grade Go”‘based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed”‘loop platform. In early July 2026, researchers identified NadMesh as a high”‘volume Go-written botnet that was aggressively deploying bot agents across internet”‘facing…
-
Hacker missbraucht Googles Gemini CLI zur Botnetz-Steuerung
Ein russischsprachiger Cyberkrimineller hat Googles KI-Tool Gemini CLI als autonomen Hacking-Agenten zur Steuerung eines Botnetzes missbraucht. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/hacker-missbraucht-gemini
-
TuxBot v3: The IoT Botnet Built With AI Bugs, Disclaimers and All
TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions…
-
Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes
A Russian-speaking threat actor known as >>bandcampro<< used a jailbroken Gemini CLI, Google's open-source terminal-based AI agent, to deploy and operate a … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/
-
148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet
A campaign of 148 npm packages disguised as student web proxies turned visitors’ browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site…
-
Gefälschte 7-Zip-Installer schleusen Proxy-Malware ein
Die Hackergruppe Lurking Lizard infiziert Geräte über gefälschte 7-Zip-Installer, um sie heimlich in ein kommerzielles Proxy-Botnetz zu integrieren. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/gefaelschte-7-zip-installer
-
HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers
A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale. The research introduces “adversarial hallucination squatting,” a novel method that exploits AI models that generate…
-
New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist.New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register…
-
AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts
The underground advertisement for the so-called Mycelium Framework reads like another feature”‘packed botnet sales pitch: cross”‘platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability”‘aware. AI compute…
-
Hackers can use 9 of the most popular AI tools to assemble massive botnets
“HalluSquatting” weaponizes LLMs’ inability to say “I don’t know.” First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/07/hackers-can-use-9-of-the-most-popular-ai-tools-to-assemble-massive-botnets/
-
âš¡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary.Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems…
-
Google und FBI zerschlagen Riesen-Botnetz NetNut
Gemeinsam mit dem FBI hat Google das NetNut-Botnetz mit rund zwei Millionen Geräten blockiert, das von Hunderten Hackergruppen zur Tarnung genutzt wurde. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/botnetz-netnut-google-fbi
-
FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors
The NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnets First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/fbi-google-take-down-netnut-proxy/
-
Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks
Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to…
-
RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow
RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk…
-
New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection strategy combining weak password attacks against Telnet and SSH services with exploitation of known RCE…

