Malware & Threats 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. Ionut ArghireJune 19, 2026
Cybercrime Dutch Police Dismantle Massive 17-Million-Device Botnet Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy... Ionut ArghireJune 1, 2026
Malware & Threats GlassWorm Botnet Disrupted Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware. Ionut ArghireMay 27, 2026
Cybercrime Canadian Man Arrested for Operating Kimwolf Botnet Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. Eduard KovacsMay 22, 2026
Malware & Threats Mirai Botnet Targets Flaw in Discontinued D-Link Routers The exploitation of the command injection vulnerability started one year after public disclosure and PoC exploit code publication. Ionut ArghireApril 22, 2026
Malware & Threats Evasive Masjesu DDoS Botnet Targets IoT Devices Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities. Ionut ArghireApril 8, 2026
Cybercrime Russian Cybercriminal Gets 2-Year Prison Sentence in US Ilya Angelov was a member of the cybercrime group tracked as TA-551, Shathak, Gold Cabin, Monster Libra, and ATK236. Eduard KovacsMarch 25, 2026
Cybercrime Aisuru and Kimwolf DDoS Botnets Disrupted in International Operation The lesser-known JackSkid and Mossad botnets have also been targeted in the operation. Eduard KovacsMarch 20, 2026
Malware & Threats 174 Vulnerabilities Targeted by RondoDox Botnet The botnet has increased its activity, peaking at 15,000 exploitation attempts per day, and taking a more targeted approach. Ionut ArghireMarch 17, 2026
Cybercrime Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet Law enforcement agencies in the US and Europe targeted the cybercrime service that has impacted 360,000 devices since 2020. Eduard KovacsMarch 13, 2026
Malware & Threats Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience Aeternum operates on smart contracts, making its command-and-control (C&C) infrastructure difficult to disrupt. Ionut ArghireFebruary 27, 2026
Malware & Threats New Keenadu Android Malware Found on Thousands of Devices The malware has been preinstalled on many devices but it has also been distributed through Google Play and other app stores. Eduard KovacsFebruary 18, 2026
Malware & Threats New ‘SSHStalker’ Linux Botnet Uses Old Techniques Estimated to have infected 7,000 systems, the botnet uses a mass-compromise pipeline, deploying various scanners and malware. Ionut ArghireFebruary 10, 2026
Malware & Threats SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown The malware is known for dropping ransomware and other payloads, and for abusing infected machines to proxy traffic. Ionut ArghireFebruary 5, 2026
Malware & Threats GoBruteforcer Botnet Targeting Crypto, Blockchain Projects The botnet’s propagation is fueled by the AI-generated server deployments that use weak credentials, and legacy web stacks. Ionut ArghireJanuary 13, 2026
Malware & Threats Kimwolf Android Botnet Grows Through Residential Proxy Networks The 2-million-device-strong botnet allows monetization through DDoS attacks, app installs, and the selling of proxy bandwidth. Ionut ArghireJanuary 5, 2026
Malware & Threats RondoDox Botnet Exploiting React2Shell Vulnerability In December, the botnet’s operators focused on weaponizing the flaw to compromise vulnerable Next.js servers. Ionut ArghireJanuary 2, 2026
Malware & Threats ‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices Linked to the Aisuru IoT botnet, Kimwolf was seen launching over 1.7 billion DDoS attack commands and increasing its C&C domain’s popularity. Ionut ArghireDecember 19, 2025
IoT Security New ‘Broadside’ Botnet Poses Risk to Shipping Companies The botnet attempts to steal credentials from infected TBK DVR devices, in addition to abusing them to launch DDoS attacks. Ionut ArghireDecember 9, 2025
Cybercrime Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps Cloudflare recently mitigated a new record-breaking Aisuru attack that peaked at 14.1 Bpps. Eduard KovacsDecember 5, 2025