Malware & Threats 23-Year-Old Sality P2P Botnet Disrupted The shutdown operation involved peer list manipulation and Sality payload URL takedown. Ionut ArghireSeptember 2, 2026
IoT Security First Malware Built Specifically for Car Head Units Fuels Botnet Kaspersky researchers have linked the malware to the BadBox botnet, which has ensnared millions of devices. Eduard KovacsAugust 25, 2026
Malware & Threats 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. Ionut ArghireJune 19, 2026
Cybercrime Dutch Police Dismantle Massive 17-Million-Device Botnet Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy... Ionut ArghireJune 1, 2026
Malware & Threats GlassWorm Botnet Disrupted Security firms took down all four command-and-control (C&C) channels used by the GlassWorm malware. Ionut ArghireMay 27, 2026
Cybercrime Canadian Man Arrested for Operating Kimwolf Botnet Jacob Butler, 23, has been arrested in Canada and US authorities are seeking his extradition on computer hacking charges. Eduard KovacsMay 22, 2026
Malware & Threats Mirai Botnet Targets Flaw in Discontinued D-Link Routers The exploitation of the command injection vulnerability started one year after public disclosure and PoC exploit code publication. Ionut ArghireApril 22, 2026
Malware & Threats Evasive Masjesu DDoS Botnet Targets IoT Devices Focused on persistence, the botnet does not engage in widespread infection and avoids blacklisted IPs and critical infrastructure entities. Ionut ArghireApril 8, 2026
Cybercrime Russian Cybercriminal Gets 2-Year Prison Sentence in US Ilya Angelov was a member of the cybercrime group tracked as TA-551, Shathak, Gold Cabin, Monster Libra, and ATK236. Eduard KovacsMarch 25, 2026
Cybercrime Aisuru and Kimwolf DDoS Botnets Disrupted in International Operation The lesser-known JackSkid and Mossad botnets have also been targeted in the operation. Eduard KovacsMarch 20, 2026
Malware & Threats 174 Vulnerabilities Targeted by RondoDox Botnet The botnet has increased its activity, peaking at 15,000 exploitation attempts per day, and taking a more targeted approach. Ionut ArghireMarch 17, 2026
Cybercrime Authorities Disrupt SocksEscort Proxy Service Powered by AVrecon Botnet Law enforcement agencies in the US and Europe targeted the cybercrime service that has impacted 360,000 devices since 2020. Eduard KovacsMarch 13, 2026
Malware & Threats Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience Aeternum operates on smart contracts, making its command-and-control (C&C) infrastructure difficult to disrupt. Ionut ArghireFebruary 27, 2026
Malware & Threats New Keenadu Android Malware Found on Thousands of Devices The malware has been preinstalled on many devices but it has also been distributed through Google Play and other app stores. Eduard KovacsFebruary 18, 2026
Malware & Threats New ‘SSHStalker’ Linux Botnet Uses Old Techniques Estimated to have infected 7,000 systems, the botnet uses a mass-compromise pipeline, deploying various scanners and malware. Ionut ArghireFebruary 10, 2026
Malware & Threats SystemBC Infects 10,000 Devices After Defying Law Enforcement Takedown The malware is known for dropping ransomware and other payloads, and for abusing infected machines to proxy traffic. Ionut ArghireFebruary 5, 2026
Malware & Threats GoBruteforcer Botnet Targeting Crypto, Blockchain Projects The botnet’s propagation is fueled by the AI-generated server deployments that use weak credentials, and legacy web stacks. Ionut ArghireJanuary 13, 2026
Malware & Threats Kimwolf Android Botnet Grows Through Residential Proxy Networks The 2-million-device-strong botnet allows monetization through DDoS attacks, app installs, and the selling of proxy bandwidth. Ionut ArghireJanuary 5, 2026
Malware & Threats RondoDox Botnet Exploiting React2Shell Vulnerability In December, the botnet’s operators focused on weaponizing the flaw to compromise vulnerable Next.js servers. Ionut ArghireJanuary 2, 2026
Malware & Threats ‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices Linked to the Aisuru IoT botnet, Kimwolf was seen launching over 1.7 billion DDoS attack commands and increasing its C&C domain’s popularity. Ionut ArghireDecember 19, 2025