Tracking & Law Enforcement 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium An individual believed to have been involved in the operation of VenomRAT was arrested recently in Greece. Eduard KovacsNovember 13, 2025
Malware & Threats TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks A new class of Mirai-based DDoS botnets have been launching massive attacks, but their inability to spoof traffic enables device remediation. Ionut ArghireOctober 28, 2025
Malware & Threats RondoDox Botnet Takes ‘Exploit Shotgun’ Approach The botnet packs over 50 exploits targeting unpatched routers, DVRs, NVRs, CCTV systems, servers, and other network devices. Ionut ArghireOctober 10, 2025
Network Security Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps The attack was aimed at a European network infrastructure company and it has been linked to the Aisuru botnet. Eduard KovacsSeptember 24, 2025
Malware & Threats ShadowV2 DDoS Service Lets Customers Self-Manage Attacks The botnet’s operators provide customers with access to an infected network of Docker containers so they can conduct DDoS attacks. Ionut ArghireSeptember 23, 2025
Malware & Threats Exposed Docker APIs Likely Exploited to Build Botnet Hackers mount the host’s file system into fresh containers, fetch malicious scripts over the Tor network, and block access to the Docker API. Ionut ArghireSeptember 9, 2025
Cybercrime RapperBot Botnet Disrupted, American Administrator Indicted The US Department of Justice has announced the takedown of the RapperBot botnet and charges against its American administrator. Ionut ArghireAugust 20, 2025
Malware & Threats Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices. Ionut ArghireJuly 18, 2025
Malware & Threats Prometei Botnet Activity Spikes Palo Alto Networks has observed a spike in Prometei activity since March 2025, pointing to a resurgence of the botnet. Ionut ArghireJune 24, 2025
Malware & Threats Recent Langflow Vulnerability Exploited by Flodrix Botnet A critical Langflow vulnerability tracked as CVE-2025-3248 has been exploited to ensnare devices in the Flodrix botnet. Eduard KovacsJune 17, 2025
Malware & Threats Recently Disrupted DanaBot Leaked Valuable Data for 3 Years Investigators leveraged a vulnerability dubbed DanaBleed to obtain insights into the internal operations of the DanaBot botnet. Eduard KovacsJune 11, 2025
Malware & Threats Mirai Botnets Exploiting Wazuh Security Platform Vulnerability CVE-2025-24016, a critical remote code execution vulnerability affecting Wazuh servers, has been exploited by Mirai botnets. Eduard KovacsJune 9, 2025
IoT Security GreyNoise Flags 9,000 ASUS Routers Backdoored Via Patched Vulnerability Professional hackers have built a network of ASUS routers that can survive firmware upgrades, factory reboots and most anti-malware scans. Ryan NaraineMay 29, 2025
Malware & Threats DanaBot Botnet Disrupted, 16 Suspects Charged The DanaBot botnet ensnared over 300,000 devices and caused more than $50 million in damages before being disrupted. Eduard KovacsMay 23, 2025
Tracking & Law Enforcement US Announces Botnet Takedown, Charges Against Russian Administrators Anyproxy and 5socks, websites offering proxy services through devices ensnared by a botnet, have been disrupted in a law enforcement operation. Eduard KovacsMay 12, 2025
Vulnerabilities Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet The patches for an exploited Samsung MagicINFO vulnerability are ineffective and a Mirai botnet has started targeting it. Ionut ArghireMay 8, 2025
Malware & Threats Europol Targets Customers of Smokeloader Pay-Per-Install Botnet Law enforcement agencies in multiple countries have announced the arrests of users of the malicious Smokeloader botnet. Ionut ArghireApril 10, 2025
Malware & Threats Unpatched Edimax Camera Flaw Exploited Since at Least May 2024 A recently disclosed Edimax zero-day vulnerability has been exploited in the wild by Mirai botnets for nearly a year. Eduard KovacsMarch 13, 2025
Malware & Threats New Ballista IoT Botnet Linked to Italian Threat Actor Cato Networks has analyzed a new IoT botnet named Ballista, which targets TP-Link Archer routers. Eduard KovacsMarch 11, 2025
IoT Security Edimax Says No Patches Coming for Zero-Day Exploited by Botnets Edimax is aware that CVE-2025-1316 has been exploited in the wild, but the impacted devices were discontinued over a decade ago. Eduard KovacsMarch 11, 2025