Botnet 2025     2026(4)  2025(24)  2024(15)  2023(5)  2022(11)

DATE

NAME

INFO

CATEGORY

SUBCATE

18.12.25

Kimwolf

Kimwolf Exposed: The Massive Android Botnet with 1.8 Million Infected Devices

BOTNET BOTNET
6.12.25 V3G4 Botnet CRIL has uncovered an active V3G4 campaign using a Mirai-derived botnet alongside a fileless, runtime-configured cryptominer. BOTNET BOTNET
4.12.25 Cloudflare's 2025 Q3 DDoS threat report --
including Aisuru, the apex of botnets
Welcome to the 23rd edition of Cloudflare’s Quarterly DDoS Threat Report. This report offers a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network. In this edition, we focus on the third quarter of 2025. BOTNET BOTNET
29.11.25 ShadowV2 At the end of October, during a global disruption of AWS connections, FortiGuard Labs observed malware named “ShadowV2” spreading via IoT vulnerabilities. These incidents affected multiple countries worldwide and spanned seven different industries. BOTNET BOTNET
21.11.25 ShadowRay 2.0 ShadowRay 2.0: Attackers Turn AI Against Itself in Global Campaign that Hijacks AI Into Self-Propagating Botnet BOTNET BOTNET
21.11.25 Tsundere Blockchain and Node.js abused by Tsundere: an emerging botnet BOTNET BOTNET
20.11.25 AISURU The Most Powerful Ever? Inside the 11.5Tbps-Scale Mega Botnet AISURU BOTNET BOTNET
23.9.25 ShadowV2 ShadowV2: An emerging DDoS for hire botnet BOTNET BOTNET
20.9.25 SystemBC The Black Lotus Labs team at Lumen Technologies has uncovered new infrastructure behind the “SystemBC” botnet, a network composed of over 80 C2s with a daily average of 1,500 victims, nearly 80% of which are compromised VPS systems from several large commercial providers. BOTNET BOTNET
17.9.25 LunoBotnet LunoBotnet: A Self-Healing Linux Botnet with Modular DDoS and Cryptojacking Capabilities BOTNET CRYPTOCURRENCY
2.9.25 PolarEdge Pondering my ORB - A look at PolarEdge Adjacent Infrastructure BOTNET IoT
8.7.25 RondoDox RondoDox Unveiled: Breaking Down a New Botnet Threat BOTNET BOTNET
21.6.25 Prometei Resurgence of the Prometei Botnet BOTNET BOTNET
20.6.25 AntiDot is an Android botnet malware that lets cybercriminals control their victim devices with high capability. LARVA-398 operates and sells this botnet as a Malware as a Service (MaaS) on underground forums. BOTNET BOTNET
1.6.25 PumaBot PumaBot: Novel Botnet Targeting IoT Surveillance Devices BOTNET BOTNET
28.5.25 PumaBot PumaBot: Novel Botnet Targeting IoT Surveillance Devices BOTNET BOTNET
16.5.24 HTTPBot High Risk Warning for Windows Ecosystem: New Botnet Family HTTPBot is Expanding BOTNET BOTNET
23.4.25 RustoBot New Rust Botnet "RustoBot" is Routed via Routers BOTNET Bot
10.4.25 AkiraBot AkiraBot | AI-Powered Bot Bypasses CAPTCHAs, Spams Websites At Scale BOTNET AI

19.3.25

BADBOX 2.0 Satori Threat Intelligence Disruption: BADBOX 2.0 Targets Consumer Devices with Multiple Fraud Schemes BOTNET BOTNET
11.3.25 Ballista Botnet Cato CTRL™ Threat Research: Ballista – New IoT Botnet Targeting Thousands of TP-Link Archer Routers BOTNET BOTNET
3.3.25 Vo1d Botnet Long Live The Vo1d Botnet: New Variant Hits 1.6 Million TV Globally BOTNET BOTNET
27.2.25 PolarEdge PolarEdge: Unveiling an uncovered ORB network BOTNET BOTNET

10.1.25

Gayfemboy Gayfemboy: A Botnet Deliver Through a Four-Faith Industrial Router 0-day Exploit. BOTNET BOTNET