BotNet Blog- 2026 2025 2024 2023 2021 2020 2019 2018
AI blog APT blog Attack blog BigBrother blog BotNet blog CyberCrime blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
DATE | NAME | Info | CATEG. | WEB |
|
5.9.26 |
Introducing More Granular Controls for AI Bot Traffic | We’ve updated our Akamai Bot Directory to split the single AI Bots category into three distinct types: AI training crawlers, AI search crawlers, and AI fetchers and agents. | BotNet blog | AKAMAI |
|
5.9.26 |
Peer Pressure: Inside the Sality Botnet Disruption Operation | CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet. | BotNet blog | CROWDSTRIKE |
|
29.8.26 |
ERMAC and HookBot are two branches of one Android banking trojan sold as a service. They forked from a shared code base and each evolved in the direction its developers took it, but the core they run is close enough that a single constant in the source decides which name the panel shows. |
|||
|
29.8.26 |
Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption |
A misconfigured open directory on 86.53.111[.]212:8080 exposed critical details of active cybercrime operator, including Moobot botnet source code, other denial of service (DOS) tools with attack records, and a fraudulent identity verification service – providing a rare view of a malicious operation in progress. |
||
|
15.8.26 |
Multi-Functional Linux Botnet “Evooo1Bot” | FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays | BotNet blog | FORTINET BLOG |
|
15.8.26 |
Kimwolf v7: An Evolution of the Kimwolf Botnet | We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. | BotNet blog | Palo Alto |
|
15.8.26 |
The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications | Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. | BotNet blog | Palo Alto |
|
1.8.26 |
Inside Astaroth's New Spambot Component | Operators of the Astaroth botnet introduced a new spambot component, a sign of their evolving operations and an expanding LATAM eCrime ecosystem. | BotNet blog | CROWDSTRIKE |
|
18.6.26 |
TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development | We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution. | BotNet blog | Palo Alto |
| 16.5.26 | Kazuar: Anatomy of a nation-state botnet | Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. | BotNet blog | Microsoft blog |
| 18.4.26 | PowMix botnet targets Czech workforce | Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call “PowMix.” | BotNet blog | CISCO TALOS |
| 11.4.26 | Masjesu Rising: The Commercial IoT Botnet Built for Stealth, DDoS, and IoT Evasion | Masjesu Botnet: Deep dive into the commercially-run IoT threat, its stealth, multi-XOR evasion, and expanded architecture targets. Secure your network! | BotNet blog | Trelix |
| 10.1.26 | Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns | GoBruteforcer (also called GoBrut) is a modular botnet, written in Go, that brute-forces user passwords for services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux servers. The botnet spreads through a chain of web shell, downloader, IRC bot, and bruteforcer modules. | BotNet blog | CHECKPOINT |