BotNet Blog- 2026 2025  2024  2023  2021  2020  2019  2018

AI blog  APT blog  Attack blog  BigBrother blog  BotNet blog  CyberCrime blog  Cyber blog  Cryptocurrency blog  Exploit blog  Hacking blog  ICS blog  Incident blog  IoT blog  Malware blog  OS Blog  Phishing blog  Ransom blog  Safety blog  Security blog  Social blog  Spam blog  Vulnerebility blog 

DATE

NAME

Info

CATEG.

WEB

5.9.26

Introducing More Granular Controls for AI Bot Traffic We’ve updated our Akamai Bot Directory to split the single AI Bots category into three distinct types: AI training crawlers, AI search crawlers, and AI fetchers and agents. BotNet blog AKAMAI

5.9.26

Peer Pressure: Inside the Sality Botnet Disruption Operation CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet. BotNet blog CROWDSTRIKE

29.8.26

What the ERMAC Source Leak Says About HookBot

ERMAC and HookBot are two branches of one Android banking trojan sold as a service. They forked from a shared code base and each evolved in the direction its developers took it, but the core they run is close enough that a single constant in the source decides which name the panel shows.

BotNet blog

CENSYS

29.8.26

Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption

A misconfigured open directory on 86.53.111[.]212:8080 exposed critical details of active cybercrime operator, including Moobot botnet source code, other denial of service (DOS) tools with attack records, and a fraudulent identity verification service – providing a rare view of a malicious operation in progress.

BotNet blog

CENSYS

15.8.26

Multi-Functional Linux Botnet “Evooo1Bot” FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays BotNet blog FORTINET BLOG

15.8.26

Kimwolf v7: An Evolution of the Kimwolf Botnet We identified a new version (v7) of the Kimwolf Android/internet-of-things (IoT) botnet. This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes. BotNet blog Palo Alto

15.8.26

The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Aeternum is a recently discovered C++ botnet loader that shifts its command-and-control (C2) infrastructure entirely to the public Polygon blockchain. Instead of relying on centralized servers or domains, threat actors operate Aeternum by writing encrypted and plaintext instructions directly using smart contracts. A smart contract is a self-executing program stored on a blockchain that automatically runs when specific conditions are met. BotNet blog Palo Alto

1.8.26

Inside Astaroth's New Spambot Component Operators of the Astaroth botnet introduced a new spambot component, a sign of their evolving operations and an expanding LATAM eCrime ecosystem. BotNet blog CROWDSTRIKE

18.6.26

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development We identified a previously undocumented modular internet-of-things (IoT) botnet framework named TuxBot v3 Evolution. BotNet blog Palo Alto
16.5.26 Kazuar: Anatomy of a nation-state botnet  Kazuar, a sophisticated malware family attributed to the Russian state actor Secret Blizzard, has been under constant development for years and continues to evolve in support of espionage-focused operations. BotNet blog Microsoft blog
18.4.26 PowMix botnet targets Czech workforce Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call “PowMix.” BotNet blog CISCO TALOS
11.4.26 Masjesu Rising: The Commercial IoT Botnet Built for Stealth, DDoS, and IoT Evasion Masjesu Botnet: Deep dive into the commercially-run IoT threat, its stealth, multi-XOR evasion, and expanded architecture targets. Secure your network! BotNet blog Trelix
10.1.26 Inside GoBruteforcer: AI-Generated Server Defaults, Weak Passwords, and Crypto-Focused Campaigns GoBruteforcer (also called GoBrut) is a modular botnet, written in Go, that brute-forces user passwords for services such as FTP, MySQL, PostgreSQL, and phpMyAdmin on Linux servers. The botnet spreads through a chain of web shell, downloader, IRC bot, and bruteforcer modules. BotNet blog CHECKPOINT