Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed

A DDoS attack on encrypted messaging app Threema, a new Linux botnet called Evooo1Bot, and T-Mobile physically severing a cable to stop an intrusion all made news this week. Here is what happened.

ThreatVectr Newsdesk· 3 min read
Aerial view, 16:9 framing, photoreal editorial style, a dense suburban neighbourhood at dusk with hundreds of softly glowing house windows, each window subtly e
Share

Key points

  • T-Mobile cut a physical network cable to halt an active hacker intrusion, an unusual step that shows how far carriers will go to contain a breach.
  • A new botnet called Evooo1Bot is targeting devices running Linux, the operating system that powers most of the world's internet servers.
  • Threema, an encrypted messaging app popular with privacy-conscious users, was hit by a DDoS attack, meaning criminals flooded its servers with fake traffic to knock the service offline.
  • Crypto4A, a firm that makes hardware security devices, earned a top-tier certification from NIST, the U.S. government's standards body for technology.

Four stories crossed the radar this week that, taken together, paint a useful picture of where the cybercrime economy is pressing hardest.

What actually happened in each case?

T-Mobile's response to its intrusion was the most striking. Rather than relying on software alone, the company physically cut a network cable to isolate the attacker. That is a dramatic move. It also confirms the breach was live and moving fast enough that engineers felt they could not wait for a software fix.

Separately, a new piece of malware called Evooo1Bot has been spreading across Linux systems. Linux runs the majority of web servers, cloud platforms, and internet-connected devices globally. When criminals take control of many such machines at once, they form a botnet, a remote-controlled army of hijacked computers typically used to send spam, steal data, or launch the kind of flooding attacks that hit Threema this week.

Threema's DDoS attack, where criminals fire enormous volumes of junk internet traffic at a server until it buckles under the load, did not appear to expose user messages. The app uses end-to-end encryption, meaning messages are scrambled so that only sender and recipient can read them. Still, an app that cannot connect is an app that cannot be used.

On the certification side, Crypto4A received a Level 4 validation under FIPS 140-3, a standard set by NIST that measures how well a hardware security module, a physical device that stores and manages encryption keys, resists tampering. Level 4 is the highest grade available. SecurityWeek flagged the achievement as part of its weekly round-up.

Should ordinary people do anything?

If you use Threema, no immediate action is needed. The DDoS attack was a disruption, not a data theft. Check that your app is updated.

If your employer runs Linux servers, this week is a reasonable moment to ask your IT team whether those systems are monitored for unusual outbound traffic, which is often the first sign a machine has joined a botnet.

Customers of T-Mobile do not need to act right now, but the intrusion is a reminder that large carriers hold significant personal data. Watching your account for unexpected changes to your phone number or billing address is always sensible.

Story What it is Who is affected
T-Mobile cable cut Active intrusion, physical containment T-Mobile customers and staff
Evooo1Bot botnet Linux malware spreading via hijacked servers Businesses running Linux infrastructure
Threema DDoS Service disruption via traffic flood Threema app users
Crypto4A FIPS 140-3 Level 4 Top government security certification Organisations buying hardware security modules
© 2026 Threat Vectr