Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed

T-Mobile physically severed a network cable to stop an active intrusion, a new Linux botnet called Evooo1Bot is spreading across hijacked servers, and Threema's encrypted messaging service was knocked offline by a DDoS attack. Here is what happened.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A technician in a data center cuts through a thick network cable with industrial shears, sparks flying, server racks illuminated in the background during an eme
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • T-Mobile cut a physical network cable to halt an active intrusion, an unusual step that shows how far carriers will go to contain a breach.
  • A new botnet called Evooo1Bot is targeting devices running Linux, the operating system that powers most of the world's internet servers.
  • Threema, an encrypted messaging app popular with privacy-conscious users, was hit by a DDoS attack, meaning criminals flooded its servers with fake traffic to knock the service offline.
  • Crypto4A, a firm that makes hardware security devices, earned a top-tier certification from NIST, the U.S. Government's standards body for technology.

Four stories crossed the radar this week that together show where the cybercrime economy is pressing hardest.

What actually happened in each case?

T-Mobile's response to its intrusion was the most striking. Rather than relying on software alone, the company physically cut a network cable to isolate the attacker. It's a dramatic move, and it confirms the breach was live and moving fast enough that engineers felt they couldn't wait for a software fix.

Separately, Evooo1Bot has been spreading across Linux systems. Linux runs the majority of web servers and cloud platforms globally. When criminals take control of many such machines at once, they form a botnet, a remote-controlled army of hijacked computers used to steal credentials or launch flooding attacks. We reported on 15 August that the Mirai-based malware, built on the same code family behind years of large-scale botnet campaigns, had been hijacking home routers since July to sell as proxies and launch attacks.

Threema's DDoS attack, where criminals fire enormous volumes of junk traffic at a server until it buckles, didn't appear to expose user messages. The app uses end-to-end encryption, meaning messages are scrambled so only sender and recipient can read them. Our 16 August story found the attackers changed tactics repeatedly to slip past defences, targeting both Threema and its Swiss hosting partner Nine. An app that can't connect is an app that can't be used, and that's the point.

On the certification side, Crypto4A received a Level 4 validation under FIPS 140-3, a standard set by NIST that measures how well a hardware security module, a physical device that stores and manages encryption keys, resists tampering. Level 4 is the highest grade available. SecurityWeek flagged the achievement as part of its weekly round-up.

Should ordinary people do anything?

If you use Threema, no immediate action is needed. The DDoS was a disruption, not a data theft. Check that your app is updated.

If your employer runs Linux servers, ask your IT team whether those systems are monitored for unusual outbound traffic, often the first sign a machine has joined a botnet.

T-Mobile customers don't need to act now, but the intrusion is a reminder that large carriers hold significant personal data. Watch your account for unexpected changes to your phone number or billing address.

Story What it is Who is affected
T-Mobile cable cut Active intrusion, physical containment T-Mobile customers and staff
Evooo1Bot botnet Linux malware spreading via hijacked servers Businesses running Linux infrastructure
Threema DDoS Service disruption via traffic flood Threema app users
Crypto4A FIPS 140-3 Level 4 Top government security certification Organisations buying hardware security modules
© 2026 Threat Vectr