Tag

#botnet

23 stories taggedbotnet.

An FBI field office with law enforcement and cyber agents gathered around seized server equipment, network diagrams showing connections to targeted government a
Threat Intelligence

The US just seized the servers behind China's hacking-for-hire empire

A private Chinese company quietly ran shared attack tools for state hackers targeting NASA, the Federal Reserve, and US hospitals. The FBI just pulled the plug.

5 min read
A multinational cybercrime task force headquarters with computers displaying botnet network topology maps, infected nodes being systematically disconnected and
Threat Intelligence

Police Hijack Sality Botnet's Own Network to Kill It Off

A four-country operation used the malware's peer-to-peer design against it, blocking infected computers from receiving fresh criminal payloads.

4 min read
A network security dashboard showing multiple simultaneous attack patterns—botnet activity, fake login attempts, and exploit chains—converging on infrastructure
Threat Intelligence

The Week in Threats: Fake Logins, AI-Powered Botnets, and Shrinking Patch Windows

A 296,000-device botnet, water utilities under scan, and an actively exploited SharePoint chain: this week's pattern is old tricks moving faster.

4 min read
A car dashboard infotainment system screen showing an update notification and suspicious network activity, with the vehicle's interior visible around it
Threat Intelligence

New Android malware slips into cars through the dashboard's own update system

Kaspersky says the DoFun head unit malware turns infected vehicles into ad-fraud engines and proxy relays for cybercrime.

4 min read
A technician in a data center cuts through a thick network cable with industrial shears, sparks flying, server racks illuminated in the background during an eme
Threat Intelligence

Zombie Cards, Cut Cables, and a Botnet: The Week's Cybercrime Stories You May Have Missed

T-Mobile physically severed a network cable to stop an active intrusion, a new Linux botnet called Evooo1Bot is spreading across hijacked servers, and Threema's encrypted messaging service was knocked offline by a DDoS attack. Here is what happened.

3 min read
A cybersecurity researcher's desk with investigation files spread out, a security camera image displayed on monitor, directory structure and authentication logs
Threat Intelligence

Researchers Say 14,500 Dahua Cameras Fell to a Six-Week Hijack Campaign

Hunt.io traced Operation CameraSwarm through an exposed 407 MB working directory, revealing password guessing, two authentication-bypass flaws, and a peer-to-peer relay trick.

3 min read
Array of home networking routers stacked and arranged on shelves in a data center environment, their status lights blinking in an unsynchronized pattern suggest
Threat Intelligence

New Evooo1Bot malware is quietly turning home routers into criminal traffic relays

Researchers say the Mirai-based botnet has been hijacking gateway devices since July to sell as proxies, steal credentials, and launch attacks.

4 min read
Network traffic visualization showing data streams disguised as normal HTTP/2 sessions, with hidden malicious packets highlighted within legitimate-looking web
Threat Intelligence

New Kimwolf v7 Botnet Disguises DDoS Attacks as Normal Web Traffic

Palo Alto Networks says the upgraded Android and smart-device botnet hides its floods inside HTTP/2 sessions that look like ordinary browsing.

3 min read
A collection of small Android TV streaming sticks arranged on a desk with a computer showing ad-fraud traffic analytics and suspicious network activity maps to
Threat Intelligence

Cheap TV streaming sticks are secretly clicking ads and pretending to be phones

Researchers say around 38,000 H96 Android TV boxes are pulling double duty as ad-fraud bots and residential proxies, funnelling roughly $50,000 a day to a mainland China outfit called the Fengwo Group.

4 min read
A network operations center with multiple server racks, one machine rebooting with lights cycling through red and amber, an engineer's hand frozen mid-gesture n
Threat Intelligence

Tengu Botnet Turns Linux Devices Against Their Own Defenders

A new Mirai spin-off reboots infected machines when responders try to shut it down, giving its persistence tricks another shot at survival.

3 min read
Network infrastructure visualization showing IoT devices interconnected with blockchain node indicators, control traffic routing through infected endpoints with
Threat Intelligence

Dysphoria Botnet Rebuilds on Blockchain After March Takedown

Researchers at CNCERT and XLab say the IoT botnet now hides its control servers behind blockchain domains and routes traffic through infected devices, making shutdowns harder.

4 min read
Illustration: a dimly lit server rack in a data centre, one panel glowing with a soft green status light
AI Security

NadMesh Botnet Is Quietly Raiding Unprotected AI Servers for Cloud Keys

A new Go-based botnet is scanning the internet for popular AI tools left exposed online, and its own dashboard brags about nearly 4,000 stolen Amazon cloud keys.

3 min read
Illustration: a cluttered desk with a small home Wi-Fi router glowing faintly, tangled ethernet cables
Threat Intelligence

A Botnet Author Asked an AI for Malware. The AI Left the Warning Label On.

Researchers found TuxBot v3 Evolution, a new IoT botnet whose creator appears to have copy-pasted AI-generated code, safety disclaimer and all.

3 min read
Illustration: a dim dental clinic reception at night
AI Security

A Russian-speaking hacker turned Google's Gemini CLI into his botnet co-pilot

For roughly a year, an attacker chatted with Google's open-source AI tool to run malware on eight computers inside a dental clinic, migrate his servers, and troubleshoot bugs in six minutes flat.

4 min read
Illustration: A dim school computer lab at dusk, rows of identical monitors glowing with abstract blue browser windows
Threat Intelligence

Fake Student Proxies on npm Turned Browsers Into a DDoS Weapon

JFrog researchers say 148 malicious packages used npm as free hosting for a booby-trapped proxy site, quietly enlisting students' browsers into an attack campaign that ran for roughly two weeks in May 2024.

3 min read
© 2026 Threat Vectr