botnet

Kimwolf Android Botnet Grows Through Residential Proxy Networks

Kimwolf Android Botnet Grows Through Residential Proxy Networks 2026-01-05 at 14:53 By Ionut Arghire The 2-million-device-strong botnet allows monetization through DDoS attacks, app installs, and the selling of proxy bandwidth. The post Kimwolf Android Botnet Grows Through Residential Proxy Networks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Kimwolf Android Botnet Grows Through Residential Proxy Networks Read More »

RondoDox Botnet Exploiting React2Shell Vulnerability

RondoDox Botnet Exploiting React2Shell Vulnerability 2026-01-02 at 14:42 By Ionut Arghire In December, the botnet’s operators focused on weaponizing the flaw to compromise vulnerable Next.js servers. The post RondoDox Botnet Exploiting React2Shell Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

RondoDox Botnet Exploiting React2Shell Vulnerability Read More »

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices 2025-12-19 at 13:49 By Ionut Arghire Linked to the Aisuru IoT botnet, Kimwolf was seen launching over 1.7 billion DDoS attack commands and increasing its C&C domain’s popularity. The post ‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

‘Kimwolf’ Android Botnet Ensnares 1.8 Million Devices Read More »

V3G4 Botnet Evolves: From DDoS to Covert Cryptomining

V3G4 Botnet Evolves: From DDoS to Covert Cryptomining 2025-12-10 at 08:53 By rohansinhacyblecom Executive Summary Cyble Research & Intelligence Labs (CRIL) has identified an active Linux-targeting campaign that deploys a Mirai-derived botnet, paired with a stealthy, fileless-configured cryptominer. The threat actor employs a multi-stage infection chain starting with a downloader that delivers architecture-specific V3G4 binaries

V3G4 Botnet Evolves: From DDoS to Covert Cryptomining Read More »

New ‘Broadside’ Botnet Poses Risk to Shipping Companies

New ‘Broadside’ Botnet Poses Risk to Shipping Companies 2025-12-09 at 14:08 By Ionut Arghire The botnet attempts to steal credentials from infected TBK DVR devices, in addition to abusing them to launch DDoS attacks. The post New ‘Broadside’ Botnet Poses Risk to Shipping Companies appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

New ‘Broadside’ Botnet Poses Risk to Shipping Companies Read More »

Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps

Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps 2025-12-05 at 13:32 By Eduard Kovacs Cloudflare recently mitigated a new record-breaking Aisuru attack that peaked at 14.1 Bpps. The post Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Aisuru Botnet Powers Record DDoS Attack Peaking at 29 Tbps Read More »

1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium

1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium 2025-11-13 at 17:50 By Eduard Kovacs An individual believed to have been involved in the operation of VenomRAT was arrested recently in Greece. The post 1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium appeared first on SecurityWeek. This article is an

1,000+ Servers Hit in Law Enforcement Takedown of Rhadamanthys, VenomRAT, Elysium Read More »

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks 2025-10-28 at 16:27 By Ionut Arghire A new class of Mirai-based DDoS botnets have been launching massive attacks, but their inability to spoof traffic enables device remediation. The post TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks appeared first on SecurityWeek. This article is an

TurboMirai-Class ‘Aisuru’ Botnet Blamed for 20+ Tbps DDoS Attacks Read More »

RondoDox Botnet Takes ‘Exploit Shotgun’ Approach

RondoDox Botnet Takes ‘Exploit Shotgun’ Approach 2025-10-10 at 15:17 By Ionut Arghire The botnet packs over 50 exploits targeting unpatched routers, DVRs, NVRs, CCTV systems, servers, and other network devices. The post RondoDox Botnet Takes ‘Exploit Shotgun’ Approach appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

RondoDox Botnet Takes ‘Exploit Shotgun’ Approach Read More »

Predicting DDoS attacks: How deep learning could give defenders an early warning

Predicting DDoS attacks: How deep learning could give defenders an early warning 2025-09-25 at 10:12 By Sinisa Markovic Distributed denial-of-service (DDoS) attacks remain one of the most common and disruptive forms of cybercrime. Defenders have traditionally focused on detecting these attacks once they are underway. New research suggests that predicting DDoS attacks in advance may

Predicting DDoS attacks: How deep learning could give defenders an early warning Read More »

Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps

Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps 2025-09-24 at 12:41 By Eduard Kovacs The attack was aimed at a European network infrastructure company and it has been linked to the Aisuru botnet. The post Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps appeared first on SecurityWeek. This article is an

Record-Breaking DDoS Attack Peaks at 22 Tbps and 10 Bpps Read More »

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks 2025-09-23 at 15:39 By Ionut Arghire The botnet’s operators provide customers with access to an infected network of Docker containers so they can conduct DDoS attacks. The post ShadowV2 DDoS Service Lets Customers Self-Manage Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks Read More »

Exposed Docker APIs Likely Exploited to Build Botnet

Exposed Docker APIs Likely Exploited to Build Botnet 2025-09-09 at 17:07 By Ionut Arghire Hackers mount the host’s file system into fresh containers, fetch malicious scripts over the Tor network, and block access to the Docker API. The post Exposed Docker APIs Likely Exploited to Build Botnet appeared first on SecurityWeek. This article is an

Exposed Docker APIs Likely Exploited to Build Botnet Read More »

Alleged Rapper Bot DDoS botnet master arrested, charged

Alleged Rapper Bot DDoS botnet master arrested, charged 2025-08-20 at 21:47 By Zeljka Zorz US federal prosecutors have charged a man with running Rapper Bot, a powerful botnet that was rented out to launch large-scale distributed denial-of-service (DDoS) attacks around the world. According to court documents, 22-year-old Ethan Foltz of Eugene, Oregon, is accused of

Alleged Rapper Bot DDoS botnet master arrested, charged Read More »

RapperBot Botnet Disrupted, American Administrator Indicted

RapperBot Botnet Disrupted, American Administrator Indicted 2025-08-20 at 19:24 By Ionut Arghire The US Department of Justice has announced the takedown of the RapperBot botnet and charges against its American administrator. The post RapperBot Botnet Disrupted, American Administrator Indicted appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

RapperBot Botnet Disrupted, American Administrator Indicted Read More »

Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet

Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet 2025-07-18 at 12:21 By Ionut Arghire Google has filed a lawsuit against the Badbox 2.0 botnet operators, after identifying over 10 million infected Android devices. The post Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet Read More »

Recent Langflow Vulnerability Exploited by Flodrix Botnet

Recent Langflow Vulnerability Exploited by Flodrix Botnet 2025-06-17 at 11:46 By Eduard Kovacs A critical Langflow vulnerability tracked as CVE-2025-3248 has been exploited to ensnare devices in the Flodrix botnet. The post Recent Langflow Vulnerability Exploited by Flodrix Botnet appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Langflow Vulnerability Exploited by Flodrix Botnet Read More »

Recently Disrupted DanaBot Leaked Valuable Data for 3 Years

Recently Disrupted DanaBot Leaked Valuable Data for 3 Years 2025-06-11 at 15:03 By Eduard Kovacs Investigators leveraged a vulnerability dubbed DanaBleed to obtain insights into the internal operations of the DanaBot botnet. The post Recently Disrupted DanaBot Leaked Valuable Data for 3 Years appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Recently Disrupted DanaBot Leaked Valuable Data for 3 Years Read More »

Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016)

Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016) 2025-06-10 at 13:31 By Zeljka Zorz Two Mirai botnets are exploiting a critical remote code execution vulnerability (CVE-2025-24016) in the open-source Wazuh XDR/SIEM platform, Akamai researchers have warned. What is Wazuh? Wazuh is a popular open-source security information and event management (SIEM) and extended detection and response

Unpatched Wazuh servers targeted by Mirai botnets (CVE-2025-24016) Read More »

Scroll to Top