#Botnetattack
Dutch Authorities Dismantle Massive Botnet Network Linked to 17 Million Compromised Devices #Botnetattack #CyberSecurity #DDOSAttacks
Dutch Authorities Dismantle Massive Botnet Network Linked to 17 Million Compromised Devices
  Dutch authorities have shut down what is believed to be one of the largest botnet operations ever uncovered, disrupting a cybercrime network that compromised more than 17 million internet-connected devices globally. The affected devices reportedly included computers, smartphones, tablets, security cameras, and other connected hardware that were unknowingly used to facilitate large-scale cyberattacks. According to Dutch investigators, approximately 200 servers located in the Netherlands were seized as part of the operation. These servers allegedly formed the backbone of a sophisticated botnet infrastructure that transformed infected devices into components of a residential proxy network. A botnet is a collection of compromised devices that cybercriminals can remotely control after infecting them with malware. Such networks are commonly used to launch Distributed Denial of Service (DDoS) attacks, distribute phishing campaigns, send spam, commit fraud, and conceal the origins of malicious online activities. Dutch media outlet NL Times reported that cybercriminals targeted devices with weak security protections, converting them into nodes within a residential proxy service. Once infected, the devices were used to redirect internet traffic and allegedly help "launch large-scale cyberattacks" without the owners' knowledge. Authorities confirmed that the network has now been taken offline. The investigation began after a cybersecurity researcher working with the National Cyber Security Centre (NCSC) identified suspicious activity linked to the botnet. The NCSC, which operates under the Netherlands' Ministry of Justice and Security, subsequently partnered with Dutch law enforcement agencies to investigate the case. Their efforts led to the identification and seizure of the servers supporting the operation. While authorities have not disclosed the exact method used to infect more than 17 million devices, cybersecurity experts note that botnets are commonly spread through malicious applications, software vulnerabilities, phishing campaigns, and brute-force attacks. The dismantled network has reportedly been linked by NL Times to Asocks, a residential proxy service that has previously faced scrutiny over alleged connections to botnet-related activities. However, Dutch police have not officially confirmed any association. In 2024, cybersecurity company HUMAN reported that a botnet known as Proxylib had infected nearly 190,000 devices and integrated them into Asocks' proxy network. Researchers connected that operation to a discontinued VPN service and at least 28 Android applications. Residential proxy services route internet traffic through the IP addresses of ordinary users, making online activity appear to originate from legitimate residential locations. While such services can have lawful uses, including bypassing geographic restrictions, experts warn that they are increasingly being exploited by cybercriminals. Following the takedown, the NCSC updated its guidance on residential proxy networks and highlighted the risks they pose. In an updated statement, the agency said the enforcement action "demonstrates" how residential proxies pose "a threat to national and international cybersecurity." The agency further warned that the technique is "being deployed more and more frequently in digital attacks," enabling activities such as DDoS attacks, phishing campaigns, credential theft, brute-force attacks, malware distribution, and SMS pumping. The operation reflects a broader international effort to combat cybercrime infrastructure. In March, authorities from Germany, Canada, and the United States coordinated actions against two major botnets known as "Aisuru" and "Kimwolf," which were allegedly responsible for large-scale DDoS attacks. U.S. authorities reported that those networks had compromised more than three million devices. Earlier this year, Google disrupted the IPIDEA proxy network, whose development kits were reportedly used by the Kimwolf botnet. Separately, the Netherlands' Fiscal Information and Investigation Service (FIOD) seized more than 800 servers connected to an illegal hosting platform allegedly used for botnet and malware-related activities. Cybersecurity experts continue to advise users to strengthen their digital defenses by creating strong passwords, regularly updating software, monitoring network activity, enabling WPA2 or WPA3 Wi-Fi security protocols, and avoiding downloads from unverified sources. Users are also encouraged to carefully review application permissions and terms of service to ensure their devices are not unknowingly enrolled in proxy networks. Traditional antivirus protection remains an important layer of defense against evolving cyber threats.
dlvr.it
June 15, 2026 at 5:33 AM
How the AWS Outage Botnet Exposed a Global IoT Weakness That No One Saw Coming #CyberSecurity #IoT #AWSOutage #BotnetAttack
www.squaredtech.co/aws-outage-b...
How The AWS Outage Botnet Exposed A Global IoT Weakness That No One Saw Coming
The AWS outage botnet attack shows how one disruption allowed a Mirai variant to infect devices across 28 countries.
www.squaredtech.co
November 27, 2025 at 4:40 PM
Urgent: D-Link routers under attack from botnets exploiting old vulnerabilities; update your firmware now! #DLink #RouterSecurity #BotnetAttack
D-Link Routers Under Attack By Botnets
Urgent: D-Link routers under attack from botnets exploiting old vulnerabilities; update your firmware now! #DLink #RouterSecurity #BotnetAttack
siliconangle.com
December 28, 2024 at 8:03 AM
🚨Mirai Malware Targets Unpatched TBK DVRs in Global Botnet Campaign🚨 Contact for Security support@wiretor.com

Read: wiretor.com/mirai-botnet...

#MiraiBotnet, #CVE20243721, #IoTSecurity, #CyberSecurity, #DVRExploit, #BotnetAttack, #WireTor, #PenetrationTesting, #ThreatDetection, #InfoSec
Mirai Botnet Exploits TBK DVR Vulnerability (CVE-2024-3721)
A new Mirai botnet variant exploits CVE-2024-3721 to hijack TBK DVR devices via command injection, risking massive IoT attacks. Stay protected
wiretor.com
June 9, 2025 at 7:33 AM
AryStinger Malware Botnet Hijacks Over 4,000 Outdated Routers for Cyberattacks #Botnet #Botnetattack #CyberAttacks
AryStinger Malware Botnet Hijacks Over 4,000 Outdated Routers for Cyberattacks
 AryStinger, a fresh malware botnet, has breached over four thousand aging routers across the globe. Devices caught in its grip now serve as launchpads for online attacks, quietly repurposed without user knowledge. Detected by analysts at Qianxin's XLab division, the threat operates under external direction. Once inside, these systems scan networks - acting as hidden pathways through which data flows undetected. Remote operators exploit them to reroute traffic, build concealed links, or run unauthorized code. Warnings stress continued expansion if neglected. Activity spans continents, tied together by weak firmware defenses. One way hackers advance their goals is by turning weak routers into tools they call “executors,” say experts. Tasks flow from a main control point to these hijacked machines, which then act without owners knowing.  Instead of running scans from one location, criminals spread the work across many devices at once. This method breaks big jobs into tiny pieces, handled quietly by each node in the network. Speed increases because searching happens all over rather than in sequence. Spotting targets becomes smoother when effort scales through scattered access points.  What makes AryStinger especially dangerous isn’t just its role in launching further attacks - it directly threatens device owners too. Because it alters DNS configurations, victims might unknowingly land on harmful sites instead of the ones they intended. Traffic moving through infected routers could be watched or captured at any moment, even when everything seems normal. Personal data, login details, financial records - none are safe once the system is compromised.  Most of the time, it takes advantage of outdated security gaps still present on aging hardware no longer supported by updates. Vulnerabilities like CVE-2013-3307, CVE-2016-5681, and CVE-2025-11837 appear frequently within its attack pattern. Older routers bear the brunt - especially models such as the D-Link DIR-850L and DIR-818LW. Previously, those exact units fell victim to AVrecon, a botnet dismantled by Lumen during 2023. Among affected devices, nearly half belong to users in South Korea - data from XLab indicates 48.5%. Following behind is China, where more than three out of ten infections occur. Smaller shares show up in Sweden, Malaysia, and Singapore. These nations report fewer cases within the overall pattern. One variant of AryStinger was found coded in C, aiming mostly at older router models.  Though less widespread, the second form - built in Go - shifts attention toward network-attached storage systems. This newer edition brings extra functions: it scans IPs and DNS entries, runs commands remotely, drops payloads, explores local networks. Open-source pentesting utilities support these inside-network probes. Each version differs not just in codebase but also in reach and complexity. Despite no evidence yet, experts suggest AryStinger's DNS-scanning setup might enable massive DNS assaults later.  Following infection, the NAS variant allows command execution through Shell, along with support for Go, Java, and Python scripts - opening multiple paths for attacker control. Even after figuring out what the malware can do, XLab scientists mention no connection between AryStinger and recognized hacking groups. Unresolved issues still linger around the botnet - its operators, along with their future aims, stay unclear. Older routers without support draw attention from specialists concerned about safety online.  When devices miss updates, they open doors hackers might walk through. A fresh model often closes those paths by staying current behind the scenes. Firmware kept up to date plays a quiet but vital role in blocking intrusions. Default logins invite trouble - switching them strengthens access control. Remote management, though convenient, widens exposure; turning it off tightens defenses. Each step reduces how easily systems can be taken over.
dlvr.it
June 22, 2026 at 2:34 PM
Global Law Enforcement Disrupts SocksEscort Proxy Network Powered by AVRecon Malware #Botnet #Botnetattack #CyberSecurity
Global Law Enforcement Disrupts SocksEscort Proxy Network Powered by AVRecon Malware
 Federal and regional police units, working alongside independent digital security experts, took down the SocksEscort hacking infrastructure. This setup used hacked gateway gadgets - infected by AVRecon - to route illicit online traffic through hidden channels.  A team at Black Lotus Labs, under Lumen Technologies, aided the takedown operation together with officials from the U.S. Department of Justice. Over multiple years, authorities found the proxy system kept around twenty thousand compromised gadgets active weekly - revealing both reach and staying power.  SocksEscort first came into view back in 2023, though signs point to activity stretching well beyond ten years. Operation relied on offering entry to seemingly legitimate IP addresses - pulled from home and office network devices. Because these connections appeared ordinary, users could mask malicious data flows under normal ISP cover. Detection tools often failed, misled by the everyday digital footprint left behind.  By early 2026, authorities reported the system had provided entry to vast numbers of IP addresses across its lifespan. Nearly 8,000 compromised routers remained operational at that point. Within the U.S., roughly a quarter of those devices were found scattered throughout the country. Though focused on one case, the ripple effects touched various forms of monetary misconduct.  A trail led authorities to connect SocksEscort with nearly $1 million siphoned from digital wallets belonging to someone in New York. Separate findings showed about $700,000 lost due to deceptive schemes targeting an industrial company based in Pennsylvania. Victims among American military personnel also faced damage after personal banking records were breached, adding further strain.  Dozens of domains and servers linked to the network were seized across Europe through joint efforts steered by Europol. Backing came from law enforcement agencies in Austria, France, and the Netherlands. Around $3.5 million in digital currency was blocked during the course of the mission. What powered the entire operation was AVRecon, a form of malicious software aimed at Linux-run home and small office routers.  By June 2023, it had taken hold on over seventy thousand machines, forming a vast network of hijacked devices. This network served one purpose: strengthening the reach of SocksEscort. Analysts found something unusual - none of the affected IPs showed up in unrelated botnet activity, pointing toward tightly managed usage. Despite setbacks during early 2023 that briefly disrupted operations through severed command channels, the group managed recovery by reconstructing systems. Control returned via decentralized nodes rather than a single hub. Activity restarted months afterward with modified communication pathways.  Early in 2025, more than 280,000 distinct IP addresses got caught up in the activity. Although infections spread globally, those based in the U.S. and the U.K. stood out - due to their appeal in hiding harmful network behavior. Outdated routers should be swapped out, many professionals suggest. Firmware updates come next on the list for staying protected. Default login details? Better revise them promptly. Remote functions that go unused tend to invite trouble - shutting those off helps block intrusions. Reducing exposure often begins with these small shifts.  A single operation reveals how digital crime groups using hidden relay systems are expanding their reach. Global teamwork across borders proves essential to weaken such operations.
dlvr.it
March 23, 2026 at 3:44 PM
Palo Alto Detects New Prometei Botnet Attacks Targeting Linux Servers #Botnet #Botnetattack #cryptocurrencymining
Palo Alto Detects New Prometei Botnet Attacks Targeting Linux Servers
Cybersecurity analysts from Palo Alto Networks’ Unit 42 have reported a resurgence of the Prometei botnet, now actively targeting Linux systems with new, upgraded variants as of March 2025. Originally discovered in 2020 when it was aimed at Windows machines, Prometei has since expanded its reach.  Its Linux-based malware strain has been in circulation since late 2020, but recent versions—designated as 3.x and 4.x—demonstrate significant upgrades in their attack capabilities. The latest Prometei malware samples are equipped with remote control functionality, domain generation algorithms (DGA) to ensure connection with attacker-controlled servers, and self-updating systems that help them remain undetected. This renewed activity highlights the botnet’s growing sophistication and persistent threat across global networks.  At its core, Prometei is designed to secretly mine Monero cryptocurrency, draining the resources of infected devices. However, it also engages in credential harvesting and can download additional malicious software depending on the attacker’s goals. Its modular framework allows individual components to carry out specific tasks, including brute-force attacks, vulnerability exploitation (such as EternalBlue and SMB bugs), mining operations, and data exfiltration.  The malware is typically delivered via HTTP GET requests from rogue URLs like hxxp://103.41.204[.]104/k.php. Prometei uses 64-bit Linux ELF binaries that extract and execute payloads directly in memory. These binaries also carry embedded configuration data in a JSON format, containing fields such as encryption keys and tracking identifiers, making them harder to analyze and block.  Once a system is compromised, the malware collects extensive hardware and software information—CPU details, OS version, system uptime—and sends this back to its command-and-control (C2) servers, including addresses like hxxp://152.36.128[.]18/cgi-bin/p.cgi. Thanks to DGA and self-update features, Prometei ensures consistent communication with attacker infrastructure and adapts to security responses on the fly.   To defend against these threats, Palo Alto Networks advises using advanced detection tools such as Cortex XDR, WildFire, and their Advanced Threat Prevention platform. These technologies utilize real-time analytics and machine learning to identify and contain threats. Organizations facing a breach can also contact Palo Alto’s Unit 42 incident response team for expert help.  The activity observed from March to April 2025 underlines the continued evolution of the Prometei botnet and the growing risk it poses to businesses relying on Linux environments. Strengthening cybersecurity protocols and remaining alert to new threats is essential in today’s threat landscape.
dlvr.it
June 30, 2025 at 2:34 PM
CVE-2026-39987 in the marimo Python notebook was exploited within days to deploy an NKAbuse blockchain botnet via a typosquatted HuggingFace Space. Attackers used reverse shells, PostgreSQL/Redis pivots, and credential harvesting. #BotnetAttack #PythonExploit
CVE-2026-39987 update: How attackers weaponized marimo to deploy a blockchain botnet via HuggingFace
Three days after disclosure of a pre-auth remote code execution in the marimo Python notebook platform (GHSA-2679-6mx9-h9xc / CVE-2026-39987), multiple actors exploited the flaw to harvest credentials, run reverse shells, pivot to PostgreSQL/Redis, and deploy a previously undocumented NKAbuse variant hosted on a typosquatted HuggingFace Space. Defenders should look for the VS Code typosquat vsccode-modetx.hf.space, the kagent implant and installer, rotated credentials, and runtime behaviors such as reverse shells and systemd/crontab persistence #NKAbuse #marimo
www.hendryadrian.com
April 16, 2026 at 6:15 AM
Illya Angelov, leader of the Mario Kart botnet, sentenced to 61 months, fined $100K, and ordered to pay $1.6M for infecting 3,000 computers daily and targeting 72 U.S. companies across 31 states. #RansomwareSupply #BotnetAttack #Russia
Head of Russian Cybercrime Group Mario Kart Sentenced for Locking Out Dozens of U.S. Businesses
A federal court sentenced Russian national Illya Angelov for operating the Mario Kart botnet that infected thousands of computers daily and sold backdoor access to ransomware groups, victimizing 72 companies across 31 U.S. states. Angelov pleaded guilty and received a reduced 61-month sentence, a $100,000 fine, and a $1.6 million money...
www.hendryadrian.com
March 25, 2026 at 10:20 AM
CRON#TRAP Malware Hides in Linux VM to Evade Antivirus and Infect Windows Systems
easy4hub.blogspot.com/2024/11/cron...
CRON#TRAP Malware Hides in Linux VM to Evade Antivirus and Infect Windows Systems - Spot
#MalwareVariant #IoTAttack #CloudSecurity #CyberThreat #BotnetAttack #IoTSecurity #Cybersecurity #MalwareAlert #CloudComputing #ThreatIntelligence
easy4hub.blogspot.com
November 9, 2024 at 2:45 AM
New AndroxGh0st Malware Variant Leveraging Mozi Botnet to Attack IoT and Cloud Services
easy4hub.blogspot.com/2024/11/new-...
New AndroxGh0st Malware Variant Leveraging Mozi Botnet to Attack IoT and Cloud Services - Spot
#AndroxGh0st #MoziBotnet #MalwareVariant #IoTAttack #CloudSecurity #CyberThreat #BotnetAttack #IoTSecurity #Cybersecurity #MalwareAlert #CloudComputin
easy4hub.blogspot.com
November 9, 2024 at 2:45 AM