International Law Enforcement Dismantles Sality Botnet
International law enforcement agencies and private cybersecurity partners have seized infrastructure associated with the Sality botnet, one of the longest-running peer-to-peer (P2P) botnets in cybercrime history. The coordinated operation, carried out on…
Cronos Tectonic Exploit Drained 4 Million in 20 Minutes
September 1, 2026 Cronos blockchain halted all transactions on August 30, 2026, after a threat actor exploited the Tectonic lending platform in a $74 million price-manipulation attack. The attacker artificially inflated the price of Tectonic’s…
MoYu Group Deploys Proxy Botnet Malware on Android Car Head Units via DoFun Update App
August 22, 2026 Kaspersky researchers have uncovered a supply-chain attack targeting Android-based car head units that uses a legitimate device-update app to spread proxy botnet malware. The operation, attributed to the MoYu threat actor group, marks the…
Mirai Successor Hijacks Routers for SOCKS5 Proxies and DDoS Attacks
August 15, 2026 A new modular Linux botnet named Evooo1Bot is actively exploiting internet-facing gateway devices across multiple regions. Also, it turns compromised routers and IoT hardware into SOCKS5 proxy relays for concealed malicious traffic. What…
Dysphoria IoT Botnet Hijacks Devices Worldwide
July 28, 2026 A rapidly evolving IoT botnet named Dysphoria has infected an estimated 200,000 devices worldwide. Consequently, defenders must understand its blockchain-based command-and-control architecture and aggressive DDoS capabilities. The botnet…
OkoBot Malware Framework Deploys 20+ Payloads to Steal Crypto and Credentials
July 16, 2026 Kaspersky’s Global Research and Analysis Team has uncovered a sophisticated malware framework called OkoBot that delivers over 20 malicious payloads to steal cryptocurrency wallet seed phrases, browser credentials, and sensitive data.…
NetNut Botnet Disrupted: FBI and Google Cut Off 2 Million Compromised Devices
July 5, 2026 A coordinated operation involving Google, the FBI, and industry partners has disrupted NetNut, one of the largest residential proxy networks in the world. The botnet, also known as Popa, compromised at least 2 million Android devices…
RustDuck Botnet Rebuilds Core in Rust for DDoS Attacks on Routers and Servers
June 30, 2026 A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers to build a distributed denial-of-service (DDoS) botnet. Researchers at QiAnXin’s XLab have tracked it…
AryStinger Botnet Hijacks 4,300 D-Link Routers for Global Proxy Network
June 22, 2026 A previously undocumented malware botnet named AryStinger has compromised more than 4,300 outdated routers worldwide. Unlike typical IoT botnets built for DDoS or cryptocurrency mining, this threat converts infected devices into distributed…
DoJ Disrupts Kimwolf Botnet: 3 Million Devices Behind DDoS Attacks
May 24, 2026 The U.S. Department of Justice announced on March 20, 2026, a major international law enforcement operation that disrupted command-and-control infrastructure powering four massive IoT botnets. This operation successfully dismantled the…