-
A covert Monero (XMR) cryptomining campaign uncovered in May 2026 is abusing Linux Pluggable Authentication Modules (PAM) to evade detection, maintain fileless execution, and persist across multiple user accounts on compromised hosts. The operation, tr…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A rapidly evolving IoT botnet dubbed “Dysphoria” has emerged as a significant global threat, leveraging blockchain-based domain resolution and a hybrid command-and-control (C2) architecture to sustain large-scale distributed denial-of-service (DDoS) op…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.
·
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In ea…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised en…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
The underground advertisement for the so-called Mycelium Framework reads like another feature‑packed botnet sales pitch: cross‑platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vul…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure origin and extend lateral reach. AryStinger leverages decade‑old v…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


