#Botnets

2025-05-23

Feds Charge 16 #Russians Allegedly Tied to #Botnets Used in #Ransomware , #Cyberattacks , and #Spying

A new US #indictment against a group of Russian nationals offers a clear example of how, authorities say, a single #malware operation can enable both criminal and state-sponsored #hacking.
#russia

wired.com/story/us-charges-16-

Manuel 'HonkHase' AtugHonkHase@chaos.social
2025-05-23

Feds Charge 16 Russians Allegedly Tied to #Botnets Used in #Ransomware, Cyberattacks, and #Spying

"A new US indictment against a group of Russian nationals offers a clear example of how, authorities say, a single #malware operation can enable both criminal and state-sponsored hacking."
wired.com/story/us-charges-16-

2025-05-22

Krebs on Security: KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS. “KrebsOnSecurity last week was hit by a near record distributed denial-of-service (DDoS) attack that clocked in at more than 6.3 terabits of data per second (a terabit is one trillion bits of data). The brief attack appears to have been a test run for a massive new Internet of Things (IoT) botnet capable of launching […]

https://rbfirehose.com/2025/05/22/krebs-on-security-krebsonsecurity-hit-with-near-record-6-3-tbps-ddos/

2025-05-14

The Register: Feds disrupt proxy-for-hire botnet, indict four alleged net miscreants. “Earlier this week, the FBI urged folks to bin aging routers vulnerable to hijacking, citing ongoing attacks linked to TheMoon malware. In a related move, the US Department of Justice unsealed indictments against four foreign nationals accused of running a long-running proxy-for-hire network that exploited […]

https://rbfirehose.com/2025/05/14/the-register-feds-disrupt-proxy-for-hire-botnet-indict-four-alleged-net-miscreants/

2025-05-13

The FBI has issued an alert about cybercriminals hijacking outdated routers to power massive proxy-for-hire networks—masking malware, fraud, and credential theft right under your nose.

Watch the full Cyberside Chats episode to hear @sherridavidoff and @MDurrin 's insights on:

🔹 The FBI’s May 2025 alert
🔹 TheMoon malware and the Faceless proxy service
🔹 What these botnets mean for your enterprise
🔹 What you need to do now to stay protected

🎥 Watch the video: youtu.be/x_40BlvWsHk
🎧 Listen to the podcast: chatcyberside.com/e/outdated-r

#Cybersecurity #RouterSecurity #ThreatIntel #Malware #CISO #CybersideChats #ProxyAbuse #TheMoonMalware #Botnets #NetworkSecurity #CISO #Cyberaware #Tech #Infosec #IT #CIO #SMB #Cyber

2025-05-08

Could your old router be an unwitting accomplice to cybercrime? The FBI warns outdated devices are turning into secret proxy networks for hackers. Time to consider an upgrade?

thedefendopsdiaries.com/exploi

#cybersecurity
#endofliferouters
#themoonmalware
#botnets
#fbiresponse

Global Threadsglobalthreads
2025-04-05

🤖 CYBERSECURITY
🔴 NSA Warns of “Fast Flux” Botnets

🔸 Rapidly rotating IPs & domains make detection harder.
🔸 Nation-states & ransomware groups use it to evade takedowns.
🔸 Wildcard DNS creates fake subdomains for hidden C2 servers.

Brian Greenberg :verified:brian_greenberg@infosec.exchange
2025-04-04

🔐 CISA: Fast Flux DNS Is a National Security Threat

Cyber actors are escalating use of fast flux DNS—a tactic that rapidly changes IP addresses and name servers tied to malicious domains—to evade detection and maintain resilient command-and-control infrastructure.

CISA’s latest advisory, backed by the NSA, FBI, and allies from Australia, Canada, and New Zealand, warns that this technique is:
・🔁 Difficult to block with traditional defenses
・💣 Used in attacks by Hive, Gamaredon, and other advanced threats
・💡 Critical for botnet survival and ransomware delivery

ISPs and DNS providers are being called on to:
・Deploy Protective DNS (PDNS) services
・Develop analytics to detect fast flux behavior
・Share threat intelligence across sectors

This is a call to arms for defenders: if you’re not watching your DNS traffic closely, you’re blind to one of the most elusive forms of modern infrastructure abuse.

👉 cisa.gov/news-events/cybersecu

#CyberSecurity #CISA #DNS #FastFlux #NationalSecurity #Botnets #ThreatDetection #InfoSec #PDNS

2025-04-03

Cybercriminals are evading detection with a trick that makes their attacks almost untraceable. How are shifting DNS records fueling fraud and malware? This could change everything we know about cybersecurity.

thedefendopsdiaries.com/unders

#fastflux
#cybersecurity
#dnssecurity
#botnets
#malwarenetworks

2025-03-28

A nicer graphic for the report, now embedded in the PDF

toce.ch/the-state-of-the-inter

#hacking #malware #botnets

Schneier on Security RSSSchneier_rss@burn.capital
2025-03-26

AI Data Poisoning

Cloudflare has a new feature—available to free users as well—that uses AI to generate random pages to feed to AI... schneier.com/blog/archives/202

#Uncategorized #spoofing #botnets #AI

Chema Alonso :verified:chemaalonso@ioc.exchange
2025-03-22
The Spamhaus Projectspamhaus@infosec.exchange
2025-03-18

We strongly recommend against providing services to entities whose AS or IP networks are listed in Spamhaus (ASN-)DROP - learn more here 👉 spamhaus.org/blocklists/do-not

#BulletproofHosting #DROP #ThreatIntel #Botnets #Phishing

Schneier on Security RSSSchneier_rss@burn.capital
2025-03-14

TP-Link Router Botnet

There is a new botnet that is infecting TP-Link routers:
The botnet can lead to comma... schneier.com/blog/archives/202

#Uncategorized #botnets #malware

2025-03-08

Ars Technica: Massive botnet that appeared overnight is delivering record-size DDoSes. “A newly discovered network botnet comprising an estimated 30,000 webcams and video recorders—with the largest concentration in the US—has been delivering what is likely to be the biggest denial-of-service attack ever seen, a security researcher inside Nokia said.”

https://rbfirehose.com/2025/03/08/ars-technica-massive-botnet-that-appeared-overnight-is-delivering-record-size-ddoses/

Angus McIntyreangusm
2025-03-06

The Internet of Shit is on the attack again, with a suspected Mirai-derivative botnet composed largely of compromised security cameras delivering a massive volumetric DDoS. Sweet.

mastodon.social/@arstechnica/1

👾 #Ramnit is a modular banking #trojan with botnet capabilities

It steals financial data and credentials, recruits infected devices into #botnets, and is notably persistent

Learn more, collect #IOCs & samples: any.run/malware-trends/ramnit/

#cybersecurity #infosec #malware

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst