Threats Tagged 'botnet'
View all threats tagged with 'botnet'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'botnet'
Click on any threat for detailed analysis and mitigation recommendations
Carbonato is a botnet malware targeting insecure Docker hosts with exposed, unauthenticated Docker daemon APIs on port 2375. It installs the Hermes Agent AI framework, specifically the GH0ST agent, to execute operator-driven commands via Telegram, enabling remote control and data theft. The malware spreads worm-like by scanning networks for other vulnerable Docker daemons and establishing persistence through multiple system mechanisms. Infection signs include the GH0ST persona file, the CARBONATO_API_KEY setting, reverse SSH tunnels, and unusual Telegram traffic. Researchers suggest the operator may be located in Costa Rica. Mitigation involves securing Docker APIs by disabling network exposure and enforcing authentication on registries. Join the discussion | Bleeping Computer | 09/24/2026, 20:10:48 UTC Added: 09/24/2026, 21:03:05 UTC |
ThreatDown researchers discovered CARBONATO, a Docker botnet that exploits exposed Docker daemons on port 2375. The operation was uncovered through an unauthenticated Docker registry exposed since May 2026, revealing two parallel activities: distribution of trojanized cryptocurrency wallet applications and a botnet infrastructure. The botnet leverages Hermes Agent, an MIT-licensed open-source AI framework, modified with a custom prompt directing it to execute commands via Telegram, maintain persistence, and harvest credentials. The campaign infrastructure spans multiple hosting providers including Linode, Hetzner, and Contabo, with activity documented from October 2024 through August 2026. Join the discussion | AlienVault OTX General | 09/24/2026, 07:56:13 UTC Added: 09/24/2026, 08:03:01 UTC |
A Redis cryptomining botnet compromised 3,562 Redis servers by exploiting unsecured no-auth configurations. The botnet operator's own files were exposed in an open directory, revealing the full toolkit and detailed campaign logs. The attack leveraged rogue replication commands to deploy a cron job that runs the XMRig miner, targeting Monero mining pools. The issue is due to missing authentication and insecure default configurations, not a software vulnerability. The affected Redis versions range from 2.8.17 to 7.2.0. Mitigation involves configuring Redis securely by enabling authentication and disabling replication features if unused. Join the discussion | Reddit NetSec | 09/08/2026, 17:53:35 UTC Added: 09/08/2026, 18:37:03 UTC |
An exposed directory at 188.245.99.156 revealed a comprehensive cryptomining toolkit containing 147 files including Python exploit source code, campaign logs, and Windows registry hives. Analysis confirms 3,562 Redis servers were compromised across two campaign runs targeting 12,966 hosts. The operation exploited unauthenticated Redis instances using rogue replication techniques to inject cron jobs that deployed XMRig miners. Victims spanned Redis versions 2.8.17 through 7.2.0 across outdated and current Linux distributions, indicating misconfiguration rather than version-specific vulnerabilities. The toolkit also targeted WordPress, MongoDB, and SSH but achieved zero confirmed compromises through those vectors. A separate February 2026 open directory linked by wallet reuse revealed Meterpreter deployment capabilities, extending the operator's known activity timeline by five months. The operation mined Monero through pool.moneroocean.stream with the same wallet used on the operator's own Windows-based work... Join the discussion | AlienVault OTX General | 09/08/2026, 16:59:09 UTC Added: 09/09/2026, 09:22:16 UTC |
The Sality peer-to-peer (P2P) botnet, active for 23 years since 2003, has been disrupted through an international law enforcement operation. Sality spread via file infection and did not use centralized command-and-control servers, relying instead on a P2P network of infected machines. The disruption exploited the botnet's trust in peer lists by manipulating these lists to isolate infected machines and sinkhole their communications. Law enforcement also took down URLs hosting Sality payloads, preventing new infections. The Shadowserver Foundation is assisting with identifying and cleaning infected machines. This operation effectively cut off the botnet's criminal operators from controlling infected hosts. Join the discussion | SecurityWeek | 09/02/2026, 08:38:00 UTC Added: 09/02/2026, 08:52:16 UTC |
International law enforcement agencies and private partners have dismantled the Sality botnet infrastructure in a coordinated global takedown. Sality is a peer-to-peer (P2P) botnet active since at least 2003, infecting over 15,000 devices worldwide. The botnet was primarily used to distribute various malware families, with the recent primary payload being EggJagger, a clipjacking malware targeting cryptocurrency wallets. The takedown involved seizing Sality-linked domains and sinkholing the botnet's P2P control channels, effectively disrupting its operations and isolating infected machines. The botnet was controlled by a criminal group tracked as SALTY SPIDER, likely based in the Republic of Bashkortostan, Russia. This operation marks the end of Sality's control by its operators after more than two decades of activity. Join the discussion | Bleeping Computer | 09/02/2026, 08:00:43 UTC Added: 09/02/2026, 08:07:13 UTC |
0 A misconfigured open directory on IP 86.53.111.212:8080 exposed the Moobot botnet source code, DDoS tools, and fraudulent services linked to an active cybercrime operation. The exposed data included StresD Pro+, a multi-user DDoS panel with multiple registered accounts and recorded attacks. Analysis of the Moobot source code revealed a dormant download-and-execute feature likely used by APT28 to deploy malware. Despite a 2024 court-authorized disruption, Moobot remains active as of August 2026, with ongoing DDoS attacks consistent with DDoS-as-a-service activity. Join the discussion | AlienVault OTX General | 08/28/2026, 02:25:31 UTC Added: 08/28/2026, 08:52:30 UTC |
Researchers at Kaspersky have identified the first malware specifically designed to target car head units, linking it to the BadBox botnet. The malware was found on an Android-based aftermarket infotainment system from the Chinese company DoFun, widely used in China and other APAC countries. Attackers exploited a vulnerability in the system's software update mechanism to deliver malicious Android applications that act as droppers, loaders, clickers, and reverse-proxy loaders. The malware supports multiple commands, primarily used to download a reverse proxy module, indicating its main purpose is to incorporate infected devices into a proxy botnet. The vendor has addressed the vulnerability after notification. The BadBox botnet has been active since at least 2023, primarily targeting Android devices such as TV boxes, and has grown to include millions of devices. This development shows an expansion of BadBox operators' delivery methods and targets to vehicle infotainment systems. Join the discussion | SecurityWeek | 08/25/2026, 11:18:22 UTC Added: 08/25/2026, 11:22:13 UTC |
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...] Join the discussion | Bleeping Computer | 08/22/2026, 14:14:24 UTC Added: 08/22/2026, 14:52:13 UTC |
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek . Join the discussion | SecurityWeek | 08/21/2026, 15:11:16 UTC Added: 08/21/2026, 15:22:11 UTC |
Showing 1 to 10 of 83 results