Skip to content
ThreatCluster

Void Botnet Exploits Ethereum for Command-and-Control Operations

First seen 20 May 2026, 22:52 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster May 21, 2026 at 22:17 UTC
  • Void Botnet employs Ethereum smart contracts for its command-and-control infrastructure.
  • The botnet is designed to evade traditional takedown methods used by authorities.
  • Discovered in March 2026, Void represents a significant evolution in cybercrime tactics.

The Void Botnet, discovered in March 2026, utilizes Ethereum smart contracts to create a resilient command-and-control (C2) infrastructure that is difficult to disrupt. This botnet has emerged on Russian-language cybercrime forums, showcasing an evolution in cybercrime tactics. Unlike traditional C2 setups that can be easily seized by authorities, Void's architecture allows it to operate beyond conventional takedown efforts. The botnet's operations raise significant concerns for cybersecurity professionals as it represents a shift towards decentralized control mechanisms. Current reports indicate that Void follows the Aeternum C2 campaign but introduces unique operational methods. The full scope of its impact is still being assessed as security researchers continue to analyze its capabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 124d ago How this analysis works

Timeline

2026-03-01
Void Botnet discovered
Security researchers identified the Void Botnet leveraging Ethereum for its C2 operations.
Gbhackers
2026-05-20
Void Botnet reported on cybercrime forums
The botnet was advertised on Russian-language forums, indicating its active recruitment and operational status.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track VOID and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed