Void Botnet Exploits Ethereum for Command-and-Control Operations
Article Content
- •Void Botnet employs Ethereum smart contracts for its command-and-control infrastructure.
- •The botnet is designed to evade traditional takedown methods used by authorities.
- •Discovered in March 2026, Void represents a significant evolution in cybercrime tactics.
The Void Botnet, discovered in March 2026, utilizes Ethereum smart contracts to create a resilient command-and-control (C2) infrastructure that is difficult to disrupt. This botnet has emerged on Russian-language cybercrime forums, showcasing an evolution in cybercrime tactics. Unlike traditional C2 setups that can be easily seized by authorities, Void's architecture allows it to operate beyond conventional takedown efforts. The botnet's operations raise significant concerns for cybersecurity professionals as it represents a shift towards decentralized control mechanisms. Current reports indicate that Void follows the Aeternum C2 campaign but introduces unique operational methods. The full scope of its impact is still being assessed as security researchers continue to analyze its capabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track VOID and Ethereum in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…
Critical RCE Vulnerability in F5 BIG-IP APM Exploited in the Wild A severe heap-based buffer overflow vulnerability, tracked as CVE-2026-94127, has been identified in F5 BIG-IP Access Policy Manager (APM), allowing unauthenticated remote code execution (RCE) on the Traffic Management Microkernel (TMM) data plane. This vulnerability is triggered when both an APM access policy and an…