Related Threat Clusters
-
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
On July 3, 2026, Google, in coordination with the FBI and other partners, disrupted the NetNut residential proxy network, also known as the Popa botnet. This operation targeted over 2 million compromised consumer…
54 articles · Updated July 2, 2026 -
US and Allies Dismantle Major IoT Botnets Behind Record DDoS Attacks
On March 20, 2026, the U.S. Justice Department, in collaboration with law enforcement from Canada and Germany, announced the dismantling of four significant botnets: Aisuru, KimWolf, JackSkid, and Mossad. These botnets…
31 articles · Updated March 20, 2026 -
Dysphoria Botnet Infects 200,000 Devices Using Blockchain for C2 Operations
The Dysphoria botnet has compromised approximately 200,000 devices globally, utilizing a sophisticated command-and-control (C2) infrastructure hidden behind Ethereum and Solana blockchain domains. Originating from the…
5 articles · Updated July 28, 2026 -
Kimwolf Botnet v7 Enhances DDoS Tactics Using Chrome Fingerprints and Ethereum
The Kimwolf botnet, primarily composed of hijacked Android TV boxes, has been upgraded to version 7, which employs advanced techniques to disguise DDoS attack traffic as legitimate web browsing. Discovered by Palo Alto…
4 articles · Updated August 12, 2026 -
Surge in DDoS Attacks Over 1 Tbps Amidst Botnet Resurgence
In the first half of 2026, Cloudflare reported a significant increase in DDoS attacks, particularly those exceeding 1 Tbps, with 935 such attacks mitigated, marking a 519% rise from Q1. April 2026 saw the peak of DDoS…
18 articles · Updated August 11, 2026 -
Tengu Botnet Utilizes Hardware Watchdog to Evade Detection and Removal
The Tengu botnet, a new variant derived from Mirai, has been discovered by Nozomi Networks Labs. It exploits the hardware watchdog feature in IoT devices to erase forensic evidence during reboots triggered by defenders…
10 articles · Updated July 28, 2026 -
Google API Key Vulnerability Exposes Gemini AI Access in Android Apps
A vulnerability in Google's API key system has allowed unauthorized access to the Gemini AI platform from numerous Android applications. CloudSEK identified that existing API keys, meant for public services,…
2 articles · Updated April 10, 2026 -
TuxBot v3 Evolution: New Modular IoT Botnet Leveraging LLM Technology
The TuxBot v3 Evolution is a newly discovered IoT botnet framework that targets a wide range of internet-connected devices, including ARM, MIPS, x86_64, PowerPC, and RISC-V architectures. It is designed for mass…
5 articles · Updated July 16, 2026 -
Jacob Butler Arrested for Operating KimWolf DDoS Botnet
Jacob Butler, a 23-year-old from Ottawa, Canada, was arrested for operating the KimWolf DDoS botnet, which infected over 2 million devices worldwide. The botnet utilized a DDoS-for-hire model, launching more than 25,000…
22 articles · Updated May 21, 2026 -
NETSCOUT Doubles DDoS Mitigation Capacity to Combat Rising Threats
On July 24, 2026, NETSCOUT announced a significant expansion of its Arbor Cloud DDoS protection capabilities, doubling its capacity to 33 Tbps. This enhancement is in response to the increasing frequency and complexity…
30 articles · Updated July 24, 2026
Recent Intelligence Reports
- Botnets before the ballots: US midterms at risk? | perspective — Scworld · August 13, 2026
- Kimwolf botnet rebuilt to survive takedowns, researchers say — Cyberscoop · August 12, 2026
- Dozens of new botnets are rising from the ashes of Kimwolf and Aisuru — Cybernews · August 11, 2026
- DDoS attacks over 1 Tbps surged fivefold in the second quarter — Bleepingcomputer · August 11, 2026
- Rebuilt in Six Days: Dysphoria IoT Botnet Hides on Blockchain to Defy Seizure — Techtimes · July 29, 2026
- Tengu Botnet Uses Hardware Watchdog to Erase Forensic Evidence on Reboot — Techtimes · July 28, 2026
- Disrupting Largest Residential Proxy Network — cloud.google.com · July 25, 2026
- A Broken System Fueling Botnets — synthient.com · July 25, 2026