ShadowV2 Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
10
occurrences
First Seen
November 26, 2025
Last Seen
May 22, 2026

ShadowV2 is a malware family tracked across 4 threat clusters and 10 intelligence report mentions on ThreatCluster. First observed November 26, 2025; most recent activity May 22, 2026.

Related Threat Clusters

  • Jacob Butler Arrested for Operating KimWolf DDoS Botnet

    Jacob Butler, a 23-year-old from Ottawa, Canada, was arrested for operating the KimWolf DDoS botnet, which infected over 2 million devices worldwide. The botnet utilized a DDoS-for-hire model, launching more than 25,000…

    22 articles · Updated May 21, 2026
  • ShadowV2 Botnet Exploits AWS Outage to Target IoT Devices Globally

    During the major AWS outage in October 2025, a Mirai-based botnet named ShadowV2 was identified infecting IoT devices across 28 countries. The botnet exploited known vulnerabilities in devices from manufacturers like…

    4 articles · Updated November 26, 2025
  • ShadowV2 Malware Campaign Targets IoT Devices Worldwide

    Cybercriminals are exploiting vulnerabilities in Internet of Things (IoT) devices to deploy a new malware campaign known as ShadowV2. This campaign is affecting IoT devices globally, posing risks to users and…

    5 articles · Updated November 27, 2025
  • Fortinet VPN Exploit Actively Targeted in Real-World Attacks

    Fortinet has reported that a five-year-old security vulnerability in its FortiOS SSL VPN software, identified as CVE-2020-12812, is being actively exploited in real-world attacks. This flaw allows attackers to bypass…

    4 articles · Updated December 26, 2025

Recent Intelligence Reports

  • Canadian Arrested for Operating KimWolf DDoS IoT Botnet — Technadu · May 22, 2026
  • Fortinet VPN exploit, Google gmail change, Aflac breach update — Linkedin · December 26, 2025
  • The Quiet Takeover: Researchers Warn ShadowV2 Botnet Exploiting IoT Devices Globally — The420.In · November 28, 2025
  • Hackers Exploit IoT Vulnerabilities to Deploy New ShadowV2 Malware — Gbhackers · November 27, 2025
  • AWS botnet smacks 28 countries, LLMs help malware authors evade detection, Anthropic ... — Linkedin · November 27, 2025
  • Hackers Actively Exploiting IoT Vulnerabilities to Deploy New ShadowV2 Malware — Cybersecuritynews · November 27, 2025
  • Cybercriminals Exploit IoT Weaknesses to Launch New ShadowV2 Malware Campaign — Cyberpress · November 27, 2025
  • New ShadowV2 botnet malware used AWS outage as a test opportunity — Bleepingcomputer · November 26, 2025

CVSS v3.1 Breakdown