threat-intel ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories This week’s ThreatsDay bulletin highlights a diverse range of cyber threats, including a 296,000-device IoT botnet, social engineering attacks targeting security teams, and a growing number of credential-stealing malware families. Notable threats include a fake login page and productivity app used for phishing, a Pytho… The Hacker News · 3d ago High CVE-2026-55040CVE-2026-63520RUsocial engineeringphishingcredential theft
threat-intel US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks The US government has disrupted a Chinese hacking platform and botnet, QTFY, used by Chinese threat actors to target military and critical infrastructure systems in the United States. The disruption targeted QScan and QT… SecurityWeek · 3d ago High CHhackingcyberespionagebotnet
threat-intel Android Malware Hijacks Update System for Car Head Units Threat actors, linked to the BadBox click-fraud botnet, are exploiting legitimate update mechanisms in car head units to spread malware. This marks the first known instance of malware targeting automotive infotainment sy… Dark Reading · 4d ago High CHandroidbotnetmalware
threat-intel FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations The FBI has disrupted a Chinese-linked hacking infrastructure, QScan and QTRouter, operated by the group QTFY, which has been targeting U.S. critical infrastructure since 2018. These tools were used to steal data and con… The Hacker News · 4d ago High CVE-2024-8190CVE-2024-8963CVE-2024-9380CHcyber espionageiotproxy
threat-intel First Malware Built Specifically for Car Head Units Fuels Botnet Researchers at Kaspersky have identified a new malware specifically designed for car head units, linked to the BadBox botnet. This represents a significant expansion of the BadBox threat, which has previously targeted An… SecurityWeek · 5d ago High CNbotnetmalwaresupply-chain
threat-intel Hackers infect Android car systems to build proxy botnet Hackers are exploiting vulnerabilities in Chinese automotive software provider DoFun's Android car head units to build a proxy botnet. The malware, initially delivered through a legitimate system application (TWCore), al… The Record · 6d ago High CHGEandroidbotnetproxy
threat-intel Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet A new malware family, dubbed JarService, is targeting Android car head units developed by DoFun, leveraging the built-in update mechanism to spread ad fraud and proxy botnet capabilities. The campaign is attributed to th… The Hacker News · Aug 21, 2026 High CNandroidcarmalware
threat-intel The invisible passenger in your car Researchers at Securelist discovered a new Android malware campaign targeting automotive head units, orchestrated by the MoYu Group, a group linked to the BADBOX botnet. The malware, delivered through legitimate system u… Securelist · Aug 21, 2026 High androidiotbotnet
threat-intel Linux Botnet Evooo1Bot Expands Mirai Capabilities Well Beyond DDoS Evooo1Bot, a Linux botnet derived from Mirai, has significantly expanded its capabilities beyond simple DDoS attacks. It now incorporates advanced features like encrypted C2 communications, SSH brute-force scanning, a re… Dark Reading · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558miraiddosbotnet
threat-intel Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies A new Linux botnet, dubbed Evooo1Bot, leveraging Mirai's code, is actively exploiting vulnerabilities in internet-facing devices to turn them into SOCKS5 proxies. The botnet utilizes a range of capabilities including enc… The Hacker News · Aug 17, 2026 High CVE-2007-3010CVE-2016-6277CVE-2018-14558botnetsocks5proxy
threat-intel New Mirai variant adds stealth capabilities to notorious botnet code A new, stealthier variant of the Mirai botnet, dubbed Evooo1Bot, has been actively exploiting vulnerabilities in internet-facing hardware for over a month. This malware boasts advanced features like encrypted communicati… The Record · Aug 13, 2026 High CACHGEmiraibotnetvulnerability
threat-intel Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing A new version of the Kimwolf/AISURU Android and IoT botnet, Kimwolf v7, has been discovered by Palo Alto Networks Unit 42. This version significantly improves its operational resilience and DDoS attack capabilities by ut… The Hacker News · Aug 11, 2026 High botnetddosadb
threat-intel The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Aeternum is a newly discovered blockchain-based botnet loader utilizing the Polygon blockchain for command and control. Instead of relying on traditional servers, threat actors use smart contracts to issue encrypted inst… Palo Alto Unit 42 · Aug 10, 2026 High blockchainc2polygon
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Botnet Hunting for Vulnerabilities in Diagnostic Tools, (Tue, Aug 4th) A SANS Internet Storm Center alert highlights a botnet actively scanning for vulnerabilities in diagnostic tools. The issue stems from a common practice of diagnostic tools executing operating system commands directly, o… SANS Internet Storm Center · Aug 4, 2026 Medium CVE-2024-12856CVE-2013-7179CVE-2020-8949command-injectionos-command-executionvulnerability
threat-intel Tengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its Process A new Mirai-derived botnet, Tengu, is leveraging hardware watchdog timers and other persistence mechanisms to re-establish itself on compromised Linux devices, even after defenders attempt to kill its main process. The b… The Hacker News · Jul 28, 2026 High botnetmiraiiot
threat-intel Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption The Dysphoria IoT botnet has evolved to become significantly harder to disrupt by incorporating blockchain-based name services and utilizing infected devices as relays. This complex architecture, stemming from the JackSk… The Hacker News · Jul 27, 2026 High CVE-2025-9528JPiotbotnetc2
threat-intel Rondo Meets Geoserver, (Wed, Jul 22nd) A Rondo botnet attack targeting Geoserver, a geographic information system tool, is being observed. The attack leverages a vulnerability (CVE-2024-36401) to execute arbitrary shell commands, delivering a Rondo payload. T… SANS Internet Storm Center · Jul 22, 2026 Medium CVE-2024-36401vulnerabilitybotnetgeoserver
threat-intel Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs A Russian-speaking threat actor, “bandcampro,” leveraged Google Gemini CLI to orchestrate a botnet and conduct various cybercrime activities, including dental clinic control and cryptocurrency fraud. The actor utilized t… The Hacker News · Jul 20, 2026 High USCARUaicybercrimebotnet
threat-intel New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens A Go botnet called NadMesh is actively targeting exposed AI services and cloud infrastructure, specifically seeking AWS keys, Kubernetes tokens, and Docker API access. The botnet, discovered by XLab and previously identi… The Hacker News · Jul 17, 2026 High CVE-2026-39987CVE-2026-41176CVE-2022-22947botnetcloud-securitydocker