<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Botnet on CuraSec</title><link>https://curasec.metacog.co.kr/tags/botnet/</link><description>Recent content in Botnet on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 02 Sep 2026 15:05:08 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/botnet/index.xml" rel="self" type="application/rss+xml"/><item><title>CrowdStrike Details Sality P2P Botnet Disruption Operation</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-peer-pressure-inside-the-sality-botnet-disruption-operation/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-peer-pressure-inside-the-sality-botnet-disruption-operation/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Sality is a long-lived Windows malware family; no new CVEs or patch action indicated. Worth reviewing for any infrastructure hardening lessons from the disruption operation.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> A disruption retrospective on a known P2P botnet improves understanding of Sality&amp;rsquo;s architecture and TTPs, but no enrichment signals suggest fresh IOCs or active targeting requiring an immediate hunt.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Sality P2P botnet infrastructure seized in international takedown</title><link>https://curasec.metacog.co.kr/insights/2026-09-02-sality-botnet-infrastructure-dismantled-in-joint-global-take/</link><pubDate>Wed, 02 Sep 2026 15:05:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-02-sality-botnet-infrastructure-dismantled-in-joint-global-take/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Sality has been a persistent Windows endpoint threat for years; the C2 sinkholing creates a window to identify residual infections in your estate, but no IOCs or TTPs are provided in this summary to act on directly.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A notable coordinated takedown of a long-running global botnet, useful context for board-level situational awareness on law enforcement effectiveness, but no organizational action is required.&lt;/li>
&lt;/ul></description></item><item><title>Android car head units infected via update app in proxy botnet attack</title><link>https://curasec.metacog.co.kr/insights/2026-08-23-hackers-infect-android-car-head-units-with-proxy-botnet-malw/</link><pubDate>Sun, 23 Aug 2026 11:32:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-23-hackers-infect-android-car-head-units-with-proxy-botnet-malw/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Supply-chain abuse of a legitimate update mechanism on Android auto head units is a useful attack pattern to understand, but there is no CVE, no EPSS signal, and no indication enterprise fleets are in scope — no patch or config action available today.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The update-app-as-dropper technique is worth filing as a TTPs reference, but no IOCs or ATT&amp;amp;CK mappings are provided in this item, so no hunt or detection can be built from it now.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Android Car Head Unit Malware Uses Built-In Updater for Ad Fraud, Botnet</title><link>https://curasec.metacog.co.kr/insights/2026-08-22-android-car-malware-spreads-through-built-in-updaters-for-ad/</link><pubDate>Sat, 22 Aug 2026 11:32:44 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-22-android-car-malware-spreads-through-built-in-updaters-for-ad/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> The updater-as-delivery-channel technique on Android-based embedded devices is a noteworthy TTP, and the proxy botnet component could eventually surface in network telemetry — but no IOCs or ATT&amp;amp;CK mappings are provided, leaving no concrete detection action available today.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Evooo1Bot Linux botnet hijacks routers as SOCKS5 relay nodes</title><link>https://curasec.metacog.co.kr/insights/2026-08-16-new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay/</link><pubDate>Sun, 16 Aug 2026 11:32:38 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-16-new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Audit internet-facing gateway devices and routers for signs of Mirai-variant compromise; harden by restricting management interfaces, disabling unused services, and ensuring firmware is current — no active KEV or PoC signals yet to force immediate action.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for anomalous SOCKS5 proxy traffic originating from edge/gateway devices; hunt for unexpected outbound relay behavior on routers in your estate since no specific IOCs are currently published.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Aeternum Botnet Uses Polygon Blockchain for Decentralized C2</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-the-permanent-threat-analyzing-aeternum-s-blockchain-based-c/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-the-permanent-threat-analyzing-aeternum-s-blockchain-based-c/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Blockchain-based C2 is an emerging evasion technique that may bypass traditional domain-blocking controls; no patch or configuration action required, but architects should consider that blocking Polygon RPC endpoints could disrupt legitimate Web3 tooling.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for outbound calls to Polygon RPC endpoints (e.g., polygon-rpc.com) from non-Web3 workloads, and develop hunting queries for processes that query smart contract ABI methods as a C2 channel.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Blockchain-anchored C2 represents a structural evasion of perimeter controls; useful context for future investments in DNS/network monitoring that can handle decentralized infrastructure, but no immediate leadership action required.&lt;/li>
&lt;/ul></description></item><item><title>Kimwolf v7 Botnet Uses Ethereum ENS for C2 and Tor Backup Routing</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-kimwolf-v7-an-evolution-of-the-kimwolf-botnet/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-kimwolf-v7-an-evolution-of-the-kimwolf-botnet/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Kimwolf v7&amp;rsquo;s use of Ethereum Name Service for C2 resolution and Tor as a fallback is a novel evasion pattern worth incorporating into threat models for IoT/edge assets, but no patch or config change applies to typical cloud/AppSec environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The ENS-based C2 resolution and Tor backup routing introduce detection gaps in traditional domain-block and DNS monitoring approaches; plan detection coverage for anomalous Ethereum ENS lookups and unexpected Tor traffic from IoT segments this quarter.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Botnet scanning for diagnostic tool vulnerabilities</title><link>https://curasec.metacog.co.kr/insights/2026-08-04-botnet-hunting-for-vulnerabilities-in-diagnostic-tools-tue-a/</link><pubDate>Tue, 04 Aug 2026 13:07:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-04-botnet-hunting-for-vulnerabilities-in-diagnostic-tools-tue-a/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Active botnet reconnaissance targeting diagnostic tool endpoints is worth noting — audit whether any exposed diagnostic URLs are publicly reachable and restrict access, but no specific CVE or exploitation confirmed here.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Consider building or tuning detections for anomalous probing of diagnostic endpoints; the SANS diary may contain specific URL patterns worth adding to WAF or SIEM watchlists once the full write-up is reviewed.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Tengu Botnet Uses Hardware Watchdog to Survive Process Kills on Linux</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-tengu-botnet-reboots-compromised-linux-devices-when-defender/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-tengu-botnet-reboots-compromised-linux-devices-when-defender/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Any Linux device with Telnet exposed and weak credentials is a candidate target; audit your estate for Telnet listeners, disable them, and review hardware watchdog configurations on edge/IoT devices so defenders can&amp;rsquo;t be stymied by the reboot-on-kill mechanism.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Build or tune detections for Telnet brute-force login bursts against Linux endpoints and flag unexpected device reboots following process termination events; update IR runbooks to account for the watchdog reboot loop before attempting to kill botnet processes on compromised hosts.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A novel DDoS botnet persistence technique that complicates incident response on Linux devices — no immediate leadership action required, but useful context if DDoS risk or IoT/edge device exposure comes up in a risk review.&lt;/li>
&lt;/ul></description></item><item><title>Dysphoria DDoS Botnet Compromises 200k Devices Globally</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, PoC, or EPSS signal provided; no specific vulnerability or affected software named in the summary. Monitor for follow-up reporting with exploitation details or affected device types that may be in your estate.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A 200k-node botnet generating DDoS and relay traffic is worth building or tuning detections for — watch for follow-up IOC releases and prepare to hunt for anomalous outbound traffic patterns consistent with botnet C2 or relay behavior.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Awareness-level item for now; if your organization relies on internet-facing services, DDoS resilience posture is worth a periodic review but this report lacks specifics that would require immediate leadership action.&lt;/li>
&lt;/ul></description></item><item><title>Russian Actor Uses Gemini CLI to Operate Dental Clinic Botnet</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-russian-speaking-hacker-uses-google-gemini-cli-to-control-bo/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-russian-speaking-hacker-uses-google-gemini-cli-to-control-bo/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Demonstrates an emerging operational pattern where attackers use open-source AI CLIs to automate credential attacks and botnet management; no specific vulnerability to patch, but worth reviewing whether Gemini CLI or similar tools are present in CI/CD or developer environments and could be abused.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The session log analysis reveals AI-assisted password cracking and botnet C2 as concrete TTPs; build or tune detections for anomalous use of AI CLI tools (Gemini CLI, others) in endpoint and network telemetry, particularly subprocess chains or outbound API calls from unexpected processes.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Illustrates that commodity AI tooling is lowering the operational bar for solo threat actors; useful context for AI usage policy discussions and future board briefings on AI-enabled threats, but no immediate organizational action required given the small scale and no named sector targeting.&lt;/li>
&lt;/ul></description></item><item><title>NadMesh Botnet Targets Exposed AI Services to Steal Cloud Keys and K8s Tokens</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Actively scanning for internet-exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to harvest AWS keys and Kubernetes tokens — exactly the stack teams deploy fast without firewall controls. Audit now for public exposure of these service ports, restrict to internal networks, and rotate AWS/K8s credentials on any host that ran them exposed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The TTPs are concrete enough to build detections around: Shodan-driven scanning targeting AI service endpoints, followed by credential exfiltration. Build hunts for unusual outbound traffic or credential API calls originating from AI service hosts; the summary appears truncated so IOCs are not yet available to act on directly.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A claimed harvest of 3,811 AWS keys illustrates the systemic risk of teams rapidly standing up AI infrastructure without security review. Raise with engineering and DevSecOps leadership to establish a deployment standard for AI tooling that includes network isolation requirements before services go live.&lt;/li>
&lt;/ul></description></item><item><title>Gemini CLI weaponized as hacking agent and botnet operator</title><link>https://curasec.metacog.co.kr/insights/2026-07-16-google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-o/</link><pubDate>Thu, 16 Jul 2026 12:18:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-16-google-gemini-cli-abused-as-a-hacking-agent-malware-botnet-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Demonstrates that open-source AI CLI tools can be weaponized as autonomous hacking agents without any vulnerability in the tool itself — worth factoring into how you restrict or monitor AI tooling in build and dev environments.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> This TTP — using legitimate AI CLI processes as attack orchestrators — is worth adding to your behavioral detection backlog; consider hunting for anomalous Gemini CLI process invocations, unusual network calls from AI tool processes, or AI binaries spawning unexpected child processes.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A real-world example of AI tools being weaponized at small scale; useful context for AI governance policy discussions and for framing acceptable-use controls around AI developer tooling.&lt;/li>
&lt;/ul></description></item></channel></rss>