Tag

Botnet

All articles tagged with #botnet

RondoDox Botnet Exploits React2Shell Flaw to Hijack IoT Devices and Servers

Originally Published 12 days ago — by The Hacker News

Featured image for RondoDox Botnet Exploits React2Shell Flaw to Hijack IoT Devices and Servers
Source: The Hacker News

Cybersecurity researchers have uncovered a nine-month campaign where the RondoDox botnet exploited the critical React2Shell vulnerability (CVE-2025-55182) to hijack IoT devices and web servers, deploying malware, cryptocurrency miners, and Mirai variants, with the threat still active as of December 2025. Organizations are urged to update vulnerable software, segment IoT devices, and enhance monitoring to prevent infection.

Oregon Man Charged Over 'Rapper Bot' DDoS Attacks

Originally Published 4 months ago — by Krebs on Security

A 22-year-old Oregon man, Ethan J. Foltz, was arrested for operating Rapper Bot, a large IoT-based botnet used for launching massive DDoS attacks, including one that disrupted Twitter/X in March 2025. The botnet, which enslaved around 65,000 devices globally, was rented out to extortionists and was responsible for over 370,000 attacks targeting thousands of victims. Foltz admitted to building and controlling the botnet, which was designed to be manageable and stealthy, and he discussed its capabilities and rival threats in encrypted chats. The case highlights the significant financial and operational risks posed by such cybercriminal activities.

FBI Urges 10 Million Android Users to Disconnect Devices Immediately

Originally Published 5 months ago — by Forbes

Featured image for FBI Urges 10 Million Android Users to Disconnect Devices Immediately
Source: Forbes

The FBI warns that over 10 million Android devices, including IoT gadgets and smart devices, are infected with the BadBox 2.0 botnet, which is used for criminal activities. Google has taken legal action and updated protections, but users are advised to disconnect suspicious devices from their networks to prevent further harm.

FBI and Google Urge 10 Million Android Users to Disconnect Devices Amid Malware Threats

Originally Published 5 months ago — by Forbes

Featured image for FBI and Google Urge 10 Million Android Users to Disconnect Devices Amid Malware Threats
Source: Forbes

The FBI warns that over 10 million Android devices, mainly low-cost IoT products from China, are infected with the malicious BadBox 2.0 malware, which is pre-installed in device firmware and used for criminal activities. Google has taken legal action and updated protections, while the FBI recommends users disconnect suspicious devices from their networks to prevent further harm.

FBI Warns of BADBOX 2.0 Android Malware Impacting Millions

Originally Published 7 months ago — by BleepingComputer

Featured image for FBI Warns of BADBOX 2.0 Android Malware Impacting Millions
Source: BleepingComputer

The FBI warns that the BADBOX 2.0 malware has infected over 1 million consumer IoT devices, mainly Android-based smart TVs and streaming devices, turning them into residential proxies for malicious activities like ad fraud and credential stuffing. Despite disruptions, the botnet continues to grow globally, with devices from China shipped worldwide, and consumers are advised to monitor their devices and avoid unofficial app stores.

Urgent: How to Check if Your Asus Router Has Been Hacked in the Latest Cyberattack

Originally Published 7 months ago — by PCMag

Featured image for Urgent: How to Check if Your Asus Router Has Been Hacked in the Latest Cyberattack
Source: PCMag

A security report reveals that around 9,000 Asus routers have been hacked by a sophisticated threat actor aiming to create a botnet. Users can check if their routers are compromised by inspecting SSH access and should perform a factory reset if infected. Updating firmware and blocking specific IPs are recommended to prevent future attacks.

FBI Warns of Widespread ASUS Router Hacks and Persistent Backdoors

Originally Published 7 months ago — by 9to5Mac

Featured image for FBI Warns of Widespread ASUS Router Hacks and Persistent Backdoors
Source: 9to5Mac

The FBI has issued a warning against 13 specific older router models, mainly from Linksys/Cisco, that are vulnerable to malware called TheMoon, which can be exploited to control devices and hide malicious activity. Users with these models should consider replacing them, especially if they haven't received updates, to avoid security risks.

Thousands of ASUS Routers Compromised by Persistent Botnet and Backdoors

Originally Published 7 months ago — by 9to5Mac

Featured image for Thousands of ASUS Routers Compromised by Persistent Botnet and Backdoors
Source: 9to5Mac

Thousands of ASUS routers have been compromised by a persistent botnet that survives firmware updates and reboots, potentially controlled by a nation state, with affected models including RT-AC3100, RT-AC3200, and RT-AX55. The only recommended mitigation is to factory reset the routers and then update the firmware, as the infection cannot be removed by updates alone.

Global Botnets Exploit Router Vulnerabilities to Maintain Persistent Backdoors

Originally Published 7 months ago — by BleepingComputer

Featured image for Global Botnets Exploit Router Vulnerabilities to Maintain Persistent Backdoors
Source: BleepingComputer

A new botnet named 'AyySSHush' has compromised over 9,000 ASUS routers by exploiting an old vulnerability to install a persistent SSH backdoor, allowing attackers to maintain access even after reboots or firmware updates. The campaign, possibly linked to a nation-state actor, also targeted other SOHO routers from Cisco, D-Link, and Linksys, and involves stealthy techniques to evade detection. ASUS has released security patches, and users are advised to update firmware, check for suspicious files, and reset their devices if compromised.

Global Cybercrime Crackdown: Major Botnet Dismantled, Chinese National Charged

Originally Published 1 year ago — by The Guardian

Featured image for Global Cybercrime Crackdown: Major Botnet Dismantled, Chinese National Charged
Source: The Guardian

US and European authorities have dismantled the "world's largest botnet," responsible for nearly $6 billion in Covid insurance fraud. The operation, codenamed Endgame, led to the arrest of multiple suspects, including Chinese national YunHe Wang, and the seizure of luxury goods and properties. The botnet, active from 2014 to 2022, spread ransomware via infected emails. The coordinated international effort involved actions in several countries and targeted various malware droppers, significantly disrupting the cybercrime ecosystem.

FBI Busts Chinese National for $6B COVID Relief Botnet Scheme

Originally Published 1 year ago — by Yahoo Finance

Featured image for FBI Busts Chinese National for $6B COVID Relief Botnet Scheme
Source: Yahoo Finance

The FBI has dismantled a massive botnet of 19 million infected computers spread across 190 countries, used for various cybercrimes including financial fraud and identity theft. The operation led to the arrest of the alleged administrator, YunHe Wang, in Singapore, and the seizure of luxury goods, cryptocurrency, and real estate. The botnet, active since 2014, generated millions by leasing access to compromised IP addresses.

FBI and Europol Dismantle $6bn Cybercrime Botnet, Arrest Chinese National

Originally Published 1 year ago — by The Hill

Featured image for FBI and Europol Dismantle $6bn Cybercrime Botnet, Arrest Chinese National
Source: The Hill

The FBI, in collaboration with international partners, dismantled the "911 S5" botnet, the world's largest, which infected 19 million computers and facilitated various cybercrimes. Chinese national YunHe Wang, who profited nearly $100 million from the operation, was arrested in Singapore and faces multiple charges that could lead to a 65-year prison sentence.

Feds Dismantle World's Largest Botnet, Arrest Administrator

Originally Published 1 year ago — by BBC.com

Featured image for Feds Dismantle World's Largest Botnet, Arrest Administrator
Source: BBC.com

The US and Europe have conducted major operations against cybercrime networks, resulting in multiple arrests and the seizure of luxury assets. The US arrested Chinese national YunHe Wang, accused of hacking 19 million devices and causing $5.9 billion in losses, while Europol arrested ringleaders in Armenia and Ukraine, taking control of over 2,000 websites. Both operations targeted botnets used for various criminal activities, including fraud and ransomware.

FBI and Europol Dismantle $6bn Cybercrime Empire, Arrest Key Figures

Originally Published 1 year ago — by WEAU

Featured image for FBI and Europol Dismantle $6bn Cybercrime Empire, Arrest Key Figures
Source: WEAU

An international law enforcement team has arrested Chinese national Yunhe Wang, disrupting the "911 S5" botnet, which officials say is the world's largest. Wang allegedly ran the botnet for nearly a decade, amassing $99 million by reselling access to criminals for identity theft, child exploitation, and financial fraud, including pandemic relief scams. Authorities seized $29 million in cryptocurrency and linked Wang to $5.9 billion in fraud losses. Wang managed the botnet through 150 servers and used his gains to purchase properties worldwide.

U.S. Dismantles Massive Botnet, Arrests Chinese National for $6B COVID Relief Theft

Originally Published 1 year ago — by The Hacker News

Featured image for U.S. Dismantles Massive Botnet, Arrests Chinese National for $6B COVID Relief Theft
Source: The Hacker News

The U.S. Department of Justice dismantled the world's largest botnet, 911 S5, which infected 19 million devices globally. Chinese national YunHe Wang, the botnet's creator, was arrested and charged with multiple offenses, facing up to 65 years in prison. The botnet facilitated various cybercrimes, including financial fraud and identity theft, generating millions of dollars for Wang. The takedown involved international cooperation and led to the seizure of significant assets.