Tag : botnet

12 attack reports | 0 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
Botnet 7777: Are You Betting on a Compromised Router? Aug. 8, 2024, 11:30 a.m. This analysis uncovers the expansion of a significant botnet operation, dubbed Quad7 or 7777 botnet, characterized by its unique … 7
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks Aug. 7, 2024, 4:16 p.m. TrendMicro highlights the dangers of internet-facing routers and elaborates on Pawn Storm's exploitation of EdgeRouters, compleme… 64
Solving the 7777 Botnet enigma: A cybersecurity quest July 23, 2024, 8 a.m. Sekoia.io investigated the mysterious 7777 botnet (aka Quad7 botnet), which compromised TP-Link routers to relay password sprayin… 4
Who You Gonna Call? AndroxGh0st Busters! July 17, 2024, 7:34 a.m. This report discusses the AndroxGh0st malware, a Python-scripted threat targeting Laravel web applications to steal sensitive dat… 7
New Threat: A Deep Dive Into the Zergeca Botnet July 5, 2024, 3:33 p.m. An analysis of a newly discovered botnet named Zergeca, implemented in Go language, with capabilities for DDoS attacks, proxying,… 13
Mining Gang's New Tool: k4spreader July 2, 2024, 8:22 a.m. QIanxin describes the discovery and analysis of k4spreader, a new malware installer and spreader tool developed by the 8220 minin… 35
The Digital Legacy of Botnet 911 S5 June 14, 2024, 10:51 a.m. The report provides an in-depth analysis of the notorious Botnet 911 S5, revealing its origins, operations, and digital remnants.… 35
Malware botnet installing NiceRAT June 6, 2024, 7:28 a.m. This report discusses a botnet that has been active since 2019, distributing various malware such as NiceRAT, Nitol, and NanoCore… 24
Threat Actors' Systems Can Also Be Exposed and Used by Other Threat Actors June 6, 2024, 7:22 a.m. This report discusses a case where a CoinMiner threat actor's proxy server, used to access an infected botnet, became the target … 34
Security Brief: Millions of Messages Distribute LockBit Black Ransomware May 13, 2024, 6:27 p.m. In late April 2024, Proofpoint observed high-volume email campaigns facilitated by the Phorpiex botnet, distributing millions of … 16
Protecting Networks from Opportunistic Ivanti Pulse Secure Vulnerability Exploitation May 10, 2024, 9:06 a.m. Juniper Threat Labs has observed attempts to exploit Ivanti Pulse Secure authentication bypass and remote code execution vulnerab… 23
New Goldoon Botnet Targeting D-Link Devices May 3, 2024, 9:27 a.m. In April 2024, FortiGuard Labs observed a new botnet exploiting a nearly decade-old D-Link vulnerability to take control of devic… 24