#botnet
10 articles
Between 14 April and 22 August 2026, ZCyberNews published 13 articles under the botnet tag, covering 10 high-severity incidents, 2 medium-severity cases, and 1 critical event. Threat actors Dort, Mirai, and MoYu Group were observed across these reports. Key vulnerabilities included CVE-2025-29635 (CVSS 8.8), CVE-2024-3721 (CVSS 6.3), and CVE-2023-33538. Affected sectors spanned telecommunications, technology, automotive, corporate, and cybersecurity services, with impact reported globally and in Brazil, Canada, the Czech Republic, and Germany.
HIGHAndroid Car Head Unit Malware Builds Proxy Botnet
Kaspersky found new Android malware spreading via DoFun head unit updaters, turning cars into proxy botnet nodes. First documented case on automotive head units.
HIGHBrazilian DDoS Firm Behind Botnet Attacks on ISPs
Brazilian anti-DDoS firm's infrastructure used to launch massive botnet attacks against rival ISPs. CEO claims breach by competitor caused the abuse.
HIGHDort Identified as Kimwolf Botmaster Behind Record DDoS Attacks
KrebsOnSecurity traces Kimwolf botmaster 'Dort' to a real identity after the botnet launched DDoS, doxing, and email flood attacks against a security researcher who disclosed its…
HIGHFeds Disrupt IoT Botnets Behind Record DDoS Attacks
US DOJ, Canada, and Germany dismantled four IoT botnets — Aisuru, Kimwolf, JackSkid, Mossad — compromising 3M+ devices, enabling record-breaking DDoS attacks.
HIGHMirai Botnet Exploits D-Link Router Flaw CVE-2025-29635
Mirai botnet operators exploit CVE-2025-29635, a CVSS 8.8 command injection flaw in end-of-life D-Link DIR-823X routers, to deploy malware and launch DDoS attacks.
HIGHThe Gentlemen Ransomware Botnet Infects 1,570+ Systems via SystemBC Proxy
Check Point Research uncovers a 1,570-victim botnet linked to The Gentlemen ransomware, using the SystemBC proxy malware to establish stealthy SOCKS5 tunnels for command and control.
MEDIUMMirai Variant Nexcorium Exploits DVR Flaw to Build DDoS Botnet
A new Mirai botnet variant, 'Nexcorium,' is exploiting a command injection flaw (CVE-2024-3721) in TBK DVRs and end-of-life TP-Link routers to conscript devices into a distributed denial-of-service (DDoS) swarm.
CRITICALTP-Link Router Flaw Exploited by Mirai Botnet Variant
Attackers are exploiting CVE-2023-33538, a command injection flaw in TP-Link Archer AX21 routers, to deploy a Mirai botnet variant. The campaign hijacks devices for DDoS attacks and credential theft.
HIGHW3LL Phishing Platform Disrupted in International Law Enforcement Operation
A coordinated law enforcement operation has disrupted the W3LL phishing-as-a-service platform, which was used to target over 800,000 corporate Microsoft 365 accounts globally.
HIGHPowMix Botnet Targets Czech Workforce with Randomized C2 Traffic
Cisco Talos researchers identify the PowMix botnet, active since December 2025, targeting Czech workers with randomized C2 beaconing to evade detection and deploy additional payloads.
Stay Updated
Get the latest cybersecurity news delivered to your inbox.