Latest updates for Botnet

Fresh curated links around Botnet are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies
  • Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies
  • Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

infosecurity-magazine.com /3 weeks ago

New Mirai-Based Linux Botnet ‘Evooo1Bot’ Turns Victims Into Proxies

Evooo1Bot is a newly observed botnet based on the Mirai framework but equipped with advanced features, turning edge devices into persistent proxies

Read source
thehackernews.com /3 weeks ago

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is e...

Read source
gbhackers.com /3 weeks ago

Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes

A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems, combining Mirai-derived DDoS cap...

Read source
thehackernews.com /1 month ago

Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware

Four compromised npm packages in the @asyncapi namespace have been observed distributing a multi-stage botnet loader, according to findings from OX Security, SafeDep, Socket, and S...

Read source
thehackernews.com /4 weeks ago

Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing

Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its op...

Read source
cybersecuritynews.com /1 month ago

NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

A sharp structural shift has been identified in the botnet landscape. Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been spreading rapidly since e...

Read source
gbhackers.com /1 month ago

New NadMesh Botnet Uses 20+ RCE Vectors to Hijack AI and MCP Infrastructure

NadMesh is a new, industrial‑grade Go‑based botnet that weaponizes more than 20 RCE vectors to hijack AI and MCP infrastructure at scale, combining autonomous scanning, exploit del...

Read source
thehackernews.com /1 month ago

New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens

A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys. A Shodan harvester keeps the scan qu...

Read source
thehackernews.com /1 month ago

Dysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid Disruption

Dysphoria, an Internet of Things (IoT) botnet line tracked by CNCERT and XLab, has adopted blockchain-based name services and infected-device relays after a March law-enforcement o...

Read source
thehackernews.com /1 month ago

148 npm Packages Disguised as Student Proxies Turned Browsers Into a DDoS Botnet

A campaign of 148 npm packages disguised as student web proxies turned visitors' browsers into a distributed denial-of-service botnet for roughly two weeks in May, according to new...

Read source
bleepingcomputer.com /3 weeks ago

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]

Read source
bleepingcomputer.com /1 month ago

New Dysphoria DDoS botnet spreads to 200k devices worldwide

A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. [...

Read source
cybersecuritynews.com /3 weeks ago

Dysphoria Botnet Turns Compromised Routers and Cameras Into DDoS Bots and C2 Relay Nodes

Dysphoria has turned a large number of everyday internet-connected devices into a potential attack network. The botnet is linked to roughly 296,000 compromised devices, placing rou...

Read source
cybersecuritynews.com /1 month ago

Botnet Is Hunting Router Ping Tools That Can Turn User Input Into Shell Commands

A botnet campaign is probing routers for weak spots in diagnostic features. The activity focuses on web paths linked to ping, traceroute and troubleshooting tools, where a poorly h...

Read source
gbhackers.com /3 weeks ago

Dysphoria Hijacks Routers, Gateways and IP Cameras to Build Massive IoT Botnet

The Dysphoria botnet has expanded into a major Internet of Things threat, with a new Shadowserver Special Report identifying approximately 296,000 compromised devices. The campaign...

Read source
gbhackers.com /1 month ago

Russian-Speaking Hacker Uses Gemini CLI to Deploy C2 Botnet in Six Minutes

A Russian-speaking threat actor tracked as “bandcampro” used Google Gemini CLI as an end-to-end operational assistant to migrate a command-and-control server, deploy a replacement...

Read source
developer-tech.com /1 month ago

Four AsyncAPI npm packages carry Miasma botnet loader

Socket has identified a software supply chain attack involving compromised AsyncAPI npm packages distributing a Miasma botnet loader. According to the company’s Threat Research Tea...

Read source
thehackernews.com /1 week ago

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operati...

Read source
thehackernews.com /5 days ago

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing acc...

Read source
iottechnews.com /1 month ago

Dysphoria IoT botnet uses blockchain domains to hide 200k bots

IoT botnet Dysphoria has infected over 200,000 devices, hiding command servers on Ethereum and Solana blockchain domains. The botnet family first appeared in the wild in March 2026...

Read source
infosecurity-magazine.com /6 days ago

International Operation Disrupts Sality P2P Botnet

US-led action sinkholes machines caught up in Sality botnet

Read source
bleepingcomputer.com /1 week ago

Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botne...

Read source
bleepingcomputer.com /1 month ago

Google Gemini CLI abused as a hacking agent, malware botnet operator

A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]

Read source
cybersecuritynews.com /2 weeks ago

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text, the malware feeds system a...

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Botnet

cybersecuritynews.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source

gbhackers.com

Recent coverage from public sources
Public source

iottechnews.com

Recent coverage from public sources
Public source

bleepingcomputer.com

Recent coverage from public sources
Public source

developer-tech.com

Recent coverage from public sources
Public source