Home/ Blog/ Topics/ Takedowns & law enforcement
Topic

Takedowns & law enforcement

Botnet disruptions, infrastructure seizures, and coordinated law-enforcement operations against cybercrime.

Security news

Weedhack stealer survives takedown by hiding servers on Ethereum, still spreading via fake Minecraft sites

Weedhack, an infostealer spread through fake Minecraft sites, survived a C2 takedown by reading server addresses from the Ethereum blockchain. How to detect it.

Security news

Malware turns Android car head units into a proxy botnet that hides attacks behind trusted home IPs

Kaspersky found the first malware built for Android car head units. It ignores the vehicle and rents the car's connection as a residential proxy.

Security news

Evooo1Bot botnet turns exposed Linux servers into credential-stealing proxies

Evooo1Bot is a new Linux botnet exploiting Confluence, WSO2 and ingress-nginx, then stealing credentials and turning servers into proxies. Detect it now.

Security news

Dysphoria botnet hides on the blockchain to survive takedowns

Dysphoria, a DDoS-for-hire IoT botnet, survived a March takedown by anchoring its command servers to Ethereum and Solana names no registrar can seize, and now

Security news

NadMesh turns exposed AI servers into cloud-key harvesters

NadMesh, a new Go botnet, scans exposed self-hosted AI tools like Ollama and ComfyUI to steal cloud keys and Kubernetes tokens.

Security news

AI wrote most of this IoT botnet, badly. That helps defenders.

Unit 42 found TuxBot v3, an IoT botnet largely written with an AI. The build is 70% broken, the working core is plain Mirai, and your defenses still hold.

Security news

The FBI seized NetNut's proxy network. Its two million compromised devices are still infected.

The FBI and Google seized the NetNut residential proxy network on July 2, but its two million compromised devices are still infected. Why IP reputation fails.

Security news

A seized iPhone gave up everything. The MacBook beside it gave up nothing.

Cellebrite's UFED tool fully read a locked iPhone in Russian custody but failed on the encrypted MacBook seized beside it.

Security news

Police seized the malware that stole 27 million passwords. The passwords still work.

Operation Endgame seized the servers behind the Amadey and StealC malware, but the 27 million credentials they already stole stay valid until you rotate them.

Security news

That decade-old router you forgot is now scanning networks for attackers

A botnet called AryStinger hijacked over 4,300 end-of-life D-Link and Linksys routers into a distributed scanning grid for reconnaissance, not DDoS. What to do.

Security news

Millions of hacked TV boxes now rent attackers a trusted home IP. Your blocklist can't see it.

Researchers linked the Popa botnet of 2 million hacked TV boxes to a residential proxy service. Here is why IP reputation no longer stops account takeovers.

Security news

Police scrubbed SocGholish from 15,000 WordPress sites. The way in is still wide open.

Operation Endgame seized 106 SocGholish servers and cleaned 14,971 WordPress sites. The takedown hit an access broker, not the entry vector.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.