Visualização normal

Ontem — 7 de Setembro de 2026Cybersecurity News

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines Mirai-style botnet tradecraft with broad persistence, DDoS, SSH probing, and proxy capabilities. The stripped 32-bit ELF masquerades as a Linux kernel worker process while targeting servers, embedded devices, and IoT-adjacent systems. It has no symbols, uses NX protection and partial RELRO, and carries a SHA-256 hash […]

The post Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Antes de ontemCybersecurity News
  • ✇Security Affairs
  • Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack Pierluigi Paganini
    Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise. Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, and targeted infrastructure operated by the Norwegian Digitalisation Agency, Digdir, together with its ser
     

Norway ’s Digital Government Infrastructure Hit by a new DDoS Attack

25 de Agosto de 2026, 14:51

Norway ’s shared government infrastructure suffered a third DDoS attack, disrupting digital services but showing no signs of data compromise.

Norway ‘s shared digital government infrastructure has been hit by another distributed denial-of-service (DDoS) attack that disrupted services used by citizens, businesses and public agencies. The incident began at 03:38 CEST on Monday, August 24, and targeted infrastructure operated by the Norwegian Digitalisation Agency, Digdir, together with its service provider Vivicta.

The timing matters because this isn’t an isolated event. Digdir says it’s the third DDoS attack against its services in a short period, following incidents in June and on August 3.

“The Norwegian Directorate for Digitalisation (Digdir) has been subjected to a denial of service attack (DDoS attack) that has been ongoing since 03:38 on the night of Monday, August 24.” reads the statement published by Digdir Agency. “This is the third time in a short time that this type of attack has been directed at Digdir’s solutions. Digdir is working closely with our subcontractor Vivicta. NSM and the Norwegian Data Protection Authority have also been notified of the case.”

That status update refers to the test environment, but the underlying attack also affected production services. Digdir reported that several shared services became completely unavailable for short periods, while others remained accessible but suffered connection failures, slow responses and longer-than-usual login times.

Digdir operates several pieces of Norway’s shared public-sector infrastructure. Among them are ID-porten, MinID, Maskinporten, eFormidling, eInnsyn, the Contact and Reservation Register, Ansattporten and other services used by government agencies and external applications.

That makes an attack on Digdir more significant than an ordinary website outage. When a shared authentication service goes down, the disruption can propagate to services that aren’t themselves under attack.

That’s exactly what happened. Altinn, Norway’s central platform for communication between citizens, businesses and government, was also affected, while other public services relying on ID-porten experienced login problems. Earlier attacks this summer produced similar effects, including disruption to access to Helsenorge, NAV and Skatteetaten.

The technical distinction is important: the attackers didn’t need to break into every downstream service. They could create disruption simply by overwhelming a shared dependency.

And that’s often the uncomfortable reality of modern public infrastructure. The weakest point isn’t necessarily the service citizens see on their screens. It can be the common authentication, messaging or data-exchange layer underneath it.

Digdir has stressed that the incident is about availability, not evidence of a successful intrusion. The agency also says it has found no indication that personal data was exposed. Digdir has notified Norway’s National Security Authority, NSM, and the Data Protection Authority, Datatilsynet, as part of its response.

“There are no indications that the attack has led to a security breach or that personal data has been compromised, says Director Frode Danielsen at Digdir.” continues the statement.

That distinction deserves attention because cyberattack doesn’t automatically mean “data theft”. In this case, the confirmed impact is service disruption, while there is currently no evidence that attackers compromised Digdir’s systems or accessed personal information.

The operational consequences are still serious. Public-sector users may see failed connections, slow responses or authentication problems even though the underlying applications themselves haven’t been compromised.

The June incident already demonstrated how much disruption a DDoS attack against Digdir’s infrastructure can cause. That attack targeted ID-porten through Vivicta’s network infrastructure and temporarily affected services including ID-porten, MinID, Maskinporten, eInnsyn and eFormidling.

Another attack followed on August 3. Digdir restored normal operations the following day, but the agency said the incident had again affected several shared services and that it would review the event together with Vivicta and other partners.

Now there’s a third incident. That repetition is more interesting from a defensive perspective than the raw duration of any single outage.

Digdir and Vivicta are clearly able to mitigate the attacks and restore services. The harder question is whether repeated attacks against the same shared infrastructure can keep generating enough operational friction to become a recurring problem for the wider public sector.

This is where DDoS stops being just a bandwidth problem. A sufficiently persistent campaign can force defenders to keep changing traffic controls, filtering rules and protection measures, while legitimate users continue to depend on the same infrastructure.

Digdir’s own status updates show that dynamic clearly. On August 24, the agency first reported improvement, then said several solutions were completely down, followed by further stabilization efforts.

There is currently no official attribution for the attacks. Norwegian media have raised the possibility of Russian involvement, but that remains speculation rather than an established finding.

That distinction matters. A DDoS campaign can be politically motivated, financially motivated, conducted for disruption or simply intended to demonstrate capability. Without technical evidence and an official attribution process, assigning responsibility to a particular state or group would be premature.

What is established is the target and the effect. The attacks repeatedly hit infrastructure that sits underneath a large number of Norwegian digital public services.

That’s enough to make the incidents strategically relevant without adding an attribution story that the evidence doesn’t yet support.

The Norwegian case is also a useful reminder that cybersecurity isn’t limited to confidentiality and integrity. Availability is a security property too, particularly when the affected systems provide national digital services.

A compromised database is an obvious security incident. An authentication service that repeatedly becomes unavailable can create a different kind of problem: citizens can’t access services, businesses can’t complete procedures and government agencies may struggle to perform routine operations.

Digdir says its services have largely stabilized, although some disruptions remain. As of the latest incident updates, ID-porten still had limitations, eSignering remained unavailable because of those ID-porten restrictions, and some users were still reporting connection problems or increased response times with Maskinporten.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Cybersecurity News
  • Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses Do Son
    Palo Alto Networks analyzed Kimwolf botnet malware. Read our Kimwolf botnet malware analysis to learn how it attacks Android TV boxes. Related Posts: Project CAV3RN Framework Adds DNS and Google Relays DeadLock Ransomware Employs Decentralized Infrastructure Apple Sends Mercenary Spyware Alerts to Users in 110+ Countries The post Kimwolf Botnet Malware Upgrades DDoS and C2 Defenses appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • DDoS Attacks Cause Major Threema Outages Pierluigi Paganini
    Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid secure messaging service, similar to WhatsApp or Signal, focused heavily on privacy and securit
     

DDoS Attacks Cause Major Threema Outages

16 de Agosto de 2026, 20:38

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks.

Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure.

Threema is a Swiss paid secure messaging service, similar to WhatsApp or Signal, focused heavily on privacy and security.

“If the attack originates simultaneously from multiple (and potentially changing) sources, it is referred to as a “Distributed Denial of Service” (DDoS) attack. This makes the attack significantly more difficult to defend against because it is not possible to simply block a single source.” reads the report. “Because sophisticated attackers constantly change their methods, sources, and attack patterns during an attack, a cat-and-mouse game ensues, with both sides continuously reacting to the other’s most recent action.”

Users began reporting Threema outages on Tuesday evening. The company initially blamed a network issue at its colocation provider, but later confirmed it was facing a series of DDoS attacks. The attacks caused intermittent disruptions into Wednesday, with users in several countries still reporting problems even after Threema’s status page showed the service as operational.

The company said a series of large-scale DDoS attacks also targeted its colocation partner, Nine. Attack patterns kept changing, making mitigation difficult. The service was unavailable for about four hours Tuesday evening, followed by intermittent outages Wednesday morning. Normal operations were restored at 12:23 p.m. CEST.

“It is not entirely clear whether Threema was the primary target or whether the attacks were directed at multiple targets. In any case, they continued over an extended period and their patterns were constantly adapted, making them difficult to defend against.” continues the report. “As a result of these attacks, Threema was unavailable on Tuesday between 7:30 p.m. and 11:30 p.m. CEST. The page providing information on the current system status was initially not updated due to a technical issue unrelated to the attack. We therefore temporarily took it offline until the problem was resolved.”

Threema communicated the service disruptions progressively through social media, while Threema Work customers received updates by email. To strengthen its defenses, Threema deployed additional upstream DDoS protection on August 14, filtering malicious traffic before it reached its infrastructure.

The company also plans to improve its status page with an incident history and RSS feed, giving users and administrators another way to receive independent service updates.

“We will also expand the status page in the coming days. The update will include an incident history and an RSS feed that interested users and Threema Work administrators can subscribe to in order to receive system updates through an independent channel.” concludes the report. “We apologize for any inconvenience caused and appreciate your understanding.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, DDoS)

“Business customers using Threema Work were informed via email on Wednesday morning about the unstable service conditions, and account managers provided information on the current situation in response to inquiries.”

To avoid similar incidents, the Swiss company has implemented “specialized DDoS protection as an additional measure” to filter attack traffic upstream and reduce the load on its infrastructure.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

  • ✇Cyber Security News
  • Threema Secure Messaging Service Hit by Massive DDoS Attack Abinaya
    Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily disrupted access for users. The incidents affected the platform on Tuesday evening and continued intermittently through Wednesday morning before normal operations were restored. According to Threema, the service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday. Users also experienced short, intermittent disruptions on Wednesda
     

Threema Secure Messaging Service Hit by Massive DDoS Attack

17 de Agosto de 2026, 08:49

Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily disrupted access for users.

The incidents affected the platform on Tuesday evening and continued intermittently through Wednesday morning before normal operations were restored. According to Threema, the service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday.

Users also experienced short, intermittent disruptions on Wednesday morning as the attacks continued and shifted in pattern. Threema confirmed that all services had returned to normal operation by 12:23 p.m. CEST.

A distributed denial-of-service attack, commonly known as a DDoS attack, attempts to make an online service unavailable by overwhelming its infrastructure with a very high volume of traffic.

Unlike a conventional attack launched from a single system, DDoS operations use many sources, often including compromised devices spread across different networks and locations. This distributed approach makes mitigation more difficult.

Security teams cannot simply block a single malicious IP address because attackers can rapidly change traffic sources, request types, and attack patterns. The result is often a continuous contest between defenders adapting their filtering controls and attackers modifying their methods.

Threema Hit by Massive DDoS Attack

Threema said the attacks targeted both its infrastructure and its colocation partner, Nine. It remains unclear whether Threema was the sole intended target or whether the activity was part of a broader campaign against multiple organizations.

The company described the incident as an ongoing wave of attacks with constantly changing patterns, making it more challenging to block without affecting legitimate users.

Importantly, Threema stressed that the attacks affected service availability rather than the confidentiality or security of user data. A DDoS attack does not inherently provide attackers with access to servers, messages, account data, or internal systems.

Its purpose is to consume network bandwidth, processing capacity, or other infrastructure resources until valid user requests can no longer be handled reliably.

The incident also affected Threema’s public status page. The company said the page was initially not updated because of a separate technical issue unrelated to the DDoS activity.

The status page was temporarily taken offline until that issue was resolved, limiting the availability of official outage information during part of the incident.

Threema communicated updates through its social media channels and notified Threema Work business customers by email on Wednesday morning. Account managers also responded to customer inquiries as the service instability continued.

Organizations using Threema OnPrem were not affected. The OnPrem product operates on customer-managed infrastructure, meaning those deployments remained available while Threema’s hosted service was under attack.

In response to the incident, Threema implemented an additional specialized DDoS protection mechanism. The new control filters malicious traffic upstream before it reaches Threema’s core infrastructure, reducing the burden on internal systems and existing defensive layers.

The company confirmed on August 14, 2026, at 6:05 p.m. CEST that the upstream filtering protection had been activated in its production environment.

Threema also plans to expand its status page with incident history and an RSS feed. This would provide users and Threema Work administrators with an independent channel to receive system status alerts during future outages.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Threema Secure Messaging Service Hit by Massive DDoS Attack appeared first on Cyber Security News.

Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes

A newly identified Linux botnet dubbed Evooo1Bot is targeting vulnerable internet-facing routers, edge appliances, cameras, and enterprise systems, combining Mirai-derived DDoS capabilities with proxy relaying, credential theft, SSH brute forcing, and exploit-driven propagation. FortiGuard Labs observed activity beginning in July 2026, with operators using a modular toolset that elevates compromised devices from disposable DDoS nodes […]

The post Evooo1Bot Turns Compromised Routers Into DDoS Bots and Anonymous Proxy Nodes appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Cyber Security News
  • 1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity Abinaya
    Cloudflare has reported a sharp rise in large-scale distributed denial-of-service attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 terabit per second. The company said hyper-volumetric attacks grew 519% between the first and second quarters, showing that attackers are increasingly capable of delivering extreme traffic floods at a rapid pace. The findings appear in Cloudflare’s 25th DDoS Threat Report, which combines data from January through June 2026.
     

1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity

13 de Agosto de 2026, 08:55

Cloudflare has reported a sharp rise in large-scale distributed denial-of-service attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 terabit per second.

The company said hyper-volumetric attacks grew 519% between the first and second quarters, showing that attackers are increasingly capable of delivering extreme traffic floods at a rapid pace.

The findings appear in Cloudflare’s 25th DDoS Threat Report, which combines data from January through June 2026. Unlike previous reports that covered each quarter separately, this edition provides a half-year view of attacks observed and mitigated across the Cloudflare network.

During the period, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion HTTP DDoS requests. This amounts to roughly 5,343 network-layer attacks per hour, or about 128,000 per day.

Cloudflare Blocks 935 DDoS Attacks Over 1 Tbps

The figures show that DDoS activity remains a constant operational threat for organizations operating public-facing infrastructure. Hyper-volumetric DDoS attacks are defined as attacks exceeding 1 Tbps, 1 billion packets per second, or 1 million requests per second.

Hyper-volumetric attacks (Source : cloudflare )
Hyper-volumetric attacks (Source: Cloudflare)

Cloudflare mitigated 805 attacks above 1 Tbps during the second quarter alone. These attacks can overwhelm internet connections, network equipment, and data centers before security teams have time to investigate alerts or manually activate mitigation controls.

Despite the growth of record-scale attacks, most DDoS incidents were smaller and shorter. Cloudflare said 96.62% of network-layer attacks stayed below 500 Mbps, while 90.60% ended in less than 10 minutes.

April 2026 was a peak month for DDoS activity and volume (Source : cloudflare )
April 2026 was a peak month for DDoS activity and volume (Source: Cloudflare)

However, even a 100 Mbps flood can disrupt an unprotected website or server. A short attack can also cause longer service problems, including routing instability, TCP retransmissions, application timeouts, and degraded downstream services.

The main attack vectors also changed significantly. DNS-based attacks represented 34.3% of all network-layer DDoS activity during the first half of the year. DNS floods increased from 25.7% of attacks in the first quarter to 40.0% in the second quarter.

Attackers use DNS floods to exhaust the query capacity of authoritative DNS servers, potentially making domains and related online services inaccessible.

CLDAP floods also grew 580% quarter over quarter, becoming the third-most-common network-layer attack vector in the second quarter.

Top attack source countries (Source : cloudflare )
Top attack source countries (Source: Cloudflare)

This technique abuses exposed LDAP-over-UDP services, often on UDP port 389, to reflect amplified traffic at victims using spoofed source addresses.

Geopolitical events continued to influence targeting patterns. Media, Production and Publishing was the most attacked industry in both quarters, receiving 14.2% of all mitigated HTTP DDoS requests. Cloudflare linked sustained pressure on the sector to coverage of events involving Iran, Ukraine, and the World Cup.

Government organizations also saw a major shift. The sector moved from 29th place in the first quarter to ninth place in the second quarter during Operation Epic Fury.

Meanwhile, China ranked as the most attacked location in the second quarter, followed by the United States and Turkey. Cloudflare said automated, always-on protection is essential because modern DDoS attacks can begin, peak, and end within seconds.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post 1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity appeared first on Cyber Security News.

Cloudflare Mitigates 23.2 Million DDoS Attacks as 1 Tbps Attacks Surge 519%

Cloudflare has mitigated 23.2 million network-layer DDoS attacks and stopped 29.64 trillion HTTP DDoS requests during the first half of 2026. This underscores a significant increase in both the frequency and intensity of Internet-scale attacks. The company’s latest DDoS Threat Report, produced by its Cloudforce One threat intelligence team, combines data collected from January to […]

The post Cloudflare Mitigates 23.2 Million DDoS Attacks as 1 Tbps Attacks Surge 519% appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

  • ✇Security Affairs
  • Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum Pierluigi Paganini
    Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following public disclosures of the botnet’s earlier activity. The new version substantially upgrades the DDoS capabilities and command infrastructure of a botnet that has been targeting Android TV boxes since August 2025, while its Linux counterpart AISURU has been active since mid-2024. The opera
     

Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum

12 de Agosto de 2026, 05:27

Kimwolf v7: The Android TV Botnet That Now Hides Its Traffic Behind Chrome Fingerprints and Ethereum

Palo Alto Networks Unit 42 discovered Kimwolf v7 on February 3, 2026, while hunting threats following public disclosures of the botnet’s earlier activity.

The new version substantially upgrades the DDoS capabilities and command infrastructure of a botnet that has been targeting Android TV boxes since August 2025, while its Linux counterpart AISURU has been active since mid-2024. The operators’ core objective hasn’t changed, build a large-scale DDoS platform, but the methods for sustaining it and hiding its traffic have become considerably more sophisticated.

“This version upgrades its distributed denial-of-service (DDoS) attack capabilities and the resilience of its command-and-control (C2) infrastructure. Kimwolf primarily affects Android TV boxes and set-top boxes.

Kimwolf v7 adds an HTTP/2-based DDoS flood that constructs complete browser fingerprints. This makes attack traffic more difficult to distinguish from legitimate browsing.” reads the report by Palo Alto Networks.

“The threat’s binary includes five hard-coded public Ethereum-based endpoints for resolving Ethereum Name Service (ENS) domains. ENS is a blockchain-based naming system used to obtain C2 addresses.”

The nghttp2 library powers the HTTP/2 flood and constructs headers that mirror legitimate Chrome browser behavior at the protocol level, making rate-limiting and fingerprint-based DDoS mitigation significantly harder.

On top of that, the botnet uses Ethereum’s naming service to resolve its command server address, querying five legitimate public blockchain RPC endpoints shuffled randomly before each attempt, which means blocking any individual endpoint does almost nothing.

“Kimwolf also carries a hard-coded Tor .onion hidden service as a backup and a local proxy architecture for flexible routing between clearnet and Tor.” continues the report. “The malware developers added this function to directly respond to C2 server takedown efforts in December 2025.”

The three-tier structure, Ethereum ENS, then Tor hidden service, then local proxy on 127.0.0.1:23075, is a direct operational response to two takedowns the botnet suffered in December 2025. The local proxy routes all C2 traffic through the same local address regardless of whether it’s going to the clearnet or Tor, which means the proxy component can be updated independently without redeploying the main bot binary. Unit 42 also identified what it assesses with moderate confidence to be an operator-controlled RPC facade at eth.rpcuniverse.com, based on its single-tenant hosting, registration timing, and exclusive presence in Kimwolf samples.

Kimwolf spreads by abusing residential proxy services to reach Android TV boxes that ship with Android Debug Bridge enabled on port 5555. Once tunneled into a local network through a proxy endpoint, attackers can install the malware without any authentication. The botnet masks itself as “netd_service” to blend in with legitimate Android system processes, and Unit 42 found eight APK packages distributed between October and December 2025 that masquerade as a system service called SystemService, probing for root access before executing a bundled kernel payload.

Version 7 also strips out all scanning, exploitation, and brute-force functionality from the main binary — the operators have separated the propagation pipeline from the DDoS core. External loaders now handle initial access, while the Kimwolf binary handles attacks and acts as a relay. The attack method count was consolidated from 43 text-named commands in earlier versions to 15 numbered methods covering layers 3 through 7, including the new HTTP/2 flood, a high-performance UDP flood with ARM NEON SIMD acceleration optimized for the processors in Android TV boxes, and a TLS/HTTPS flood. Unit 42 clustered C2 infrastructure across 22 IP addresses in Saint Petersburg, Russia, all sharing the same SSH host key between December 2025 and February 2026.

The defensive guidance from Unit 42 is straightforward: treat Android TV boxes as untrusted devices and segment them from enterprise networks. Disabling ADB or restricting it to USB-only access removes the primary way this botnet gets onto devices. For detection, watch for outbound HTTPS connections to Ethereum RPC endpoints from devices that normally have no business touching blockchain services, Tor circuit activity or SOCKS5 proxy traffic from TV boxes, connections to localhost port 23075, and any Android consumer device running a process named “netd_service.”

“Kimwolf v7 is a focused evolution of an already large-scale botnet. The HTTP/2 flood with Chrome browser fingerprinting complicates application-layer DDoS mitigation, as attack traffic now mirrors legitimate browser behavior at the protocol and header level.” concludes the report. “The three-tier C2 system (Ethereum ENS, Tor .onion, local proxy) indicates that the operators are investing in infrastructure built to withstand takedown operations.”

In March, the U.S. DoJ disrupted command-and-control infrastructure used by several IoT botnets, including AISURUKimwolf, JackSkid, and Mossad. The operation involved authorities from Canada and Germany, along with major tech companies, to target botnet operators and weaken their global cybercrime activities.

The AISURU/Kimwolf botnet was linked to a record-breaking DDoS attack that peaked at 31.4 Tbps and lasted just 35 seconds. Cloudflare said the November 2025 incident was part of a surge in hyper-volumetric HTTP DDoS attacks observed in late 2025, all automatically detected and mitigated.

Kimwolf is a newly discovered Android botnet linked to the Aisuru botnet that has infected over 1.8 million devices and issued more than 1.7 billion DDoS attack commands, according to XLab.

The Kimwol Android botnet primarily targets TV boxes, compiled using the NDK and equipped with DDoS, proxy forwarding, reverse shell, and file management functions. It encrypts sensitive data with a simple Stack XOR, uses DNS over TLS to hide communication, and authenticates C2 commands with elliptic curve digital signatures. Recent versions even incorporate EtherHiding to resist takedowns via blockchain domains.

Kimwolf follows a naming pattern of “niggabox + v[number]”; versions v4 and v5 have been tracked. By taking over one C2 domain, researchers observed around 2.7 million IPs interacting over three days, indicating a likely infection scale exceeding 1.8 million devices. Its infrastructure spans multiple C2s, global time zones, and versions, making it hard to estimate the total number of infections.

The botnet borrows the code from the Aisuru family, however, operators redesigned it to evade detection. Its primary function is traffic proxying, though it can execute massive DDoS attacks, as seen in a three-day period issuing 1.7 billion commands between November 19 and 22.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Kimwolf v7)

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails

Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

New Dolphin X Malware Uses AI Profiler to Rank High-Value Victims

Dolphin X malware targets more than 300 apps and includes an AI Profiler that scores infected Windows PCs to help criminals identify high-value victims quickly.

FBI and Spanish Police Arrest Alleged Cyber Army of Russia Reborn Member

Spanish police and the FBI arrested an alleged Cyber Army of Russia Reborn member as international efforts against pro Russia cyberattacks continue worldwide.
  • ✇Firewall Daily – The Cyber Express
  • Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests Ashish Khaitan
    A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed denial-of-service (DDoS) assault designed to overwhelm the company's infrastructure and hinder public access to its journalism. According to Tempo's technology team, the attacks generated an extraordinary
     

Indonesian Media Outlet Tempo Targeted by 24.9 Million DDoS Requests

cyberattacks on Tempo

A major wave of cyberattacks on Tempo has disrupted access to one of Indonesia's leading news websites, with the media outlet reporting millions of malicious requests directed at its servers over several days. The Tempo cyberattack, which began on Friday, June 5, 2026, involved a distributed denial-of-service (DDoS) assault designed to overwhelm the company's infrastructure and hinder public access to its journalism. According to Tempo's technology team, the attacks generated an extraordinary volume of fake internet traffic, placing significant pressure on the organization's servers and temporarily affecting the availability of the website for readers in Indonesia and elsewhere.

24.9 Million Requests Recorded During Cyberattacks on Tempo 

Tempo Digital Chief Technology Officer Heru Tjatur Tjahja said the cyberattacks on Tempo had reached an unprecedented scale. By Monday, June 8, 2026, the company's monitoring systems had logged a total of 24.9 million requests aimed at its servers.  “The total attacks flooding our website as of June 8 reached 24.9 million requests,” Tjahja said on Monday, June 8, 2026.  The Tempo cyberattack relied on bot-generated traffic, a common tactic used in DDoS incidents. Such attacks typically involve networks of compromised devices sending enormous numbers of requests simultaneously, overwhelming targeted systems and making websites difficult or impossible to access.  Tjahja explained that preliminary findings indicated the attacks occurred intermittently but intensified dramatically during certain periods. 

Largest Wave Hit During Evening Hours 

The investigation into the cyberattacks on Tempo revealed a pattern in the timing of the attacks. According to Tjahja, the attackers frequently launched their operations during evening and early morning hours, when activity surged sharply.  One of the most significant attack waves occurred between 8:30 p.m. and midnight. During that period alone, Tempo recorded 12.97 million attack requests within a span of just two hours.  “For example, the first major wave consisted of 12.97 million attacks in only two hours. From 8:30 p.m. until midnight, the attackers carried out a digital assault,” he said.  The intensity of the attack highlighted the scale of resources being used against the Indonesian media organization. 

Attack Traffic Traced Beyond Indonesia 

Early analysis conducted by Tempo's technology team suggested that the sources of the malicious traffic extended well beyond Indonesia's borders.  While the exact identities of those responsible remain unclear, investigators traced attack activity to multiple countries. According to Tempo, traffic associated with the cyberattacks on Tempo originated from Colombia, the United States, the Philippines, Bangladesh, Mexico, and Indonesia.  The international nature of the attack traffic reflects the complexity of modern DDoS operations, which often use distributed networks of compromised devices globally to conceal the origin of an attack. 

Possible Link to Earlier CMS Breach Attempt 

Tjahja believes the Tempo cyberattack may be connected to an earlier security incident that targeted the organization's content management system (CMS) at the end of May 2026.  During that earlier intrusion attempt, attackers managed to unpublish several articles that had already been published on the website. According to Tjahja, the content affected by the breach involved corruption-related reporting.  However, the CMS architecture limited the level of access available to unauthorized users. As a result, the attackers were unable to permanently remove the articles and could only temporarily unpublish them.  According to Tjahja, the sequence of events suggests a possible connection between the two incidents.  “It appears that those behind the attacks were unhappy and then proceeded with the DDoS attack,” he said. 

TV boxes maliciosas: descubra como uma “SuperBox” barata transforma sua casa em um nó proxy para cibercriminosos | Blog oficial da Kaspersky

2 de Junho de 2026, 10:00

Netflix, Apple TV+, Disney+, Hulu, Amazon Prime, YouTube Premium… Hoje em dia, as famílias que seguem a lei costumam pagar, em média, de cinco a dez assinaturas apenas para assistir ao conteúdo que desejam, com gastos mensais facilmente ultrapassando a casa dos cem dólares. Não é surpresa, portanto, que as redes sociais e os marketplaces on-line estejam registrando um aumento na demanda por “caixas mágicas”. Surgidas no final de 2025, essas TV boxes Android prometem desbloquear milhares de canais e oferecer acesso gratuito a serviços de streaming mediante um único pagamento.

Os anúncios desses dispositivos estão inundando o TikTok e o Instagram: influenciadores sorridentes tiram os SuperBoxes da caixa, conectam-nos à TV e navegam por inúmeros canais. Parece a solução perfeita contra o alto preço das assinaturas, certo? Mas, na prática, essa é uma das formas mais fáceis de permitir a entrada de uma botnet na sua rede doméstica.

Captura de tela de um vídeo do TikTok mostrando um SuperBox em ação

Um vídeo promocional no TikTok explicando como é ótimo quando tudo é grátis simplesmente cancelar todas as suas assinaturas

O que há de errado com essas TV boxes baratas?

Já surgiram vários relatos sobre TV boxes maliciosas, mas agora sua divulgação atingiu uma escala realmente alarmante.

No final de 2025, analistas examinaram vários modelos do SuperBox, um dispositivo popular disponível nas principais lojas de varejo e marketplaces on-line. As descobertas foram muito preocupantes: logo após serem ligados, os dispositivos começaram a enviar solicitações aos servidores do aplicativo de mensagens chinês Tencent QQ e ao serviço de proxy Grass, efetivamente disponibilizando a largura de banda da Internet do usuário para terceiros.

Dentro do firmware, os pesquisadores descobriram aplicativos completamente incomuns em um reprodutor de mídia: um scanner de rede, um analisador de tráfego e ferramentas de sequestro de DNS. Com isso, o dispositivo não apenas transmite conteúdo pirata, mas também vasculha a rede local em busca de outros alvos (incluindo interfaces industriais SCADA) e fica pronto para participar de ataques DDoS. Também foi descoberto que os SuperBoxes contêm pastas com o nome revelador “secondstage”, um forte indício de malware em vários estágios.

Mais recentemente, em abril de 2026, o podcast Darknet Diaries publicou uma entrevista com um pesquisador de segurança conhecido pelo pseudônimo D3ada55, que compartilhou diversos detalhes preocupantes sobre essas caixas, incluindo o fato de que elas ainda eram vendidas livremente em plataformas como Amazon, Walmart e Best Buy.

A evolução da infecção: do BADBOX ao Keenadu

O caso do SuperBox está longe de ser a única ocorrência em que os dispositivos Android foram transformados em nós de botnet ou vendidos com infecções de fábrica. Aqui estão os casos mais recentes:

  • BADBOX 2.0. Em julho de 2025, a Google processou os operadores de uma botnet que comprometeu mais de 10 milhões de dispositivos Android, principalmente TV boxes, tablets e projetores baratos que não tinham certificação do Google Play Protect. Conforme informamos anteriormente, o BADBOX 2.0 tem como alvo TV boxes e opera tanto como uma rede proxy quanto como uma plataforma de fraude publicitária.
  • Kimwolf. Em dezembro de 2025, a equipe do QiAnXin XLab descobriu uma botnet DDoS que havia sequestrado cerca de 1,8 milhão de dispositivos Android. O hardware infectado incluía modelos genéricos de fabricantes pouco conhecidos que usavam nomes chamativos como TV BOX, SuperBox, XBOX, SmartTV e outros. O alcance da infecção foi enorme, com dispositivos comprometidos distribuídos para o mundo todo. Os países mais atingidos foram o Brasil, Índia, Estados Unidos, Argentina, África do Sul, Filipinas e México.
  • Keenadu. Nossos especialistas descobriram esse malware à espreita no firmware de dispositivos novos em novembro de 2025, mas ele só chamou atenção depois de publicarmos um estudo sobre ele em fevereiro de 2026. O Keenadu se disfarça de componente legítimo do sistema, até mesmo entrando em aplicativos de desbloqueio facial e potencialmente concedendo aos invasores acesso a dados biométricos, informações bancárias e mensagens pessoais.

Todas essas histórias compartilham a mesma origem: o cavalo de Troia Triada, documentado pela primeira vez pelos nossos pesquisadores em 2016 e apelidado na época de “um dos cavalos de Troia móveis mais avançados”. Ao longo da última década, ele evoluiu de um malware comum para um backdoor modular integrado diretamente ao firmware durante a fabricação.

Como o esquema de infecção funciona

Os fabricantes de TV boxes baratas cortam gastos em tudo: certificação do Google Play Protect, auditorias de firmware e atualizações de segurança. Muitos desses dispositivos são executados no Android Open Source Project sem nenhuma garantia de segurança. Em algum lugar ao longo da cadeia de suprimentos, seja na fábrica, por meio de um intermediário ou em uma distribuidora, um backdoor é injetado na imagem do firmware. Nossos especialistas suspeitam que o próprio fabricante pode nem estar ciente do comprometimento.

A escala da infecção transforma milhões de caixas idênticas na base perfeita para uma botnet: cada dispositivo comprometido representa um endereço IP exclusivo que pode ser alugado para terceiros. Operadores de botnet, como o Kimwolf, lucram com isso não apenas por meio de ataques DDoS distribuídos, mas também revendendo a largura de banda de smart TVs e TV boxes infectadas.

O que isso significa para você

Uma TV box infectada fica na sala de estar, conectada ao Wi-Fi doméstico. Isso significa que ela pode detectar smartphones com aplicativos bancários, unidades de armazenamento conectadas à rede (NAS) com arquivos da família, câmeras IP, fechaduras inteligentes, computadores de trabalho e qualquer outro dispositivo conectado à sua rede Wi-Fi.

Com esse tipo de vetor de acesso inicial dentro da sua rede doméstica, um invasor pode interceptar tráfego não criptografado, falsificar solicitações de DNS, verificar portas e procurar vulnerabilidades em dispositivos vizinhos. Além disso, seu endereço IP pode ser usado para atividades fraudulentas. Como resultado, na melhor das hipóteses, seu IP acabará entrando em listas de bloqueio, e serviços legítimos começarão a barrar seu acesso por atividade suspeita; na pior, autoridades podem bater à sua porta.

Como identificar um gadget potencialmente perigoso

Você deve ficar alerta se um dispositivo:

  • For vendido sob uma marca sem nome ou genérica, como T95, X96Q, MX10, TV BOX, SuperBox ou similares
  • Promete acesso vitalício gratuito a serviços premium pagos mediante um único pagamento
  • Exige que você desative o Google Play Protect ou instale APKs de terceiros durante a configuração inicial
  • Não tem uma certificação do Play Protect
  • É promovido por meio de campanhas agressivas de spam nas redes sociais

Como evitar hospedar um nó de botnet

  • Compre TV boxes certificadas com Google Play Protect ou adquira dispositivos diretamente de operadoras de telecomunicações e provedores de Internet confiáveis.
  • Isole todos os dispositivos domésticos inteligentes. Configure uma rede Wi-Fi separada no roteador da sua casa para TV boxes, câmeras, alto-falantes inteligentes, aspiradores robóticos e dispositivos semelhantes, mantendo smartphones, unidades NAS e computadores na rede principal. Isso evita que o malware se espalhe para seus dispositivos mais importantes.
  • Atualize o firmware com frequência em todos os dispositivos, e não se esqueça do roteador, pois ele também representa um elo vulnerável na cadeia.
  • Remova todos os aplicativos da TV box Android que não foram instalados por você, especialmente lojas de aplicativos alternativas, “impulsionadores” de Wi-Fi e “limpadores de sistema”.
  • Monitore o tráfego da sua rede. Roteadores modernos e o Kaspersky Premium conseguem exibir os destinos de conexão de cada dispositivo. Conexões frequentes entre um reprodutor de mídia e servidores na China representam um forte sinal de alerta de segurança.
  • Instale o Kaspersky Premium em todos os seus dispositivos, pois ele protege contra cavalos de Troia e bloqueia páginas de phishing usadas para distribuir arquivos APK infectados.
  • Não desative o Google Play Protect e evite instalar APKs de fontes duvidosas, pois esse é o principal vetor de infecção usado para burlar a loja oficial de aplicativos.
  • Em caso de dúvida, devolva a TV box. Não vale a pena arriscar sua biometria, dados bancários ou a reputação do seu endereço IP por causa de um dispositivo de streaming barato.

Quer saber como proteger seus dispositivos domésticos inteligentes? Leia mais nas nossas postagens relacionadas:

A sua TV, seu smartphone e seus alto-falantes inteligentes estão espionando você?

Seu roteador está trabalhando secretamente para inteligências estrangeiras?

Casa não tão inteligente

Lar, smart lar

Como proteger sua casa smart

Massive “Low and Slow” DDoS Attack Hits Platform With 2.45 Billion in 5 Hours

DataDome researchers uncovered a massive low and slow DDoS attack that delivered 2.45 billion requests using 1.2 million IP addresses.

Hackers Use Jenkins Access to Deploy DDoS Botnet Against Gaming Servers

A new campaign shows misconfigured Jenkins servers abused to deploy a DDoS botnet targeting gaming systems, with Valve Corporation infrastructure in focus.
  • ✇Firewall Daily – The Cyber Express
  • eBay Struggles with Widespread Outage, Disrupting Transactions and API Access Ashish Khaitan
    The e-commerce platform eBay, a giant in online auctions and fixed-price listings, faced widespread disruptions beginning late Sunday, April 26, 2026, extending into Monday, as users across the globe reported severe technical issues. The eBay outage, which has crippled essential features of the site, particularly the API, has left many buyers and sellers frustrated, struggling to access critical functions, including search features, listings, and checkout processes.  As users faced slow page
     

eBay Struggles with Widespread Outage, Disrupting Transactions and API Access

eBay Outage

The e-commerce platform eBay, a giant in online auctions and fixed-price listings, faced widespread disruptions beginning late Sunday, April 26, 2026, extending into Monday, as users across the globe reported severe technical issues. The eBay outage, which has crippled essential features of the site, particularly the API, has left many buyers and sellers frustrated, struggling to access critical functions, including search features, listings, and checkout processes.  As users faced slow page loads, failed transactions, and difficulty completing sales, a series of unverified reports surfaced suggesting that the hacktivist group 313 Team was behind the massive denial-of-service (DDoS) attack, claiming responsibility for the outage. While the true cause remains unconfirmed by eBay, the timing and scale of the disruption have fueled speculation that a cyberattack was involved. 

The Scope of the eBay Outage 

The eBay outage first began to affect eBay users on the afternoon of April 26, when they began reporting issues with the platform’s functionality. According to Downdetector, a popular service that tracks online outages, the spike in complaints reached around 3:30 PM ET, with the situation worsening the evening. As of 10:30 PM ET, more than 1,300 outage reports were logged, although the number eventually decreased to about 600 by 11:50 PM ET.  Users complained that essential functions like search were malfunctioning, and pages were loading extremely slowly. "I can't even search for anything or complete a purchase," one frustrated user posted on social media. Others echoed similar concerns, noting that critical transactions were unable to be completed, with error messages preventing them from checking out.  Sellers also voiced their frustrations, noting that they could not access the API, which is crucial for the functioning of third-party tools used to manage listings, inventory, and sales. "It’s been nearly 6 hours since the API went down, and we have no word from support," one seller wrote, emphasizing the financial impact of the outage. 

Social Media Users Complain About the Outage

While eBay has not officially confirmed the cause of the outage, rumors quickly began circulating on social media that the hacktivist group 313 Team was responsible for a DDoS attack targeting the platform. DDoS attacks, which flood a website with traffic to overwhelm its servers and take it offline, have become a frequent tactic for hacktivist groups in recent years. The group, which has previously targeted high-profile organizations, allegedly posted a claim on various forums, taking credit for the disruption. However, this attribution has not been independently verified, and eBay has not provided details about the nature of the attack. The company’s official status page displayed no alerts of a cyberattack, showing only minor updates on the system’s functionality.  Despite these official updates, the community’s response has been vocal, with many users continuing to report issues well into the night. One individual posted, "It’s not just down for me, it’s down for everyone. Is this part of a bigger attack targeting e-commerce sites?"  With eBay’s customer support channels largely silent or offering only generic responses, users took to social media to express their frustration. The company’s Instagram account, where many users had previously reached out for help, quickly became a forum for complaints. One commenter wrote, “Brooo you’re down—come on, get up! I need to pay for an auction.” Others left similar messages, questioning the reliability of the platform and demanding answers. 

Bluesky Back Online After DDoS Attack, as Iran-Linked 313 Team Takes Credit

Bluesky is back online after a roughly 24-hour DDoS attack disrupted services, with the Iran-linked 313 Team claiming responsibility and no data breach reported.
  • ✇Firewall Daily – The Cyber Express
  • Bluesky, Fast-Growing X Alternative, Hit by Sophisticated DDoS Attack Ashish Khaitan
    A service disruption at Bluesky last week exposed the growing challenges faced by fast-expanding social media platforms, after the company confirmed that a “sophisticated” distributed denial-of-service (DDoS) incident was behind widespread outages. The Bluesky cyberattack began late on April 15, 2026, and quickly escalated, interrupting core functions across the app and leaving users unable to reliably access feeds, notifications, threads, and search.  The incident occured at a time when Blue
     

Bluesky, Fast-Growing X Alternative, Hit by Sophisticated DDoS Attack

Bluesky cyberattack

A service disruption at Bluesky last week exposed the growing challenges faced by fast-expanding social media platforms, after the company confirmed that a “sophisticated” distributed denial-of-service (DDoS) incident was behind widespread outages. The Bluesky cyberattack began late on April 15, 2026, and quickly escalated, interrupting core functions across the app and leaving users unable to reliably access feeds, notifications, threads, and search.  The incident occured at a time when Bluesky has been experiencing rapid user growth, making it a more visible target for large-scale attacks. While disruptions of this nature often raise concerns about potential data breaches or unauthorized access, the company repeatedly stated that the attack was limited to service availability.   Throughout the outage, Bluesky issued a series of public updates to keep users informed about the platform’s status and the steps being taken to mitigate the attack.  

Bluesky Cyberattack Disrupts Core Platform Functions 

The disruption began at approximately 11:40 PM PDT on April 15, when Bluesky received initial reports of intermittent outages. Engineers responded immediately, working overnight to contain what was later described as a “sophisticated” DDoS attack. As the attack intensified over the next several hours, it began to impact the platform’s functionality.  In an early update, Bluesky stated: “We are experiencing some service interruptions, and our team is working on the issue. You can find the latest updates at status.bsky.app or follow @status.bsky.app.”  As more users reported issues, the company clarified the extent of the disruption: “The attack is impacting our application, with users experiencing intermittent interruptions in service for their feeds, notifications, threads and search.”  DDoS attacks function by overwhelming servers with massive volumes of traffic, effectively preventing legitimate users from accessing services. In this case, the cyberattack on Bluesky followed that pattern, focusing on disrupting availability rather than infiltrating systems or extracting sensitive data. 

Platform Stabilizes While Attack Continues 

By around 9 PM PDT on April 16, Bluesky reported that the platform had stabilized despite the continued presence of DDoS traffic. The company noted: “The application has remained stable since approximately 9 PM PDT, April 16 despite ongoing Distributed Denial-of-Service (DDoS) attacks. We have not seen any evidence of unauthorized access to private user data.”  This message was reiterated in subsequent updates, reinforcing the company’s position that user data remained secure. In its final communication on the incident, Bluesky stated: “The application has remained stable since the evening of April 16 and we have seen no evidence of unauthorized access to private user data. Given the ongoing stability, this will be our final update.” 

Attribution Remains Unclear as Platform Continues to Grow 

The company has not officially attributed the attack to any specific group or actor. However, a group identifying itself as “313 Team,” reportedly claimed responsibility through a Telegram message, stating that it had carried out a “massive cyberattack” targeting Bluesky’s application programming interface (API).  The incident comes amid a period of significant growth for the platform. Since its inception, Bluesky has expanded to approximately 43.7 million users, driven in part by users migrating from X following political developments in the United States 

Operation PowerOFF: 75K Users of DDoS-for-Hire Services Identified and Warned

Operation PowerOFF identifies and warns 75K users of DDoS-for-hire services, nets 4 arrests, and seizes 53 domains in a Europol-led crackdown.
❌
❌