New Mirai botnet targets tens of flaws in popular IoT devicesSecurity Affairs·Jun 22, 20:58 UTC · Jun 22, 2023MalwareCVE-2019-12725CVE-2019-17621CVE-2019-20500+13 CVEs47
Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet CampaignsPalo Alto Unit 42·Mar 8, 18:14 UTC · Mar 8, 2019MalwareCVE-2018-10561CVE-2018-1562CVE-2018-10562+2 CVEs47
Multi-exploit IoT/Linux Botnets Mirai and Gafgyt Target Apache Struts, SonicWallPalo Alto Unit 42·Sep 17, 09:02 UTC · Sep 17, 2018MalwareCVE-2018-9866CVE-2017-5638CVE-2017-17215+1 CVEs47
Hacking the hackers - IOT botnet author adds his own backdoor on top of a ZTE router backdoorSecurity Affairs·Nov 12, 21:37 UTC · Nov 12, 2018Malware42
Backdoors in DKaspersky Securelist·May 23, 10:00 UTC · May 23, 2018MalwareCVE-2018-6212CVE-2018-6213CVE-2018-6211+1 CVEs47
Mozi Botnet is responsible for most of the IoT TrafficSecurity Affairs·Sep 20, 14:06 UTC · Sep 20, 2020MalwareCVE-2014-8361CVE-2017-17215CVE-2018-10561+1 CVEs47
New AyySSHush botnet compromised over 9,000 ASUS routers, adding a persistent SSH backdoor.Security Affairs·May 29, 06:19 UTC · May 29, 2025MalwareCVE-2023-3978047
New Mirai Variant and ZHtrap Botnet Malware Emerge in the WildThe Hacker News·Mar 18, 03:14 UTC · Mar 18, 2021MalwareCVE-2020-25506CVE-2021-27561CVE-2021-27562+4 CVEs47
Juniper Warns of Mirai Botnet Targeting SSR Devices with Default PasswordsThe Hacker News·Dec 24, 05:50 UTC · Dec 24, 2024MalwareCVE-2023-1389CVE-2018-1753247
Mirai Botnet Exploits Ivanti Connect Secure Flaws for Malicious Payload DeliveryThe Hacker News·May 9, 11:04 UTC · May 9, 2024MalwareCVE-2023-46805CVE-2024-2188747
RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoSThe Hacker News·Jun 30, 17:45 UTC · Jun 30, 2026Malware in the wildCVE-2017-17215CVE-2025-29635CVE-2024-1781+1 CVEs160
Linux Malware Delivered via Malicious RAR Filenames Evades Antivirus DetectionThe Hacker News·Aug 22, 15:33 UTC · Aug 22, 2025Malware42
Shellbot Botnet Targets IoT devices and Linux serversSecurity Affairs·Nov 6, 07:22 UTC · Nov 6, 2018Malware42
FIN7 hackers target enterprises with weaponized USB drives via USPSSecurity Affairs·Mar 29, 12:08 UTC · Mar 29, 2020Malware42
The EAGERBEE backdoor may be related to the CoughingDown actorKaspersky Securelist·Jan 6, 08:02 UTC · Jan 6, 2025Malware42
Eagerbee backdoor targets govt entities and ISPs in Middle EastSecurity Affairs·Jan 7, 06:23 UTC · Jan 7, 2025MalwareCVE-2021-2685547
FINALDRAFT Malware Exploits Microsoft Graph API for Espionage on Windows and LinuxThe Hacker News·Feb 28, 04:32 UTC · Feb 28, 2025Malware142
Thousands of Asus routers are being hit with stealthy, persistent backdoorsArs Technica · Security·May 28, 22:12 UTC · May 28, 2025MalwareCVE-2023-3978047
Researchers Warn of Facefish Backdoor Spreading Linux RootkitsThe Hacker News·May 29, 08:17 UTC · May 29, 2021Malware42
New Aquabot Botnet Exploits CVE-2024The Hacker News·Jan 30, 06:41 UTC · Jan 30, 2025Malware in the wildCVE-2024-41710CVE-2018-10561CVE-2018-10562+3 CVEs60
New Mozi P2P Botnet targets Netgear, D-Link, Huawei routersSecurity Affairs·Dec 25, 22:10 UTC · Dec 25, 2019MalwareCVE-2014-8361CVE-2017-17215CVE-2018-10561+1 CVEs47
The Death botnet grows targeting AVTech devices with a 2Security Affairs·Jul 25, 07:05 UTC · Jul 25, 2018Malware42
Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT DevicesThe Hacker News·Oct 29, 15:38 UTC · Oct 29, 2025Malware in the wildCVE-2017-9841CVE-2021-3129CVE-2022-47945+2 CVEs160
Necro Python Malware Upgrades With New Exploits and Crypto Mining CapabilitiesThe Hacker News·Jun 3, 17:01 UTC · Jun 3, 2021MalwareCVE-2021-21972CVE-2017-0144CVE-2017-014547
Toptal GitHub Breach Exposes 73 Repositories and Injects Malware into 10 npm PackagesThe Hacker News·Aug 6, 10:50 UTC · Aug 6, 2025Malware42
Kaspersky SOC analyzes an incident involving a web shell used as a backdoorKaspersky Securelist·Feb 28, 04:00 UTC · Feb 28, 2025Malware42
Netgear Routers' Flaws Expose Users to Malware, Remote Attacks, and SurveillanceThe Hacker News·May 12, 15:59 UTC · May 12, 2023MalwareCVE-2023-27357CVE-2023-27368CVE-2023-27369+2 CVEs47
FreakOut botnet target 3 recent flaws to compromise Linux devicesSecurity Affairs·Oct 12, 22:18 UTC · Oct 12, 2021MalwareCVE-2020-28188CVE-2021-3007CVE-2020-796147
Chaos RAT Malware Targets Windows and Linux via Fake Network Tool DownloadsThe Hacker News·Jun 4, 12:55 UTC · Jun 4, 2025MalwareCVE-2024-30850CVE-2024-3183947
New Condi Malware Hijacking TP-Link WiThe Hacker News·Jun 21, 05:36 UTC · Jun 21, 2023MalwareCVE-2023-138947
RustDuck: The Botnet That's Still Small but Engineering Like It Plans to GrowSecurity Affairs·Jul 1, 10:25 UTC · Jul 1, 2026Malware in the wildCVE-2025-29635CVE-2017-17215CVE-2024-1781+1 CVEs160
A new Mirai botnet variant targets DigiEver DSSecurity Affairs·Dec 26, 15:38 UTC · Dec 26, 2024MalwareCVE-2023-1389CVE-2018-1753247
Gafgyt botnet is targeting EoL Zyxel routersSecurity Affairs·Aug 11, 08:16 UTC · Aug 11, 2023Malware in the wildCVE-2017-18368CVE-2017-1836360
KashmirBlack, a new botnet in the threat landscape that rapidly growsSecurity Affairs·Oct 26, 17:09 UTC · Oct 26, 2020MalwareCVE-2017-9841CVE-2018-9206CVE-2019-9194+4 CVEs47
Most wanted malware in January 2019: A new threat speaks upHelp Net Security·Feb 14, 00:00 UTC · Feb 14, 2019Malware in the wildCVE-2017-7269CVE-2014-0160CVE-2014-034660
Kaspersky discovered a backdoor account and other issues in D-Link DIRSecurity Affairs·May 24, 06:17 UTC · May 24, 2018MalwareCVE-2018-6213CVE-2018-6210CVE-2018-6211+1 CVEs47
Updated - The new Wicked Mirai botnet leverages at least three new exploitsSecurity Affairs·May 20, 08:33 UTC · May 20, 2018MalwareCVE-2016-6277CVE-2018-1056147