✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
KadNap Malware: Over 14,000 Asus Routers Hijacked into Stealth Botnet
In August 2025, cybersecurity researchers identified a new malware strain named KadNap, which primarily targets Asus routers to conscript them into a botnet used for proxying malicious traffic. By March 2026, over 14,000 devices had been infected, with more than 60% located in the United States. KadNap employs a customized version of the Kademlia Distributed Hash Table (DHT) protocol, enabling it to conceal command-and-control (C2) infrastructure within a peer-to-peer network, thereby evading traditional network monitoring and enhancing resilience against detection and disruption efforts. The malware is distributed through a shell script that establishes persistence via cron jobs, downloads a malicious ELF file, and executes it, effectively integrating the compromised device into the botnet. ([thehackernews.com](https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html?utm_source=openai)) The emergence of KadNap underscores a growing trend of sophisticated malware targeting edge networking devices, exploiting their vulnerabilities to build resilient botnets. This incident highlights the critical need for organizations and individuals to secure their network infrastructure, as such compromised devices can be leveraged for various malicious activities, including anonymizing cybercriminal operations and facilitating large-scale attacks. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/new-kadnap-botnet-hijacks-asus-routers-to-fuel-cybercrime-proxy-network/?utm_source=openai))
4 months ago
Kill Chain
UNC4899's $1.5 Billion Cryptocurrency Heist: Lessons for the Industry
In February 2025, the North Korean state-sponsored hacking group UNC4899, also known as TraderTraitor, orchestrated a sophisticated cyberattack resulting in the theft of approximately $1.5 billion from the cryptocurrency exchange Bybit. The attackers compromised a developer's macOS workstation at Safe{Wallet}, a multisignature wallet platform, by deploying a malicious Docker project. This initial breach allowed them to hijack AWS session tokens, bypass multi-factor authentication, and inject malicious JavaScript into Safe{Wallet}'s application. Consequently, they manipulated a routine Ethereum transfer from Bybit's cold wallet to its hot wallet, redirecting the funds to addresses under their control. ([blog.it-expert.net](https://blog.it-expert.net/summaries/The-Feed_2025-03-10.html?utm_source=openai)) This incident underscores the escalating threat posed by state-sponsored cyber actors targeting the cryptocurrency sector. The use of advanced social engineering tactics, exploitation of cloud infrastructure vulnerabilities, and sophisticated supply chain attacks highlight the need for enhanced security measures and vigilance within the industry. ([thehackernews.com](https://thehackernews.com/2025/07/n-korean-hackers-used-job-lures-cloud.html?utm_source=openai))
4 months ago
Kill Chain
UAT-9244's New Malware Threatens South American Telecoms
Since 2024, the China-linked advanced persistent threat actor UAT-9244 has been targeting telecommunication service providers in South America, compromising Windows, Linux, and network-edge devices. The group employs three previously undocumented malware families: TernDoor, a Windows backdoor; PeerTime, a Linux backdoor utilizing the BitTorrent protocol; and BruteEntry, a brute-force scanner that establishes proxy infrastructure. These tools enable UAT-9244 to maintain persistent access, execute remote commands, and expand their network infiltration. This incident underscores the evolving sophistication of state-sponsored cyber threats targeting critical infrastructure. The use of novel malware and advanced techniques highlights the need for enhanced cybersecurity measures and vigilance within the telecommunications sector.
4 months ago
Kill Chain
The Rising Threat of Compromised cPanel Credentials in Cybercrime Markets
In March 2025, a cybercriminal known as "miya" advertised for sale compromised SSH, cPanel, Mail, and WebHost Manager (WHM) credentials belonging to a Canadian car dealership on a dark web forum, pricing the access at $400. These credentials provided potential attackers with privileged access to the dealership's critical systems, including remote command-line server control via SSH, administrative capabilities through WHM and cPanel, and access to sensitive communications via the mail server. The breach underscored the escalating cybersecurity risks faced by automotive retailers, who increasingly rely on interconnected digital systems to manage sales, customer data, and backend infrastructure. ([cyberpress.org](https://cyberpress.org/cybercriminal-miya-stolen/?utm_source=openai)) This incident highlights a broader trend of cybercriminals targeting cPanel and other site management credentials to facilitate unauthorized access to web servers and associated services. The sale of such credentials on underground forums has become increasingly common, with prices ranging from $3 to $5, depending on the target and level of access provided. ([documents.trendmicro.com](https://documents.trendmicro.com/assets/wp/wp-north-american-underground.pdf?utm_source=openai))
4 months ago
Kill Chain
Kimwolf Botnet's 2026 Rampage: A Wake-Up Call for IoT Security
In late 2025, the Kimwolf botnet emerged as a significant cybersecurity threat, infecting over 2 million Android devices worldwide, primarily targeting off-brand smart TVs and set-top boxes. Exploiting vulnerabilities in residential proxy networks and exposed Android Debug Bridge (ADB) services, Kimwolf transformed these devices into nodes for large-scale distributed denial-of-service (DDoS) attacks. Notably, in November 2025, the botnet launched a record-setting DDoS attack peaking at 31.4 terabits per second, underscoring its unprecedented scale and impact. ([thehackernews.com](https://thehackernews.com/2026/02/aisurukimwolf-botnet-launches-record.html?utm_source=openai)) The rapid proliferation and sophistication of Kimwolf highlight the escalating threat posed by botnets leveraging IoT devices. This incident underscores the urgent need for enhanced security measures in consumer electronics and the importance of proactive defense strategies to mitigate the risks associated with large-scale botnet attacks.
4 months ago
Kill Chain
Iran's 2026 Internet Blackout: A New Era of Digital Repression
In January 2026, the Iranian government imposed a comprehensive internet blackout amid escalating nationwide protests. This shutdown disrupted all forms of digital communication, including mobile networks, landlines, and even satellite services like Starlink. The blackout aimed to suppress the coordination of protests and conceal human rights violations. Concurrently, Iran implemented a two-tiered internet system, granting unrestricted access to government officials and loyalists via 'white SIM cards,' while the general populace faced severe restrictions. This strategy effectively isolated citizens, preventing both internal coordination and external information dissemination. The incident underscores a growing trend among authoritarian regimes to leverage internet control as a tool for social suppression. The international community has condemned these actions, emphasizing the need for global efforts to uphold internet freedom and human rights.
4 months ago
Kill Chain
Critical Unauthenticated RCE Vulnerability in Juniper Networks PTX Series Routers
In February 2026, Juniper Networks disclosed a critical vulnerability (CVE-2026-21902) in its Junos OS Evolved operating system running on PTX Series routers. This flaw, stemming from incorrect permission assignments in the On-Box Anomaly Detection framework, allows unauthenticated, network-based attackers to execute code with root privileges. The vulnerability affects Junos OS Evolved versions prior to 25.4R1-S1-EVO and 25.4R2-EVO, potentially leading to full device compromise. The exposure of such a critical service over externally accessible ports underscores the importance of rigorous access controls and timely patch management. Organizations relying on PTX Series routers should prioritize applying the provided patches or implementing recommended mitigations to prevent potential exploitation.
4 months ago
Kill Chain
Malicious StripeApi NuGet Package Mimics Official Library to Steal API Tokens
In February 2026, a malicious NuGet package named StripeApi.Net was discovered impersonating the legitimate Stripe.net library. Uploaded by a user named StripePayments on February 16, 2026, the package closely resembled the official library, using the same icon and nearly identical documentation. The threat actor artificially inflated the download count to over 180,000 across 506 versions to appear credible. The package replicated some of Stripe.net's functionality but modified critical methods to collect and exfiltrate sensitive data, including users' Stripe API tokens, to the attacker. The package was removed shortly after its discovery, minimizing potential damage. ([thehackernews.com](https://thehackernews.com/2026/02/malicious-stripeapi-nuget-package.html?utm_source=openai)) This incident underscores the persistent threat of supply chain attacks targeting software repositories. The use of typosquatting and artificial download inflation highlights the need for developers to exercise caution when integrating third-party libraries. Ensuring the authenticity of packages and monitoring for suspicious activity are crucial to maintaining software supply chain security.
4 months ago
Kill Chain
Critical Zyxel Router Vulnerability (CVE-2025-13942) Exposes Networks to Remote Attacks
In February 2026, Zyxel identified a critical command injection vulnerability (CVE-2025-13942) in the UPnP function of several router models, including 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and wireless extenders. This flaw allows unauthenticated remote attackers to execute operating system commands on affected devices by sending specially crafted UPnP SOAP requests. While the vulnerability has a CVSS score of 9.8, its exploitation is contingent upon both UPnP and WAN access being enabled, with the latter disabled by default. Zyxel has released security patches to address this issue and strongly advises users to update their firmware promptly. The significance of this vulnerability is underscored by the widespread deployment of Zyxel devices, often provided by internet service providers as default equipment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is monitoring multiple Zyxel vulnerabilities, highlighting the ongoing risk to network security.
5 months ago
Kill Chain
ShinyHunters Breach Exposes 6.2 Million Odido Customers in 2026
In February 2026, Dutch telecommunications provider Odido suffered a significant data breach orchestrated by the cybercriminal group ShinyHunters. The attackers infiltrated Odido's customer service system, compromising sensitive personal information of approximately 6.2 million customers. The stolen data included full names, home addresses, email addresses, phone numbers, bank account numbers (IBAN), dates of birth, and identity document details such as passport and driver's license numbers. ShinyHunters threatened to release this data on the dark web unless a ransom was paid. Odido confirmed the breach and advised customers to remain vigilant for potential misuse of their personal information. ([scancomply.com](https://scancomply.com/blog/february-2026-data-breach-report?utm_source=openai)) This incident underscores the escalating threat posed by sophisticated cybercriminal groups like ShinyHunters, who have previously targeted major organizations worldwide. The breach highlights the critical need for robust cybersecurity measures, especially in sectors handling vast amounts of personal data. Organizations must prioritize the implementation of advanced security protocols and employee training to mitigate the risks associated with such targeted attacks.
5 months ago
Kill Chain
Fake Gemini AI Chatbot Drives Google Coin Scam in 2026
In February 2026, cybercriminals launched a sophisticated scam involving a counterfeit AI chatbot impersonating Google's Gemini assistant to promote a fictitious cryptocurrency called 'Google Coin.' The fraudulent website, designed to mimic Google's branding, featured a chatbot that engaged users with convincing investment projections, claiming that a $395 investment could yield $2,755 upon listing. Victims were guided through a polished presale dashboard to make irreversible cryptocurrency payments, resulting in significant financial losses. ([malwarebytes.com](https://www.malwarebytes.com/blog/ai/2026/02/scammers-use-fake-gemini-ai-chatbot-to-sell-fake-google-coin?utm_source=openai)) This incident underscores the escalating use of AI-driven social engineering tactics in cybercrime. The ability of scammers to deploy AI chatbots that convincingly impersonate trusted brands highlights the urgent need for enhanced vigilance and verification mechanisms to protect consumers from such deceptive schemes.
5 months ago
Kill Chain
Keenadu Malware: A 2026 Android Supply Chain Attack
In early 2026, security researchers discovered 'Keenadu,' a sophisticated malware embedded within the firmware of various Android devices. This malware, introduced through a supply chain attack, integrates into the Android 'Zygote' process, allowing it to infect every application on the device. Once active, Keenadu grants attackers extensive control, enabling actions such as hijacking browser searches, committing ad fraud, and potentially accessing sensitive user data. The malware was found pre-installed on devices from multiple manufacturers, including the Alldocube iPlay 50 mini Pro tablet, and was also distributed through compromised applications on official app stores. As of February 2026, approximately 13,000 devices across countries like Russia, Japan, Germany, Brazil, and the Netherlands have been affected. ([darkreading.com](https://www.darkreading.com/mobile-security/supply-chain-attack-embeds-malware-android-devices?utm_source=openai)) This incident underscores the escalating threat of supply chain attacks targeting firmware, highlighting the need for rigorous security measures throughout the manufacturing and software development processes. The ability of Keenadu to operate at the firmware level makes detection and removal particularly challenging, emphasizing the importance of proactive security practices and the use of trusted devices and software sources.
5 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports