✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
CISA 2025 Issues Guidance to Mitigate Bulletproof Hosting Provider Risks
In November 2025, the Cybersecurity and Infrastructure Security Agency (CISA), together with the NSA, FBI, Department of Defense Cyber Crime Center, and international partners, released comprehensive guidance to combat risks posed by Bulletproof Hosting Providers (BPHs). BPHs are infrastructure providers that knowingly lease servers and networking resources to cybercriminals, enabling ransomware, phishing, malware distribution, and denial-of-service attacks at scale. The guidance urges Internet Service Providers and network operators to apply blocklists, traffic analysis, intelligence sharing, and stronger vetting to prevent malicious actors from exploiting BPH resources, aiming to bolster the digital resilience of critical infrastructure sectors globally. The ongoing proliferation of cyberattacks leveraging BPH infrastructure underscores the urgency of these recommendations. With threat actors increasingly turning to anonymized, resilient hosting to evade law enforcement and detection, proactive mitigation by ISPs is crucial to limiting damage and strengthening industry-wide cybersecurity defense.
6 months ago
Kill Chain
ImunifyAV RCE Flaw Puts Millions of Linux Websites at Immediate Risk in 2024
In June 2024, a critical remote code execution (RCE) vulnerability was discovered in ImunifyAV, a malware scanner widely deployed on Linux web servers hosting millions of websites globally. Attackers could exploit this unauthenticated flaw to execute arbitrary code on vulnerable servers, potentially gaining full control over hosting environments and compromising customer websites at scale. The flaw threatened the security of hosting providers and their clients, enabling advanced threat actors to launch further attacks, steal data, or deploy additional malware. Immediate patching was required to prevent exploitation in the wild. This incident underscores the increasing risks posed by third-party security tool vulnerabilities, especially in shared and cloud-hosted web environments. Rapid exploitation of newly disclosed software flaws and supply chain attacks continues to rise, highlighting the critical importance of timely patch management and zero trust controls.
6 months ago
Kill Chain
Google Targets Smishing Triad: 2025 Lawsuit Disrupts Phishing-as-a-Service Operations
In November 2025, Google filed a landmark lawsuit in the Southern District of New York targeting the so-called "Smishing Triad," a China-based phishing-as-a-service group responsible for operating the Lighthouse phishing kit. This kit empowers cybercriminals to impersonate over 400 brands and conduct high-volume SMS attacks, luring victims worldwide into divulging payment information and one-time passcodes. Attackers leveraged the compromised data to enroll payment cards in mobile wallets on Apple and Google devices, allowing them to transact and cash out at scale. Google identified over a million victims in 120 countries, with Smishing Triad operators rotating up to 25,000 phishing domains in an eight-day window. The case highlights an increasing sophistication and industrialization of mobile phishing schemes, where threat actors utilize automation, rapid domain turnover, and collaboration across specialized roles. Legal escalation by a major tech company reflects growing efforts to disrupt cross-border cybercrime ecosystems that evade technical and regulatory countermeasures.
6 months ago
Kill Chain
Cloudflare Top Domain Rankings Compromised by Aisuru Botnet in 2025
In October 2025, Cloudflare faced an unprecedented attack by the Aisuru botnet, a rapidly scaling network of compromised IoT devices. The botnet leveraged its vast fleet to overwhelm Cloudflare's public DNS resolver (1.1.1.1) with massive volumes of automated queries, propelling its malicious command-and-control domains to the top ranks of Cloudflare's most-queried website list. This manipulation triggered widespread concern over data integrity and brand confusion, as Aisuru domains temporarily displaced legitimate top domains like Google and Apple. In response, Cloudflare resorted to redacting and eventually removing suspicious domains from its ranking list, highlighting significant security gaps in popular trust datasets. This incident underscores the mounting risk posed by large IoT botnets to critical internet infrastructure, including DNS reliability and reputation-based services. It reveals how attackers exploit both technical and social trust mechanisms, with potential downstream effects on security decisions that leverage third-party domain rankings.
6 months ago
Kill Chain
Arrest of 764 Group Leader Signals Crackdown on Online Child Exploitation and Extremism
In December 2023, Baron Cain Martin, alleged leader of the violent extremist group 764, was arrested in Tucson, Arizona, following an extensive federal investigation. Unsealed in June 2024, the indictment charges Martin with 29 counts, including producing and distributing child sexual abuse material (CSAM), cyberstalking, conspiracy to commit wire fraud, animal cruelty, and providing material support to terrorists. Federal law enforcement alleges that Martin not only led the illicit collective but also created detailed guides for grooming and exploiting minors. The operation exploited online anonymity, targeting vulnerable young individuals across the globe. At least nine victims, primarily minors, have been identified, with the group's activities linked to broader networks such as The Com. The Martin case spotlights alarming trends in cyber-enabled abuse and violent extremism, highlighting law enforcement’s ongoing efforts to dismantle depraved online collectives. The prosecution’s severity underscores rising societal and regulatory pressure to address digital child exploitation, encrypted criminal coordination, and psychologically manipulative methods used by such groups.
6 months ago
Kill Chain
Critical 2025 Raisecomm Authentication Bypass: Root Access Risk to ICS Networks
In October 2025, a critical remote authentication bypass vulnerability (CVE-2025-11534) was publicly disclosed in Raisecomm RAX701-GC series network equipment, allowing unauthenticated attackers to establish SSH sessions and gain root shell access without providing valid credentials. Discovered and reported by security researchers from runZero, this exploit poses an elevated risk to infrastructure sectors relying on these devices globally, as affected firmware versions remain susceptible with exploits achievable at low complexity and no prior privileges. Business and operational impacts include full remote compromise, lateral movement potential, and the ability for attackers to implant persistent threats or disrupt essential communications and IT operations. The incident is especially pressing now, indicating a rising trend in targeting embedded and edge devices in critical environments via misconfigurations or software flaws. As attackers expand their focus to accessible infrastructure, organizations face increasing pressure to implement robust access controls, proactive segmentation, and defense-in-depth strategies to safeguard operational networks.
6 months ago
Kill Chain
Aisuru Botnet’s 2025 Shift: From DDoS Disruptor to Proxy Powerhouse
In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations. This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.
6 months ago
Kill Chain
How Botnets Exploited Cloud Flaws in 2024: A Modern Security Wake-Up Call
In early 2024, security researchers observed an escalating wave of activity from botnets such as Mirai, leveraging vulnerabilities and misconfigurations across cloud environments and Internet-exposed assets. Attackers targeted PHP servers, IoT devices, and cloud gateways, exploiting both known flaws and weak security controls. Once compromised, these assets were co-opted into large-scale botnets used for distributed denial-of-service (DDoS) attacks, cryptomining, and lateral movement into business networks. The campaign underscored gaps in east-west traffic visibility, workload segmentation, and egress filtering, significantly increasing operational and reputational risk for enterprises. This incident is part of a growing trend where botnets and automated threat actors shift focus to cloud and hybrid environments, capitalizing on common misconfigurations. Organizations face mounting pressure to modernize defenses, as attackers rapidly adapt to evolving architectures and compliance expectations.
6 months ago
Kill Chain
North Korean BlueNoroff APT Hits Fintech and Web3 in Sophisticated 2024 Crypto Heist
In early 2024, the North Korean APT group BlueNoroff (a sub-group of Lazarus) launched sophisticated cross-platform campaigns against fintech executives and Web3 developers worldwide. The attackers utilized fake business collaboration and job recruitment lures distributed via phishing documents and messaging apps to implant malware on both Windows and macOS devices. Once in the network, BlueNoroff leveraged their established toolkits—including custom backdoors and credential stealers—to escalate privileges and ultimately exfiltrate cryptocurrency assets. This activity resulted in significant fund theft for several organizations, eroding trust in targeted fintech sectors. This incident highlights the continuous evolution of state-sponsored cybercrime groups, who now use highly adaptive social engineering paired with platform-agnostic malware. The financial sector, especially emerging blockchain and crypto startups, remains a primary focus amid a surge of advanced financially-motivated nation-state attacks.
6 months ago
Kill Chain
Spear-Phishers Impersonate Tesla & Red Bull Recruiters in Targeted Job Scam (2024)
In early 2024, cyber attackers launched a coordinated spear-phishing campaign targeting social media influencers and digital marketing professionals by impersonating talent recruiters from popular brands such as Tesla and Red Bull. The threat actors distributed convincing fake job offers via email and LinkedIn, luring victims to share personal information, credentials, and résumé files. The adversaries’ primary objectives were data theft and potential follow-up attacks leveraging stolen credentials and information, causing reputational damage and exposing a sensitive subset of professionals. This incident highlights the growing use of sophisticated social engineering tactics against targeted individuals in the digital marketing and influencer space. Similar attacks have proliferated across industries, underlining the urgent need for heightened workforce awareness, advanced email security, and robust identity controls.
6 months ago
Kill Chain
RondoDox Botnet Unleashes 'Exploit Shotgun' on Edge Devices
In early 2024, cybersecurity researchers uncovered the RondoDox Botnet, a rapidly evolving threat that leverages an 'exploit shotgun' methodology to compromise a wide range of consumer edge devices worldwide. The botnet scans for and exploits multiple zero-day and known vulnerabilities across routers and IoT devices, often gaining initial access through unpatched firmware or exposed management interfaces. Once inside, RondoDox deploys malware that enables remote control, data exfiltration, and lateral movement, allowing attackers to build a resilient, distributed botnet infrastructure which has been used for DDoS attacks and potentially other malicious activities. The decentralized campaign demonstrates sophisticated automation, making incident response and containment significantly more difficult for defenders. This incident is highly relevant as it highlights the surge in automated botnet attacks targeting unmanaged edge devices, a trend driven by increasing adoption of IoT and remote work infrastructure. The RondoDox tactics underscore the urgency for organizations to address lateral movement, patch management, and zero trust segmentation, especially as regulatory scrutiny on device and network security continues to intensify.
6 months ago
Kill Chain
Blue Angel Suite Faces 2024 Webctrl.cgi OS Command Injection Attempts
In October 2024, threat actors attempted to exploit an OS command injection vulnerability targeting the Blue Angel Software Suite's web interface on embedded Linux devices. Attackers issued crafted POST requests to the '/cgi-bin/webctrl.cgi' endpoint, aiming to inject arbitrary shell commands via the 'ipaddress' parameter. These attacks, detected by honeypots, mirror previous vulnerabilities such as CVE-2025-34033, which allows authenticated attackers to execute code as root by manipulating input passed to system commands like 'ping'. The incidents highlight persistent risks across IoT and broadband equipment, potentially providing attackers with full system control. This incident underscores a growing trend in targeting network appliances and IoT infrastructure for initial access and lateral movement. As regulatory attention increases and attackers shift toward exploiting device misconfigurations and weak input validation, robust segmentation and up-to-date patch management are even more critical.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports