Cybersecurity News
Filters
Filtered by tag: botnet × Clear
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
Matched: health
ToxNetV2 is a Linux botnet targeting AArch64 systems that integrates NVIDIA's NIM AI service into its controller to suggest attack commands. The controller feeds system and botnet data to the AI model, parsing structured responses into a queue of proposed actions — including shell commands, SSH access, and file operations — that human operators must approve before execution. The botnet uses a peer-to-peer structure and includes scanning, self-propagation, and 17 network-attack modules. Researchers at JOESecurity noted the malware embeds a jailbreak prompt to reduce AI refusals.
Android car systems abused by hackers to launch new malware that pulls devices into a hidden proxy network
Kaspersky discovered Android malware targeting DoFun car head units by hijacking the TWCore update app to install malicious APKs. The multi-stage attack deploys a dropper, loader, and reverse proxy tool, with the apparent goal of building a botnet from internet-connected vehicles. Kaspersky attributed the campaign to MoYu Group, previously linked to the BadBox botnet. DoFun has since patched the vulnerabilities.
Even connected car head units are being targeted by hackers now — experts warn in-car systems are at risk of being hijacked into a botnet
Kaspersky has identified the first malware campaign built specifically to target Android-based car head units, linking it to the MoYu Group behind the BadBox botnet. Attackers hijacked a legitimate software update channel in DoFun-manufactured devices to silently deliver malware capable of ad fraud, displaying unwanted ads, and harvesting device data. The malware runs invisibly with no user-facing interface. DoFun says the issue has since been resolved on most affected devices.
FBI Seizes NetNut Proxy Platform, Popa Botnet
The FBI seized hundreds of domains tied to NetNut, a residential proxy service run by Israeli company Alarum Technologies. The action followed a KrebsOnSecurity report linking NetNut to the Popa botnet, a network of at least two million devices infected without owner consent. The seizure involved industry partners and came roughly two weeks after the security findings were published.
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
A years-long Android botnet called Popa has hijacked millions of consumer TV boxes to relay traffic tied to ad fraud, account takeovers, and data scraping. Security researchers have linked the operation to NetNut, a residential proxy service run by Alarum Technologies, a publicly traded Israeli company listed on NASDAQ.
