XorBot Botnet Resurfaces with Advanced Evasion and Exploits, Threatens IoT Devices
Penetration Testing
NOVEMBER 27, 2024
NSFOCUS has identified a resurgence of the XorBot botnet, a potent threat to Internet of Things (IoT) devices worldwide.
This site uses cookies to improve your experience. To help us insure we adhere to various privacy regulations, please select your country/region of residence. If you do not select a country, we will assume you are from the United States. Select your Cookie Settings or view our Privacy Policy and Terms of Use.
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Used for the proper function of the website
Used for monitoring website traffic and interactions
Cookies and similar technologies are used on this website for proper function of the website, for tracking performance analytics and for marketing purposes. We and some of our third-party providers may use cookie data for various purposes. Please review the cookie settings below and choose your preference.
Penetration Testing
NOVEMBER 27, 2024
NSFOCUS has identified a resurgence of the XorBot botnet, a potent threat to Internet of Things (IoT) devices worldwide.
The Last Watchdog
DECEMBER 17, 2023
The Internet of Things ( IoT ) is on the threshold of ascending to become the Internet of Everything ( IoE.) This was the theme of Infineon Technologies’ OktoberTech 2023 conference, which I had the privilege of attending at the Computer History Museum in the heart of Silicon Valley.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
SecureList
SEPTEMBER 21, 2023
IoT devices (routers, cameras, NAS boxes, and smart home components) multiply every year. The first-ever large-scale malware attacks on IoT devices were recorded back in 2008, and their number has only been growing ever since. Telnet, the overwhelmingly popular unencrypted IoT text protocol, is the main target of brute-forcing.
Security Affairs
MARCH 8, 2025
They found unsecured IoT devices, including webcams and a fingerprint scanner, using them to bypass security defenses and successfully deploy the ransomware. The IoT device was running a lightweight Linux OS, that was the perfect target for Akiras Linux ransomware variant. ” reads the report published by the S-RM team.
Krebs on Security
MAY 20, 2025
The brief attack appears to have been a test run for a massive new Internet of Things (IoT) botnet capable of launching crippling digital assaults that few web destinations can withstand. us , one of the domains seized in the FBI’s 2023 crackdown. On May 8, 2023, the U.S. For reference, the 6.3 Image: Cloudflare.
Security Affairs
JANUARY 4, 2025
According to OFAC, between 2022 and 2023, Flax Typhoon hacked U.S. In September 2024, cybersecurity researchers from Lumens Black Lotus Labs discovered a new botnet, named Raptor Train, composed of small office/home office (SOHO) and IoT devices. The experts believe the botnet is controlled by a Chine-linked APT group Flax Typhoon.
The Last Watchdog
SEPTEMBER 5, 2023
New government rules coupled with industry standards meant to give formal shape to the Internet of Things (IoT) are rapidly quickening around the globe. When it comes to IoT, we must arrive at specific rules of the road if we are to tap into the full potential of smart cities, autonomous transportation and advanced healthcare.
The Last Watchdog
DECEMBER 16, 2024
Sundaresan Bindu Sundaresan , Cybersecurity Director, LevelBlue In 2025, cybercriminals will exploit supply chain vulnerabilities, ransomware, IoT botnets, and AI-driven phishing. Rising IoT use demands standards to prevent device weaponization, while AI-enabled phishing challenges defenses.
Security Affairs
MARCH 9, 2025
The experts warn that a hidden feature poses a security risk for millions of IoT devices. “Tarlogic Securityhas detected a hidden functionality that can be used as a backdoor in the ESP32, a microcontroller that enables WiFi and Bluetooth connection and is present inmillions of mass-market IoT devices.”
Security Affairs
DECEMBER 17, 2024
In March 2023, Lumen Black Lotus Labs researchers uncovered a sophisticated campaign called HiatusRAT that infected over 100 edge networking devices globally. Starting in mid-June through August 2023, Black Lotus Labs observed multiple newly compiled versions of the HiatusRAT malware discovered in the wild.
eSecurity Planet
AUGUST 9, 2021
A malicious advertising campaign originating out of Eastern Europe and operating since at least mid-June is targeting Internet of Things (IoT) devices connected to home networks, according to executives with GeoEdge, which offers ad security and quality solutions to online and mobile advertisers. Malvertising is Evolving.
SecureWorld News
JUNE 13, 2023
In a digital landscape increasingly dependent on interconnected devices, the rise in malicious Internet of Things (IoT) botnet activity is becoming a significant cause for concern. This tactic is commonly associated with a variety of IoT botnets, exploiting the lax security measures present in billions of IoT devices worldwide.
Security Affairs
SEPTEMBER 18, 2024
Researchers warn of a new IoT botnet called Raptor Train that already compromised over 200,000 devices worldwide. Cybersecurity researchers from Lumen’s Black Lotus Labs discovered a new botnet, named Raptor Train, composed of small office/home office (SOHO) and IoT devices.
Security Boulevard
MAY 3, 2023
Sectrio, the premier IoT and OT security company has launched the findings of its latest edition of its much-awaited OT and IoT threat environment landscape analysis report 2023. The […] The post Sectrio’s OT and IoT threat report uncovers the Chinese intelligence conveyor belt appeared first on Security Boulevard.
SecureList
NOVEMBER 9, 2022
What cyberthreats for business will be the greatest in 2023? The ongoing geopolitical storm brings not only classical cyberthreats for business, but also unpredictable risks and ‘black swans’ The main problem for 2023 will be supply-chain stability and cybersecurity. Threat modeling approaches will be changed in 2023.
SecureWorld News
JANUARY 16, 2025
Digital transformation: The integration of IoT, SCADA systems, and advanced analytics has increased operational efficiency but also expanded the attack surface. A report from 2023 revealed that 67% of energy and utility companies faced ransomware attacks, with many incidents exploiting unpatched vulnerabilities.
Dark Reading
NOVEMBER 12, 2020
With 5G IoT devices projected to hit 49 million units by 2023, researchers launch programs to keep IoT from becoming a blackhole of exfiltration.
Security Boulevard
SEPTEMBER 23, 2023
Introduction The convergence of the Internet of Things (IoT) and endpoint security has become a pivotal focal point for small businesses. The integration of IoT has revolutionized operational processes. The post Unlocking IoT Endpoint Security in 2023: What You Need to Know appeared first on Security Boulevard.
Security Affairs
DECEMBER 4, 2023
Cybersecurity researchers discovered a new variant of the P2PInfect botnet that targets routers and IoT devices. Researchers at Cado Security Labs discovered a new variant of the P2Pinfect botnet that targets routers, IoT devices, and other embedded devices. ” reads the report published by Cado Security.
CyberSecurity Insiders
NOVEMBER 29, 2022
As we look forward to 2023 a number of emerging trends are top security areas that executives should focus. This area will continue to be an ongoing challenge for organizations in 2023. This challenge will continue in 2023 and we expect that the growth in this area will be in the double digits. IoT and DoS. Ransomware.
Security Affairs
MARCH 12, 2025
Cato CTRL researchers observed a new botnet, called Ballista botnet, which is exploiting a remote code execution (RCE) vulnerability, tracked as CVE-2023-1389 (CVSS score 8.8), in TP-Link Archer routers. Since early 2025, Cato CTRL has tracked the Ballista botnet targeting TP-Link Archer routers via CVE-2023-1389.
SecureList
DECEMBER 1, 2023
Quarterly figures According to Kaspersky Security Network, in Q3 2023: Kaspersky solutions blocked 694,400,301 attacks from online resources across the globe. Financial threats Financial threat statistics In Q3 2023, Kaspersky solutions blocked the launch of at least one piece of banking malware on the computers of 76,551 unique users.
SecureList
DECEMBER 4, 2023
The statistics in this report cover the period from November 2022 through October 2023. Fill the form below to download the Kaspersky Security Bulletin 2023. Millions of Kaspersky users around the globe assist us in collecting information about malicious activity. Found 106,357,530 unique malicious URLs.
Security Affairs
AUGUST 28, 2023
Researchers spotted an updated version of the KmsdBot botnet that is now targeting Internet of Things (IoT) devices. The Akamai Security Intelligence Response Team (SIRT) discovered a new version of the KmsdBot botnet that employed an updated Kmsdx binary targeting Internet of Things (IoT) devices.
The Hacker News
NOVEMBER 2, 2023
The unexpected drop in malicious activity connected with the Mozi botnet in August 2023 was due to a kill switch that was distributed to the bots. First, the drop manifested in India on August 8," ESET said in an analysis published this week. "A A week later, on August 16, the same thing happened in China.
CyberSecurity Insiders
JANUARY 25, 2023
According to recent threat intelligence from SonicWall, global ransomware attempts declined 31% YoY as cybercriminals and nation-state actors opted for never-before-seen malware variants, IoT malware, and cryptojacking in attacks motivated by financial gain and state-sponsored hacktivism.
Thales Cloud Protection & Licensing
OCTOBER 2, 2023
Cybersecurity Awareness Month 2023 – What it is and why we should be aware madhav Tue, 10/03/2023 - 05:33 The inception of Cybersecurity Awareness Month in 2004 came at a critical juncture in our technological history. As we are well and truly in the digital-first age, the need for robust cybersecurity measures is glaringly evident.
CyberSecurity Insiders
DECEMBER 21, 2022
While many of the same trends and threats remain, 2023 is likely to keep us on our toes as these threats mature and the landscape continues to shift. Many security professionals have emphasized the importance of asset management for IoT and other internet-connected devices. Increased challenges for web application asset management.
Schneier on Security
DECEMBER 15, 2023
This was the Internet of Things (IoT). In 2023, we upgraded the “thinking” part with large-language models (LLMs) like GPT. And they will increasingly control our environment, through IoT devices and beyond. And it had smarts in the middle, using sensor data to figure out what to do and then actually do it.
Jane Frankland
NOVEMBER 20, 2023
My Predictions for Cybersecurity in 2023 were… Technology enables opportunities as fast as it introduces threats. Here are my predictions for 2023. Types of attacks.
CyberSecurity Insiders
JANUARY 10, 2023
Increased vulnerability is causing headaches and expenses due to numerous societal shifts – whether it’s the proliferation of the internet of things (IoT) in every aspect of business and society, or the widespread adoption of home and remote working that began during the Covid-19 pandemic and has persisted in many organizations.In
Security Boulevard
JANUARY 3, 2023
IoT and OT Cybersecurity predictions for India for 2023 are based on the trends we have observed in India’s digital space over the last 4 years, our research on […]. The post 2023 will be an important year for cybersecurity in India appeared first on Security Boulevard.
Security Affairs
JUNE 22, 2023
Since March 2023, Unit 42 researchers have observed a variant of the Mirai botnet spreading by targeting tens of flaws in D-Link, Zyxel, and Netgear devices. Since March 2023, researchers at Palo Alto Networks Unit 42 have observed a new variant of the Mirai botnet targeting multiple vulnerabilities in popular IoT devices.
Security Affairs
DECEMBER 26, 2024
. “Using a Mirai malware variant that incorporates ChaCha20 and XOR decryption algorithms, it has been seen compromising vulnerable Internet of Things (IoT) devices in the wild, such as the DigiEver DVR, and TP-Link devices through CVE-2023-1389.”
CyberSecurity Insiders
JANUARY 6, 2023
Here are the five challenges that will alter the industry in 2023: Zero trust will replace perimeter security. Organizational data is flowing outside of traditional closed networks and into the cloud, while the 5G-powered Internet of Things (IoT) is vastly multiplying endpoints at risk from attack.
Security Boulevard
JANUARY 9, 2023
The post CES 2023 FAIL: Worst in Show for Security and Privacy appeared first on Security Boulevard. The Consumer Electronics Show wrapped up yesterday. But some vendors faced stiff criticism over their privacy and security stances.
The Hacker News
APRIL 18, 2025
percent of the attacks between November 2023 and February 2025 targeting the United States. From 2020 to 2023, the XorDDoS trojan has increased significantly in prevalence," Cisco Talos researcher Joey Chen said in a Thursday analysis.
Penetration Testing
DECEMBER 9, 2023
A critical vulnerability affecting the Syrus4 IoT Gateway, a technology found in over 119,000 vehicles across 49 countries, has been left unpatched for months, leaving millions of drivers vulnerable to hacking.
We Live Security
DECEMBER 11, 2023
Have we learned nothing from late IoT regulations that left the market swamped with old insecure devices? AI has been around for a while now, but governments are only starting to issue legislation to regulate it. Is it too late?
CSO Magazine
APRIL 6, 2023
Developers of ThingsBoard, an open-source platform for managing IoT devices that's used in various industry sectors, have fixed a vulnerability that could allow attackers to escalate their privileges on a server and send requests with administrative privileges.
Security Boulevard
MARCH 30, 2023
An ongoing rise in IoT attacks sees many companies and consumers facing threats from spying to having data stolen. Read More The post The Ongoing Rise in IoT Attacks: What We’re Seeing in 2023 appeared first on Nuspire. The post The Ongoing Rise in IoT Attacks: What We’re Seeing in 2023 appeared first on Security Boulevard.
Security Through Education
JANUARY 18, 2023
What are some personal cybersecurity concerns for 2023? IBM describes the internet of things (IoT) as the “the concept of connecting any device … to the Internet and to other connected devices.” Basically, the IoT encompasses anything from smart microwaves and fridges to self-driving cars and fitness devices (to name a few).
SecureWorld News
AUGUST 3, 2024
The hidden weakness: human error Despite leaps in cybersecurity technology, human error remains an Achilles heel in SCADA and IoT security. Then there's Nvidia's 2023 cyberattack, where phishing schemes tricked personnel into surrendering their credentials and exposing sensitive records. The attacker's gateway? Human blunders.
The Last Watchdog
AUGUST 1, 2022
I had the chance to discuss the wider significance of Matter with Mike Nelson, DigiCert’s vice president of IoT security. The security specification raises the bar for IoT security and privacy through the following approaches: •Establishing a strong device identity so only trusted devices can join a smart home.
Expert insights. Personalized for you.
We have resent the email to
Are you sure you want to cancel your subscriptions?
Let's personalize your content