logo

Did anyone recently notice that the Spamhaus XBL just got really big?

ID: 9338b94d-f6f9-5460-b6f4-8b3e8e78c237

STIX ID: report--9338b94d-f6f9-5460-b6f4-8b3e8e78c237

Feed Name: The Spamhaus Project

Threat Score
75/100

Date Published: 2017-12-19

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

Over the last three weeks the XBL blacklist grew dramatically: IoT scanning and infections (including Mirai and a Mirai-like Satori variant targeting Huawei home gateways) increased IoT entries from under 1M to over 2.5M (with ~1.2M Mirai detections in Egypt), and the Andromeda/Gamarue C2 takedown added a feed that expanded entries from tens of thousands to over 6M, indicating large-scale active botnet compromise and C2 telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.