Did anyone recently notice that the Spamhaus XBL just got really big?
ID: 9338b94d-f6f9-5460-b6f4-8b3e8e78c237
STIX ID: report--9338b94d-f6f9-5460-b6f4-8b3e8e78c237
Feed Name: The Spamhaus Project
Threat Score
Over the last three weeks the XBL blacklist grew dramatically: IoT scanning and infections (including Mirai and a Mirai-like Satori variant targeting Huawei home gateways) increased IoT entries from under 1M to over 2.5M (with ~1.2M Mirai detections in Egypt), and the Andromeda/Gamarue C2 takedown added a feed that expanded entries from tens of thousands to over 6M, indicating large-scale active botnet compromise and C2 telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
