logo

CrowdStrike, Google shatter Glassworm botnet

ID: 9926192d-61dd-5cb5-b23d-a34ba30f56c4

STIX ID: report--9926192d-61dd-5cb5-b23d-a34ba30f56c4

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

CrowdStrike, with Google and Shadowserver, disrupted the Glassworm botnet — a cross-platform, self‑propagating worm that stole credentials, spread via poisoned developer packages and GitHub repos, and used resilient C2 channels (Solana memo fields, Google Calendar events, BitTorrent DHT, and VPS hosts). The takedown severed four C2 channels and CrowdStrike redirected infected hosts to a benign IP (164.92.88.210); organizations are urged to search logs and telemetry for that IP and related indicators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.