logo

Botnet Exposed: Hackers Leave Worker Access and Root Passwords Wide Open

ID: f7f9eb8d-16a0-5356-bba8-248f5df2e669

STIX ID: report--f7f9eb8d-16a0-5356-bba8-248f5df2e669

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-04-14

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Researchers discovered an unauthenticated Flask-based control panel and full command-and-control stack for a Twitter/X credential‑stuffing botnet, exposing worker IPs, root passwords, and REST endpoints that allow anyone to manage campaigns, upload lists, and exfiltrate results; telemetry showed millions of login attempts (≈4.86M total) with 138 confirmed account takeovers and ~85% of attempts blocked by 2FA. The workers reside in a Turkish-registered /24 block (Komuta Savunma), the UI is Turkish, and uniform root-password patterns indicate an automated provisioning pipeline; recommendations include enabling 2FA and enforcing rate limiting and anomaly detection on authentication endpoints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.