Cybercriminals move deeper into networks, hiding in edge infrastructure
ID: 81586ba7-e915-571f-aa6d-6281a456afe7
STIX ID: report--81586ba7-e915-571f-aa6d-6281a456afe7
Feed Name: Help Net Security
This report describes the 2022–2025 evolution of proxy and botnet infrastructure, documenting major threat families (Aisuru, Vo1d, AWM, Rhadamanthys, SystemBC, DanaBot) and campaigns (Secret Blizzard / Storm-0156). It highlights massive scale (millions of IPs, thousands of C2 nodes), exploitation of edge devices and proxy services, frequent use of unpatched CVEs, rapid rebuilding of control planes after disruption, and operational impacts including sustained large-scale DDoS (up to ~30 Tbps) and widespread low-detection C2 infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
