logo

CrowdStrike, Google Take Down Glassworm Botnet

ID: 9852364b-1e6e-568d-8d00-97591c2bb0c9

STIX ID: report--9852364b-1e6e-568d-8d00-97591c2bb0c9

Feed Name: Infosecurity Magazine (News)

Threat Score
85/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

...
...

CrowdStrike, Google and the Shadowserver Foundation jointly disrupted the Glassworm botnet by simultaneously taking down all four of its command-and-control channels, which used a mix of traditional VPS C2 servers and resilient indirect channels (Google Calendar dead-drops, BitTorrent P2P, and Solana blockchain memos). Glassworm, active since early 2025, was used in supply-chain attacks that trojanized VS Code extensions and poisoned npm/Python packages and reportedly led to the compromise of over 300 GitHub repositories via stolen developer credentials, posing a significant threat to developer ecosystems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.