logo

What do Ports Hear When Nobody's Listening? An Assessment of Automated Cybercrime [Guest Diary], (Wed, Jun 24th)

ID: b58112a8-6360-5015-8c2b-d53fe79fb117

STIX ID: report--b58112a8-6360-5015-8c2b-d53fe79fb117

Feed Name: SANS ISC Diary

Threat Score
75/100

Date Published: 2026-06-25

Date Updated: 2026-06-25

...
...

**Executive summary:** A SANS ISC intern's honeypot diary documents multiple active botnet campaigns (Terrabot, r00ts3c, RondoDox) scanning and exploiting consumer routers and enterprise services using known CVEs (including Log4Shell and ShadowRay), fileless payloads, and staged binaries, with telemetry showing hardcoded staging servers, user-agents, IP-based IoCs and operational patterns that reveal both sloppy commodity automation and more sophisticated, enterprise-capable infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.