Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
ID: b37e39bd-5781-5c0d-bccb-92a34285f0fe
STIX ID: report--b37e39bd-5781-5c0d-bccb-92a34285f0fe
Feed Name: The Hacker News
Cybersecurity researchers disclosed an active campaign delivering a novel Windows botnet named **PowMix** (observed since Dec 2025) that uses ZIP attachments with LNK-triggered PowerShell loaders to execute encrypted payloads in memory, establish persistence via scheduled tasks, and communicate with C2 using randomized beacon intervals and embedded identifiers; the report also discusses **RondoDox**, a separate botnet family that mines cryptocurrency with XMRig and conducts DDoS attacks while exploiting many internet-facing vulnerabilities. The disclosure highlights shared tactics (ZIP delivery, scheduled-task persistence, Heroku-based C2), evasion techniques (jittered beaconing, in-memory execution, anti-analysis), and active maintenance, though final payload objectives remain unclear.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
