logo

Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic

ID: b37e39bd-5781-5c0d-bccb-92a34285f0fe

STIX ID: report--b37e39bd-5781-5c0d-bccb-92a34285f0fe

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed an active campaign delivering a novel Windows botnet named **PowMix** (observed since Dec 2025) that uses ZIP attachments with LNK-triggered PowerShell loaders to execute encrypted payloads in memory, establish persistence via scheduled tasks, and communicate with C2 using randomized beacon intervals and embedded identifiers; the report also discusses **RondoDox**, a separate botnet family that mines cryptocurrency with XMRig and conducts DDoS attacks while exploiting many internet-facing vulnerabilities. The disclosure highlights shared tactics (ZIP delivery, scheduled-task persistence, Heroku-based C2), evasion techniques (jittered beaconing, in-memory execution, anti-analysis), and active maintenance, though final payload objectives remain unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.