Log inSign up
abuse.ch
3,420 posts
abuse.ch profile banner
@abuse_ch

abuse.ch

@abuse_ch
Fighting malware and botnets
Zurich
abuse.ch
Joined May 2009
302
Following
37.8K
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • Pinned
    @abuse_ch
    abuse.ch
    @abuse_ch
    Aug 7
    📢 To our incredible community of contributors: thank you for everything you do to keep the internet safe! 🛡️ To help protect our platforms and maintain the high-quality data you rely on, here is a quick refresher on our submission guidelines across MalwareBazaar, URLhaus, and
    3
  • @abuse_ch
    abuse.ch
    @abuse_ch
    Sep 2
    #BoratRAT spreading using similar tactics as #ClickFix 👇 1️⃣ Fake Microsoft Security Verification 🔑 leading to malicious PowerShell execution 🖱️ 2️⃣ Command triggers a DNS TXT request to recapture-robot .today 🌐 to obtain a PowerShell script 📜 3️⃣ Script drops payload,
    BoratRAT spreading through a ClickFix like lure
    Botnet C2 serving "BoratRat" SSL certificate
    Malicious DNS TXT record serving a PowerShell script, leading to malware infection with BoratRAT
    2
  • @abuse_ch
    abuse.ch
    @abuse_ch
    Aug 24
    Overlord RAT 🔌 dropped by Amadey loader 🔥 Botnet C2 server: mypamella .xyz ➡️ NameSilo 🇺🇸 136.175.82.88:443 ➡️ 2ETELECOM🇧🇬 Payload is bulletproof hosted 🛡️at Omegatech LTD 🇳🇱 🌐 urlhaus.abuse.ch/url/3906755/ 📄 Malware sample: bazaar.abuse.ch/sample/ac1f8b3… 🦊 Further IOCs on ThreatFox:
    Overlord RAT botnet admin panel
    2
  • @abuse_ch
    abuse.ch
    @abuse_ch
    Aug 19
    NeedleStealer 🪡🪝 written in Go ⤵️ 🔎 HTTP user agents observed: User-Agent: Loader-cli/v1 user-agent: Go-http-client/2.0 📡 Botnet C2s, all behind Cloudflare CDN: http://woolvilli .com/api/v2 http://allremdeskriki .com/api/v2 http://dubl1allremriki .com/api/v2
    NeedleStealer botnet admin panel
    3
  • @abuse_ch
    abuse.ch
    @abuse_ch
    Aug 18
    We identified a new malware called #HypeAgent which acts as information stealer & loader. It is dominantly spread through malspam 📧, first observed on August 1, 2026 🔭👀 Key Capabilities ⤵️ 🕵️ Stealer & Loader: Supports 200+ commands; drops/executes payloads, including crypto
    Image
    HypeAgent botnet C2 communication observed during tria.ge sandbox run
    1
Advertisement
Advertisement