The Kimwolf IoT botnet — with roughly 700,000 infected devices spanning TV streaming boxes, digital picture frames, and routers — accidentally Sybil-attacked the I2P anonymity network this week while attempting to pivot its C2 infrastructure there. By flooding I2P with fake nodes, the botmasters overwhelmed legitimate routing to the point where existing users couldn't connect. The remarkable detail: the botmasters openly discussed the incident in a public Discord channel, admitting they "accidentally disrupted I2P" after attempting to enroll 700K bots as nodes. This is a rare case of a threat actor openly broadcasting its own operational blunder — and it reveals the botnet's serious scale and ambition.
On the extortion front, the Scattered Lapsus ShinyHunters (SLSH) gang is escalating fast. Unlike Russian ransomware affiliates who maintain a reputation for honoring payments, SLSH operates with no such code — they harass, threaten, and physically swat executives and their families while simultaneously notifying journalists and regulators. Security firm Unit 221B is tracking them closely and the verdict is stark: engaging beyond a flat refusal to pay only invites more escalation. Multiple victims have reportedly paid anyway, likely to suppress stolen data exposure, not to stop the harassment. The group's fractious, unreliable nature makes payment a losing bet regardless.
New malware infrastructure is also on the board. The ClickFix campaign now delivers MIMICRAT (aka AstarionRAT), a custom C++ RAT with ETW and AMSI bypass, a multi-stage PowerShell chain, and a Lua-scripted shellcode loader. Final C2 runs over HTTPS port 443 using HTTP profiles that mimic legitimate web analytics traffic — a deliberate evasion signature. MIMICRAT supports 22 post-exploitation commands including Windows token impersonation and SOCKS5 tunneling. Delivery infrastructure spans compromised legitimate sites across multiple industries and geographies. Meanwhile, PayPal has disclosed a software error in a loan application that exposed customer SSNs and sensitive PII for nearly six months before detection — a silent breach that flew under the radar. And CISA has added two Roundcube flaws (CVSS 9.9 and 7.2) to its KEV catalog after attackers weaponized the critical deserialization flaw within 48 hours of public disclosure.