← Back to News
AI Analysis by The Wire
February 22, 2026 Focus: THREAT INTELLIGENCE Impact: 8/10

Kimwolf Botnet Sybils I2P, SLSH Gang Swats Executives, MIMICRAT Hits with ETW/AMSI Bypass — Feb 22 Evening Edition

The Kimwolf IoT botnet — with roughly 700,000 infected devices spanning TV streaming boxes, digital picture frames, and routers — accidentally Sybil-attacked the I2P anonymity network this week while attempting to pivot its C2 infrastructure there. By flooding I2P with fake nodes, the botmasters overwhelmed legitimate routing to the point where existing users couldn't connect. The remarkable detail: the botmasters openly discussed the incident in a public Discord channel, admitting they "accidentally disrupted I2P" after attempting to enroll 700K bots as nodes. This is a rare case of a threat actor openly broadcasting its own operational blunder — and it reveals the botnet's serious scale and ambition.

On the extortion front, the Scattered Lapsus ShinyHunters (SLSH) gang is escalating fast. Unlike Russian ransomware affiliates who maintain a reputation for honoring payments, SLSH operates with no such code — they harass, threaten, and physically swat executives and their families while simultaneously notifying journalists and regulators. Security firm Unit 221B is tracking them closely and the verdict is stark: engaging beyond a flat refusal to pay only invites more escalation. Multiple victims have reportedly paid anyway, likely to suppress stolen data exposure, not to stop the harassment. The group's fractious, unreliable nature makes payment a losing bet regardless.

New malware infrastructure is also on the board. The ClickFix campaign now delivers MIMICRAT (aka AstarionRAT), a custom C++ RAT with ETW and AMSI bypass, a multi-stage PowerShell chain, and a Lua-scripted shellcode loader. Final C2 runs over HTTPS port 443 using HTTP profiles that mimic legitimate web analytics traffic — a deliberate evasion signature. MIMICRAT supports 22 post-exploitation commands including Windows token impersonation and SOCKS5 tunneling. Delivery infrastructure spans compromised legitimate sites across multiple industries and geographies. Meanwhile, PayPal has disclosed a software error in a loan application that exposed customer SSNs and sensitive PII for nearly six months before detection — a silent breach that flew under the radar. And CISA has added two Roundcube flaws (CVSS 9.9 and 7.2) to its KEV catalog after attackers weaponized the critical deserialization flaw within 48 hours of public disclosure.

Impact Score
8/10
Key Stories
Kimwolf Botnet Sybil-Attacks I2P Network with 700K IoT Bots
Krebs on Security
SLSH Gang Swatting Executives in Data Ransom Escalation
Krebs on Security
ClickFix Campaign Delivers MIMICRAT with ETW/AMSI Bypass
The Hacker News
PayPal Breach: Software Error Exposed SSNs for Nearly 6 Months
BleepingComputer
CISA Adds Roundcube CVSS 9.9 and 7.2 Flaws to KEV After 48hr Weaponization
The Hacker News
Analyst Take
Three themes stand out this cycle. First, Kimwolf is not just a DDoS gun — it's actively experimenting with anonymization infrastructure for C2 resilience, and the botmasters' public candor about their own mistakes is operationally unusual. Track this for future C2 architecture moves. Second, SLSH is the most dangerous extortion group right now precisely because they don't follow the rules other ransomware crews live by — the swatting escalation makes them uniquely coercive and unpredictable. No-pay is the only defensible posture. Third, the 48-hour Roundcube weaponization timeline is the real signal in the CISA KEV addition — the gap between patch disclosure and active exploitation is now measured in hours, not days or weeks. Patch Tuesday cycles are structurally too slow for this threat environment.