CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
2026-05-27T14:51:45Z•85c367cc950948a7359a817ae1ef7a2fac0e8108e06b0bff35fca0b747f09d31
access-tokensanthropic-mythosapplebotnet-arrestbotnet-takedowncisacrowdstrikecybersecurity-loggingeuropolfederal-policyfirst-vpnglasswormgooglekali365kimwolfmicrosoft-365open-sourcephishing-kitquantum-resistant-cryptoshadowserversupply-chain-compromisevulnerability-discovery
What happened
Multiple CyberScoop reports describe a mix of active threats, takedowns, and policy/defensive developments. CrowdStrike, with help from Google and Shadowserver, dismantled the Glassworm botnet that had been infecting hundreds of open-source projects since early 2025 by seizing attacker-controlled infrastructure. The FBI warned of a fast-growing phishing kit called Kali365 that abuses Microsoft device-authorization pages to obtain persistent access tokens for Microsoft 365 accounts. Law enforcement also arrested the alleged leader of the Kimwolf botnet and European authorities disrupted the ‘If
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- 85c367cc950948a7359a817ae1ef7a2fac0e8108e06b0bff35fca0b747f09d31
- Enrichment time
- 2026-05-27T14:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.