CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain

2026-05-27T14:51:45Z85c367cc950948a7359a817ae1ef7a2fac0e8108e06b0bff35fca0b747f09d31
access-tokensanthropic-mythosapplebotnet-arrestbotnet-takedowncisacrowdstrikecybersecurity-loggingeuropolfederal-policyfirst-vpnglasswormgooglekali365kimwolfmicrosoft-365open-sourcephishing-kitquantum-resistant-cryptoshadowserversupply-chain-compromisevulnerability-discovery

What happened

Multiple CyberScoop reports describe a mix of active threats, takedowns, and policy/defensive developments. CrowdStrike, with help from Google and Shadowserver, dismantled the Glassworm botnet that had been infecting hundreds of open-source projects since early 2025 by seizing attacker-controlled infrastructure. The FBI warned of a fast-growing phishing kit called Kali365 that abuses Microsoft device-authorization pages to obtain persistent access tokens for Microsoft 365 accounts. Law enforcement also arrested the alleged leader of the Kimwolf botnet and European authorities disrupted the ‘If

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
85c367cc950948a7359a817ae1ef7a2fac0e8108e06b0bff35fca0b747f09d31
Enrichment time
2026-05-27T14:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.