Anti-DDoS Firm Heaped Attacks on Brazilian ISPs

2026-05-06T07:23:31Zcdae0d41682fcaf391b5bf09e5d47e75ef8ad74643e242e7cc390f8b483747f9
Adobe Reader exploitDDoSGandCrabGoogle Chrome zero‑dayIoT botnetIranMicrosoft Office tokensPatch TuesdayREvilRussiaScattered SpiderSharePoint zero‑dayWindows Defender BlueHammeranti‑DDoS abusebotnetlaw enforcement takedownnation‑state activityphishingransomwarerouter vulnerabilitiessmishingsupply‑chain/competitor abusetoken theftwiperzero‑day

What happened

Multiple active, large-scale threats and disclosures: a Brazilian anti‑DDoS firm was implicated in enabling massive DDoS attacks against ISPs via a botnet; Russian state‑linked actors exploited known router flaws to harvest Microsoft Office authentication tokens from >18,000 networks; U.S./allied law enforcement disrupted four major IoT botnets (Aisuru, Kimwolf, JackSkid, Mossad) that had compromised millions of devices; and an Iran‑targeting worm/wiper (CanisterWorm) and an Iran‑linked wiper against Stryker were reported. Crimeware updates include a guilty plea from a senior Scattered Spider/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
cdae0d41682fcaf391b5bf09e5d47e75ef8ad74643e242e7cc390f8b483747f9
Enrichment time
2026-05-06T07:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.