:

GLASSWORM BOTNET DISRUPTED IN C2 TAKEDOWN

INDUSTRY DESK1 MIN READ
WED, MAY 27, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Researchers have dismantled the Glassworm botnet's command-and-control infrastructure after targeting developers in supply-chain attacks. The operation exploited Solana blockchain transactions and BitTorrent DHT networks for resilient communications.

Security researchers successfully disrupted Glassworm, a botnet that attacked software developers as part of supply-chain compromise campaigns. The threat actors used an innovative dual-layer infrastructure combining Solana blockchain transactions with BitTorrent Distributed Hash Table (DHT) networks to maintain control over infected systems. The blockchain-based approach allowed attackers to publish C2 commands as Solana transactions, while the DHT network provided a decentralized fallback mechanism. This redundancy made traditional takedown efforts difficult. The coordinated disruption targeted both layers of the infrastructure, effectively severing communications between the botnet operators and compromised endpoints. Researchers did not disclose additional details about the operation's scope or the number of affected systems. The incident highlights evolving tactics among threat actors leveraging blockchain and peer-to-peer networks to build resilient attack infrastructure that circumvents conventional law enforcement and security responses.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Manchester Airports Group disclosed a breach affecting Manchester, Stansted, and East Midlands airports. Hackers accessed data from approximately 8.7 million customers.

4H AGOAI Desk

A lawsuit alleges that Elon Musk's xAI trained its Grok language models using child sexual abuse material, including both real and AI-generated imagery.

4H AGOAI Desk

The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.

16H AGOSecurity Desk

A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.

16H AGOAI Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.