Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C Domains Surge +771%

Spamhaus H1 2026 Botnet Threat Update (TL-2026-2469) is a medium-severity tracked intrusion set, first published 2026-09-12. It has no confirmed attribution, maps to 18 MITRE ATT&CK techniques (T1003.001, T1027, T1055), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-2469

Threat ID
TL-2026-2469
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-09-12
Last reviewed
2026-09-12
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
19

Malware and tooling in Spamhaus H1 2026 Botnet Threat Update

Malware and tooling: Cobalt Strike, Remote Access Trojans (RATs), Cobalt Strike, Rubeus - S1071, Sliver - S0633, garble, gobfuscate

Spamhaus's January-June 2026 botnet threat update reports observed botnet C&C servers fell 30% to 14,952 while the open-source Sliver C2 framework rose 58% (1,904 to 3,008 detections) to overtake Cobalt Strike, which fell 68% (3,451 to 1,110) and dropped from #1 to #4 - its largest recorded decline. .cn C&C domains surged 771% and India's PDR registrar saw a 901% spike in abused registrations, while REGRU cut abuse by 90%.

How Spamhaus H1 2026 Botnet Threat Update works

The Spamhaus Project's semi-annual Botnet Threat Update for January-June 2026 documents a structural shift in the command-and-control (C2) tooling landscape tracked across its botnet C&C corpus. Total observed botnet C&C servers fell 30% period-over-period to 14,952, yet Spamhaus separately notes overall botnet C&C activity rose 24% in the same window - the two figures together indicating a smaller but more active tracked infrastructure base rather than a genuine decline in botnet operations. This 24% rise continues a trend from the immediately preceding period: Spamhaus's 'Botnet Threat Update July to December 2025' (published 2026-01-12) already reported a 24% period-over-period C&C activity increase, and Spamhaus's CERT Insight Portal materials separately state botnet C&C activity detected by Spamhaus rose 56% across calendar year 2025.

The headline finding is a leadership change among adversary C2 frameworks. Sliver, the open-source, cross-platform Golang C2 framework originally built by Bishop Fox as a red-team tool (MITRE ATT&CK Software S0633) and now widely abused by financially motivated and espionage threat actors as a Cobalt Strike alternative, climbed from 1,904 to 3,008 detections (+58%) to take the #1 spot. Cobalt Strike (MITRE ATT&CK Software S0154) - long the dominant commercial red-team-tool-turned-adversary-C2 framework - fell from 3,451 to 1,110 detections (-68%), dropping from #1 to #4. Spamhaus states this is Cobalt Strike's largest percentage decline since it began tracking the framework, consistent with a broader industry pattern of licensing crackdowns, cracked-license takedown pressure, and improved signature-based detection pushing adversaries toward Sliver and other emerging frameworks. Spamhaus's Top 20 botnet-associated malware list is now 42% Remote Access Trojans (RATs) by family count (unchanged from the July-December 2025 period), underscoring that C2-framework and RAT tradecraft together dominate the tracked botnet corpus.

MITRE ATT&CK's own Sliver (S0633) software page - cited directly as a primary technical source for this record - documents the specific tradecraft driving Sliver's detection-engineering relevance: built-in UAC-bypass and access-token-manipulation capabilities for privilege escalation; PowerShell command execution; Wireguard, HTTP(S), and DNS-based C2 channels; AES-GCM-256 symmetric and mutual-TLS/RSA asymmetric encrypted channels; Go-native obfuscation via the garble and gobfuscate libraries; a built-in SOCKS5 internal proxy; a procdump command for LSASS credential dumping; and incorporation of the Rubeus toolkit for forging Kerberos Golden Tickets. MITRE documents APT29 (G0016), Cinnamon Tempest (G1021), and TA551 (G0127) as threat groups that have used Sliver - concrete evidence that Sliver's H1 2026 detection surge reflects genuine, diverse adversary adoption rather than isolated red-team noise.

The report also documents a sharp shift in the domain-registration infrastructure adversaries use to stand up C2: .cn (China) botnet C&C domain registrations surged 771%, and India-based registrar PDR (Publicdomainregistry.com) saw abused registrations spike 901%. In contrast, Russian registrar REGRU cut abuse by 90%, which Spamhaus frames as a positive counter-trend against otherwise rising registrar abuse - notably, a different Russia-based registrar had recorded a +9,608% surge in abused botnet C&C domains in the immediately preceding July-December 2025 period, underscoring how registrar-level abuse patterns can swing sharply between consecutive reporting periods. These figures describe where and through whom adversaries are acquiring C2 domain infrastructure (MITRE ATT&CK Resource Development), not a specific victim campaign, and Spamhaus does not attribute the trend to a single threat actor or campaign.

Alongside the update, Spamhaus references its CERT Insight Portal - a free tool for government-funded national/regional CERTs and CSIRTs (over 100 of which already rely on Spamhaus data for remediation, per Spamhaus) - that layers enriched IP/ASN/malware/country metadata atop three underlying Spamhaus data sources: the Botnet Controller List (BCL), the Spamhaus Blocklist (SBL), and the Exploits Blocklist (XBL, which detects malware-infected hosts and underpins the portal's 'Bot Report'). The portal's separate 'Botnet C&C Report' cross-references detected botnet C&C servers against Malpedia, the Fraunhofer FKIE malware-family reference database, for family-level correspondence. This tooling is part of a broader push - alongside network operators and law enforcement - to target bulletproof hosting providers and the IP brokers/network carriers/datacenters that sustain them.

No CVE, specific network IOC list (IPs/domains/hashes), or single-campaign threat-actor attribution is stated in the primary H1 2026 source; this record documents the tracked framework/infrastructure-abuse statistics, their MITRE ATT&CK-documented technical basis, and their detection-engineering implications rather than fabricating attribution or indicators the source does not provide.

MITRE ATT&CK techniques used in TL-2026-2469

Credential Access

T1003.001 LSASS Memory; T1558.001 Golden Ticket

Defense Evasion

T1027 Obfuscated Files or Information; T1055 Process Injection

Execution

T1059.001 PowerShell

Command and Control

T1071 Application Layer Protocol; T1071.001 Web Protocols; T1071.004 DNS; T1090.001 Internal Proxy; T1090.004 Domain Fronting

Privilege Escalation

T1134 Access Token Manipulation; T1548.002 Bypass User Account Control

command-and-control

T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography

Resource Development

T1583 Acquire Infrastructure; T1583.001 Domains; T1583.003 Virtual Private Server; T1583.005 Botnet

Remediation for Spamhaus H1 2026 Botnet Threat Update

Immediate actions

  • Update C2 detection signatures and behavioral analytics to prioritize Sliver (mTLS/HTTP(S)/DNS/Wireguard listener traffic, Golang implant staging artifacts, self-signed certificate patterns) given its rise to the #1 tracked C2 framework in H1 2026
  • Increase scrutiny of newly registered .cn top-level domains and domains registered through India's PDR registrar in DNS resolution and proxy logs, given the 771% and 901% abuse spikes respectively reported for H1 2026
  • Do not deprioritize Cobalt Strike detection coverage despite its 68% drop in Spamhaus's tracked corpus - Spamhaus separately reports overall botnet C&C activity rose 24% in the same period, indicating displacement toward Sliver rather than an overall reduction in C2 activity
  • Hunt for Sliver-specific host artifacts documented by MITRE: procdump-style LSASS access, PowerShell child processes spawned from unusual parents, SOCKS5 internal-proxy traffic, and Rubeus-style Kerberos ticket-forging activity

Longer-term hardening

  • Deploy or extend EDR/NDR behavioral coverage tuned for open-source Golang C2 frameworks (Sliver: T1573.001/.002 encrypted channels, T1071.001/.004 web/DNS C2, T1090.001 internal proxy, T1027 Go-native obfuscation via garble/gobfuscate) alongside existing Cobalt Strike signatures
  • Integrate Spamhaus's Botnet Controller List (BCL), Spamhaus Blocklist (SBL), and Exploits Blocklist (XBL) feeds into perimeter/DNS security controls; government-funded CERTs/CSIRTs should evaluate onboarding to the Spamhaus CERT Insight Portal for enriched IP/ASN/malware/country-level botnet C&C and bot-infection reporting
  • Track Remote Access Trojan (RAT) family prevalence in detection engineering roadmaps, given RATs have comprised 42% of Spamhaus's Top 20 botnet-associated malware families across both the H2 2025 and H1 2026 reporting periods
  • Treat sudden shifts in registrar-of-record (e.g., PDR) or ccTLD (e.g., .cn) volume in an organization's own DNS telemetry as a leading indicator of adversary infrastructure churn, correlating against Spamhaus's semi-annual botnet threat updates
  • Cross-reference internal malware detections against Malpedia family entries when consuming Spamhaus/CERT Insight Portal botnet C&C data, to align internal naming with the community-standard malware-family taxonomy

Timeline of Spamhaus H1 2026 Botnet Threat Update

  • Spamhaus publishes 'Networks Hosting Botnet C&Cs: Same Players, Same Problems' (H2 2024 data, Alibaba overtakes Tencent for #1 abused-hosting rank) - cited here as background on Spamhaus's hosting-network tracking methodology, not part of the H1 2026 figures.
  • Per Spamhaus's CERT Insight Portal materials, botnet C&C activity detected by Spamhaus rose 56% across calendar year 2025, providing broader annual context for the 24% period-over-period rise reported in both the H2 2025 and H1 2026 updates.
  • End of the prior tracking period Spamhaus uses as its H1 2026 comparison baseline: Cobalt Strike held #1 with 3,451 detections; Sliver stood at 1,904 detections.
  • Spamhaus's January-June 2026 botnet C&C measurement window begins.
  • Spamhaus publishes the 'Botnet Threat Update July to December 2025' report: C&C activity rose 24% period-over-period, RATs again comprised 42% of the Top 20 botnet-associated malware, and a Russia-based registrar recorded a +9,608% surge in abused botnet C&C domain registrations - the immediate prior-period baseline for the H1 2026 update.
  • Measurement window closes: 14,952 total observed botnet C&C servers (-30%); Sliver rises to 3,008 detections (+58%, #1); Cobalt Strike falls to 1,110 detections (-68%, #4); .cn C&C domain registrations +771%; PDR registrar abuse +901%; REGRU registrar abuse -90%.
  • Security Boulevard and other outlets syndicate/summarize the H1 2026 findings the same day.
  • Spamhaus publicizes enhancements to its CERT Insight Portal (enriched IP/ASN/malware/country botnet C&C reporting, including the XBL-backed Bot Report and Malpedia-correlated Botnet C&C Report, for government CERTs/CSIRTs) alongside the H1 2026 update.
  • The Spamhaus Project publishes the 'Botnet Threat Update January to June 2026' report and accompanying blog post.

Sources cited for Spamhaus H1 2026 Botnet Threat Update

More in threat intel

Detection coverage for TL-2026-2469

As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2469 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats