Spamhaus H1 2026 Botnet Threat Update: Sliver Overtakes Cobalt Strike as Leading C2 Framework, .cn C&C Domains Surge +771%
Spamhaus H1 2026 Botnet Threat Update (TL-2026-2469) is a medium-severity tracked intrusion set, first published 2026-09-12. It has no confirmed attribution, maps to 18 MITRE ATT&CK techniques (T1003.001, T1027, T1055), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-2469
- Threat ID
- TL-2026-2469
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-09-12
- Last reviewed
- 2026-09-12
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Spamhaus H1 2026 Botnet Threat Update
Malware and tooling: Cobalt Strike, Remote Access Trojans (RATs), Cobalt Strike, Rubeus - S1071, Sliver - S0633, garble, gobfuscate
Spamhaus's January-June 2026 botnet threat update reports observed botnet C&C servers fell 30% to 14,952 while the open-source Sliver C2 framework rose 58% (1,904 to 3,008 detections) to overtake Cobalt Strike, which fell 68% (3,451 to 1,110) and dropped from #1 to #4 - its largest recorded decline. .cn C&C domains surged 771% and India's PDR registrar saw a 901% spike in abused registrations, while REGRU cut abuse by 90%.
How Spamhaus H1 2026 Botnet Threat Update works
The Spamhaus Project's semi-annual Botnet Threat Update for January-June 2026 documents a structural shift in the command-and-control (C2) tooling landscape tracked across its botnet C&C corpus. Total observed botnet C&C servers fell 30% period-over-period to 14,952, yet Spamhaus separately notes overall botnet C&C activity rose 24% in the same window - the two figures together indicating a smaller but more active tracked infrastructure base rather than a genuine decline in botnet operations. This 24% rise continues a trend from the immediately preceding period: Spamhaus's 'Botnet Threat Update July to December 2025' (published 2026-01-12) already reported a 24% period-over-period C&C activity increase, and Spamhaus's CERT Insight Portal materials separately state botnet C&C activity detected by Spamhaus rose 56% across calendar year 2025.
The headline finding is a leadership change among adversary C2 frameworks. Sliver, the open-source, cross-platform Golang C2 framework originally built by Bishop Fox as a red-team tool (MITRE ATT&CK Software S0633) and now widely abused by financially motivated and espionage threat actors as a Cobalt Strike alternative, climbed from 1,904 to 3,008 detections (+58%) to take the #1 spot. Cobalt Strike (MITRE ATT&CK Software S0154) - long the dominant commercial red-team-tool-turned-adversary-C2 framework - fell from 3,451 to 1,110 detections (-68%), dropping from #1 to #4. Spamhaus states this is Cobalt Strike's largest percentage decline since it began tracking the framework, consistent with a broader industry pattern of licensing crackdowns, cracked-license takedown pressure, and improved signature-based detection pushing adversaries toward Sliver and other emerging frameworks. Spamhaus's Top 20 botnet-associated malware list is now 42% Remote Access Trojans (RATs) by family count (unchanged from the July-December 2025 period), underscoring that C2-framework and RAT tradecraft together dominate the tracked botnet corpus.
MITRE ATT&CK's own Sliver (S0633) software page - cited directly as a primary technical source for this record - documents the specific tradecraft driving Sliver's detection-engineering relevance: built-in UAC-bypass and access-token-manipulation capabilities for privilege escalation; PowerShell command execution; Wireguard, HTTP(S), and DNS-based C2 channels; AES-GCM-256 symmetric and mutual-TLS/RSA asymmetric encrypted channels; Go-native obfuscation via the garble and gobfuscate libraries; a built-in SOCKS5 internal proxy; a procdump command for LSASS credential dumping; and incorporation of the Rubeus toolkit for forging Kerberos Golden Tickets. MITRE documents APT29 (G0016), Cinnamon Tempest (G1021), and TA551 (G0127) as threat groups that have used Sliver - concrete evidence that Sliver's H1 2026 detection surge reflects genuine, diverse adversary adoption rather than isolated red-team noise.
The report also documents a sharp shift in the domain-registration infrastructure adversaries use to stand up C2: .cn (China) botnet C&C domain registrations surged 771%, and India-based registrar PDR (Publicdomainregistry.com) saw abused registrations spike 901%. In contrast, Russian registrar REGRU cut abuse by 90%, which Spamhaus frames as a positive counter-trend against otherwise rising registrar abuse - notably, a different Russia-based registrar had recorded a +9,608% surge in abused botnet C&C domains in the immediately preceding July-December 2025 period, underscoring how registrar-level abuse patterns can swing sharply between consecutive reporting periods. These figures describe where and through whom adversaries are acquiring C2 domain infrastructure (MITRE ATT&CK Resource Development), not a specific victim campaign, and Spamhaus does not attribute the trend to a single threat actor or campaign.
Alongside the update, Spamhaus references its CERT Insight Portal - a free tool for government-funded national/regional CERTs and CSIRTs (over 100 of which already rely on Spamhaus data for remediation, per Spamhaus) - that layers enriched IP/ASN/malware/country metadata atop three underlying Spamhaus data sources: the Botnet Controller List (BCL), the Spamhaus Blocklist (SBL), and the Exploits Blocklist (XBL, which detects malware-infected hosts and underpins the portal's 'Bot Report'). The portal's separate 'Botnet C&C Report' cross-references detected botnet C&C servers against Malpedia, the Fraunhofer FKIE malware-family reference database, for family-level correspondence. This tooling is part of a broader push - alongside network operators and law enforcement - to target bulletproof hosting providers and the IP brokers/network carriers/datacenters that sustain them.
No CVE, specific network IOC list (IPs/domains/hashes), or single-campaign threat-actor attribution is stated in the primary H1 2026 source; this record documents the tracked framework/infrastructure-abuse statistics, their MITRE ATT&CK-documented technical basis, and their detection-engineering implications rather than fabricating attribution or indicators the source does not provide.
MITRE ATT&CK techniques used in TL-2026-2469
Credential Access
T1003.001 LSASS Memory; T1558.001 Golden Ticket
Defense Evasion
T1027 Obfuscated Files or Information; T1055 Process Injection
Execution
Command and Control
T1071 Application Layer Protocol; T1071.001 Web Protocols; T1071.004 DNS; T1090.001 Internal Proxy; T1090.004 Domain Fronting
Privilege Escalation
T1134 Access Token Manipulation; T1548.002 Bypass User Account Control
command-and-control
T1573.001 Symmetric Cryptography; T1573.002 Asymmetric Cryptography
Resource Development
T1583 Acquire Infrastructure; T1583.001 Domains; T1583.003 Virtual Private Server; T1583.005 Botnet
Remediation for Spamhaus H1 2026 Botnet Threat Update
Immediate actions
- Update C2 detection signatures and behavioral analytics to prioritize Sliver (mTLS/HTTP(S)/DNS/Wireguard listener traffic, Golang implant staging artifacts, self-signed certificate patterns) given its rise to the #1 tracked C2 framework in H1 2026
- Increase scrutiny of newly registered .cn top-level domains and domains registered through India's PDR registrar in DNS resolution and proxy logs, given the 771% and 901% abuse spikes respectively reported for H1 2026
- Do not deprioritize Cobalt Strike detection coverage despite its 68% drop in Spamhaus's tracked corpus - Spamhaus separately reports overall botnet C&C activity rose 24% in the same period, indicating displacement toward Sliver rather than an overall reduction in C2 activity
- Hunt for Sliver-specific host artifacts documented by MITRE: procdump-style LSASS access, PowerShell child processes spawned from unusual parents, SOCKS5 internal-proxy traffic, and Rubeus-style Kerberos ticket-forging activity
Longer-term hardening
- Deploy or extend EDR/NDR behavioral coverage tuned for open-source Golang C2 frameworks (Sliver: T1573.001/.002 encrypted channels, T1071.001/.004 web/DNS C2, T1090.001 internal proxy, T1027 Go-native obfuscation via garble/gobfuscate) alongside existing Cobalt Strike signatures
- Integrate Spamhaus's Botnet Controller List (BCL), Spamhaus Blocklist (SBL), and Exploits Blocklist (XBL) feeds into perimeter/DNS security controls; government-funded CERTs/CSIRTs should evaluate onboarding to the Spamhaus CERT Insight Portal for enriched IP/ASN/malware/country-level botnet C&C and bot-infection reporting
- Track Remote Access Trojan (RAT) family prevalence in detection engineering roadmaps, given RATs have comprised 42% of Spamhaus's Top 20 botnet-associated malware families across both the H2 2025 and H1 2026 reporting periods
- Treat sudden shifts in registrar-of-record (e.g., PDR) or ccTLD (e.g., .cn) volume in an organization's own DNS telemetry as a leading indicator of adversary infrastructure churn, correlating against Spamhaus's semi-annual botnet threat updates
- Cross-reference internal malware detections against Malpedia family entries when consuming Spamhaus/CERT Insight Portal botnet C&C data, to align internal naming with the community-standard malware-family taxonomy
Timeline of Spamhaus H1 2026 Botnet Threat Update
- Spamhaus publishes 'Networks Hosting Botnet C&Cs: Same Players, Same Problems' (H2 2024 data, Alibaba overtakes Tencent for #1 abused-hosting rank) - cited here as background on Spamhaus's hosting-network tracking methodology, not part of the H1 2026 figures.
- Per Spamhaus's CERT Insight Portal materials, botnet C&C activity detected by Spamhaus rose 56% across calendar year 2025, providing broader annual context for the 24% period-over-period rise reported in both the H2 2025 and H1 2026 updates.
- End of the prior tracking period Spamhaus uses as its H1 2026 comparison baseline: Cobalt Strike held #1 with 3,451 detections; Sliver stood at 1,904 detections.
- Spamhaus's January-June 2026 botnet C&C measurement window begins.
- Spamhaus publishes the 'Botnet Threat Update July to December 2025' report: C&C activity rose 24% period-over-period, RATs again comprised 42% of the Top 20 botnet-associated malware, and a Russia-based registrar recorded a +9,608% surge in abused botnet C&C domain registrations - the immediate prior-period baseline for the H1 2026 update.
- Measurement window closes: 14,952 total observed botnet C&C servers (-30%); Sliver rises to 3,008 detections (+58%, #1); Cobalt Strike falls to 1,110 detections (-68%, #4); .cn C&C domain registrations +771%; PDR registrar abuse +901%; REGRU registrar abuse -90%.
- Security Boulevard and other outlets syndicate/summarize the H1 2026 findings the same day.
- Spamhaus publicizes enhancements to its CERT Insight Portal (enriched IP/ASN/malware/country botnet C&C reporting, including the XBL-backed Bot Report and Malpedia-correlated Botnet C&C Report, for government CERTs/CSIRTs) alongside the H1 2026 update.
- The Spamhaus Project publishes the 'Botnet Threat Update January to June 2026' report and accompanying blog post.
Sources cited for Spamhaus H1 2026 Botnet Threat Update
- Botnet C&C | Botnet Threat Update January to June 2026 | Report
- Botnet Threat Update January to June 2026 - Security Boulevard
- Botnet Threat Update January to June 2026 | daily.dev
- NEW: Spamhaus CERT Insight Portal - Enhanced Botnet C&C Intelligence
- Botnet Spotlight | Networks Hosting Botnet C&Cs: Same Players, Same Problems
- Botnet C&C | Botnet Threat Update July to December 2025 | Report
- Sliver, Software S0633 | MITRE ATT&CK
- Cobalt Strike, Software S0154 | MITRE ATT&CK
- Acquire Infrastructure, Technique T1583 | MITRE ATT&CK
- Sliver (win.sliver) Malware Family | Malpedia
More in threat intel
- Infostealer Logs Expose Replayable AI Session Tokens and API Keys Enabling MFA Bypass
- China-Based AI Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. Frontier AI Models
- Autonomous AI-agent frameworks automating credential theft and cyber espionage (Google Threat Intelligence Group Q3 2026 AI Threat Tracker)
- ClearFake WebDAV infection chain delivering Amatera stealer 4.1.5-alpha, ZigCryptoStealer, and NetSupport Manager 12.44 (UAT-10820)
- OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and Scope Violations Found in Safety Testing
Detection coverage for TL-2026-2469
As of 2026-09-12, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2469 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.