Spamhaus H2 2025 Botnet Threat Update: VenomRAT Developer Arrest, Latrodectus Resurgence, and Shift Toward Domain-Based C2 Amid Bulletproof Hosting Crackdowns
Spamhaus H2 2025 Botnet Threat Update (TL-2026-2470), also tracked as Botnet Spotlight: Pressure Rises on Botnets, is a medium-severity malware campaign, first published 2026-01-27. It is attributed to TA577 - G1037 with medium confidence, affects Venom RAT (malware family, Quasar RAT derivative) Windows endpoints, maps to 15 MITRE ATT&CK techniques (T1027, T1053.005, T1059.001), and is covered by 9 detection rules and 25 indicators of compromise.
Key facts for TL-2026-2470
- Threat ID
- TL-2026-2470
- Also known as
- Botnet Spotlight: Pressure Rises on Botnets, Operation Endgame (November 2025 phase)
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-01-27
- Last reviewed
- 2026-01-27
- Attribution
- TA577 - G1037
- Attribution confidence
- MEDIUM
- Motivation
- FINANCIAL
- Target sectors
- government administration, health, critical-infrastructure, finance, cryptocurrency, cloud-hosting
- Target regions
- Global, North America, Europe
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Spamhaus H2 2025 Botnet Threat Update
Malware and tooling: BackConnect, Brute Ratel C4, Elysium, IcedID, Latrodectus - S1160, Lumma Stealer - S1213, NJRat, Quasar RAT, Remcos, Rhadamanthys, Venom RAT, XWorm
Spamhaus's Botnet Spotlight for July-December 2025 documents steep declines in live botnet C2 servers at major cloud providers, driven by Europol's Operation Endgame (1,025 servers and 20 domains seized in November 2025, VenomRAT's principal developer arrested in Greece) and the dismantling of the Netherlands-based bulletproof hoster CrazyRDP. Despite this pressure, the Latrodectus loader resurfaced after a May 2025 takedown that produced no arrests, and rising botnet-controller counts at Contabo, DigitalOcean, and ColoCrossing show operators shifting toward domain-based C2 and less-cooperative hosting providers.
How Spamhaus H2 2025 Botnet Threat Update works
Spamhaus's semiannual Botnet Spotlight report (published 2026-01-27, authored by Jonas Arnold) tracks live and newly observed botnet command-and-control servers across the internet's largest hosting networks for the July-December 2025 period. It records sharp declines in live C2 counts at Huawei (-76%), Tencent (-54%), Alibaba (-46%), Amazon (-43%), and Google (-41%), attributing the drop primarily to sustained law-enforcement pressure rather than voluntary provider hardening -- Tencent and Alibaba, notably, still showed double-digit increases in newly observed controllers (+16% and +14% respectively), indicating the underlying abuse pipeline persists even as legacy infrastructure is cleaned up.
The dominant driver was Europol and Eurojust's Operation Endgame, whose November 2025 phase (coordinated 10-14 November from The Hague, with searches across 11 locations in Germany, Greece, and the Netherlands, and agencies from Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the UK, and the US) took down 1,025 servers and seized 20 domains tied to three malware operations: the Rhadamanthys infostealer, the VenomRAT remote access trojan, and the Elysium proxy botnet. Rhadamanthys had infected hundreds of thousands of systems across 175 countries (per Shadowserver tracking, March-November 2025) and held several million stolen credentials, with its principal operator controlling access to over 100,000 victim cryptocurrency wallets; more than 60% of its C2 servers reportedly went undetected on VirusTotal. VenomRAT -- a Quasar RAT derivative sold for roughly $150/month and distributed chiefly via TA558 phishing campaigns (JavaScript downloader -> PowerShell -> payload, lures in Portuguese/Spanish/English) -- lost its principal developer to arrest in Greece on 2025-11-03, and both its advertising domain (remotesystem.in) and licensing domain (venomlicense.com) were seized; Proofpoint observed no further VenomRAT activity in its telemetry after September 2025. Elysium operated as a rentable proxy botnet, routing criminal traffic through hundreds of thousands of compromised residential devices to mask attacker origin, with observed links to campaigns against critical infrastructure, healthcare, and government targets. This November action followed the May 2025 Operation Endgame 2.0 phase, which took down roughly 300 servers and 650 domains and issued 20 international arrest warrants -- but produced no arrests tied to Latrodectus, whose over 44,000 infected IPs were only partially remediated. Separately, Dutch police dismantled the bulletproof hosting provider CrazyRDP on 2025-11-12, seizing roughly 250 physical servers (supporting thousands of VMs) from datacenters in The Hague and Zoetermeer; the no-KYC, no-logs provider had been implicated in more than 80 law-enforcement investigations spanning ransomware, botnets, phishing, and CSAM distribution.
Despite this pressure, the report's central warning is that takedowns without arrests are self-defeating: Latrodectus -- a loader attributed to the Lunar Spider group (also linked to IcedID) and distributed by TA577/TA578 via hijacked-email-thread malspam and, in tax-season waves, SEO-poisoned fake-IRS sites -- resurfaced after its arrest-less May 2025 takedown, again delivering Lumma Stealer, IcedID, BackConnect C2, and Brute Ratel C4 as follow-on payloads. Spamhaus also flags Contabo, DigitalOcean, and ColoCrossing as hosting providers with rising live and newly observed botnet-controller counts, and names smaller Western bulletproof hosters (virtualine.org, as210558.net, simplecarrier.net) operating on a 'separation of liabilities' model. Together these findings indicate botnet operators are structurally adapting: shifting from easily IP-blocklisted infrastructure toward domain-based C2 and toward hosting providers less willing or able to act on abuse reports, meaning IP-reputation blocking alone is no longer sufficient defense.
MITRE ATT&CK techniques used in TL-2026-2470
Defense Evasion
T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion
Persistence
T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy
Discovery
T1082 System Information Discovery
Credential Access
T1555 Credentials from Password Stores
Initial Access
T1566.002 Phishing: Spearphishing Link
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server
Affected products and versions in Spamhaus H2 2025 Botnet Threat Update
- Venom RAT (malware family, Quasar RAT derivative) — Windows endpoints infected via TA558 phishing delivery
Vulnerable versions: All builds distributed prior to the November 2025 takedown - Rhadamanthys (malware family) — Windows endpoints infected via infostealer delivery
Vulnerable versions: All builds active March-November 2025 - Latrodectus (malware family, Lunar Spider) — Windows endpoints infected via malspam/SEO-poisoning loader delivery
Vulnerable versions: v1.4 (2024-07) and later, active post-resurgence - Elysium (proxy botnet) — Compromised residential/IoT devices used as proxy exit nodes
Vulnerable versions: All devices enrolled prior to November 2025 takedown - Multiple IaaS/hosting providers — Cloud/VPS hosting abused for botnet C2 (Huawei Cloud, Tencent Cloud, Alibaba Cloud, AWS, Google Cloud, Contabo, DigitalOcean, ColoCrossing, CrazyRDP)
Vulnerable versions: Ongoing abuse as of H2 2025
Fixed in: CrazyRDP dismantled 2025-11-12
Remediation for Spamhaus H2 2025 Botnet Threat Update
Immediate actions
- Retrospectively hunt for historical connections to the seized VenomRAT infrastructure domains remotesystem.in and venomlicense.com
- Audit outbound network connections to Contabo, DigitalOcean, and ColoCrossing IP ranges for anomalous RAT/loader beaconing given their rising botnet-controller share
- Direct potentially compromised users toward politie.nl/checkyourhack and haveibeenpwned.com to check credential exposure from the Rhadamanthys takedown dataset
Workarounds
- Restrict PowerShell execution policy and script-host (wscript/cscript) execution on endpoints to reduce loader-stage execution success
- Apply email filtering tuned against hijacked-email-thread malspam and SEO-poisoning lures impersonating Microsoft Azure, Cloudflare, and IRS tax-form portals
Longer-term hardening
- Shift botnet/C2 detection strategy from IP-reputation blocklists toward DNS- and domain-reputation-based detection given the industry-wide move to domain-based C2
- Deploy behavioral detection for JavaScript-downloader-to-PowerShell execution chains characteristic of VenomRAT/TA558 delivery
- Monitor for the full Latrodectus follow-on payload set (Lumma Stealer, IcedID, BackConnect, Brute Ratel C4) as a linked cluster rather than isolated single-family alerts
Timeline of Spamhaus H2 2025 Botnet Threat Update
- Latrodectus loader first observed in the wild, attributed to the Lunar Spider group and linked to prior IcedID operations.
- Latrodectus v1.4 released, adding AES256 encryption, new backdoor commands, and improved obfuscation.
- Latrodectus activity surges through the US tax season, using SEO-poisoned fake-IRS sites to deliver W2-themed lures.
- Operation Endgame 2.0 (coordinated by Europol/Eurojust, 19-22 May) takes down roughly 300 servers and 650 domains and issues 20 international arrest warrants, targeting Latrodectus infrastructure among others, but produces no Latrodectus-linked arrests.
- Proofpoint records the last VenomRAT-associated campaign activity in its telemetry before a months-long lull.
- Rhadamanthys reaches a peak of 535 active command-and-control servers and averages over 4,000 uniquely infected IPs per day, per Black Lotus Labs tracking.
- The principal VenomRAT suspect, a 39-year-old Albanian national, is arrested in Greece.
- Dutch police dismantle the bulletproof hosting provider CrazyRDP, seizing roughly 250 physical servers from datacenters in The Hague and Zoetermeer.
- Europol publicly announces the latest Operation Endgame phase: 1,025 servers and 20 domains seized targeting Rhadamanthys, VenomRAT, and the Elysium proxy botnet, coordinated across 11 countries.
- Close of the July-December 2025 reporting window covered by Spamhaus's Botnet Spotlight, during which live botnet C2 counts fell sharply at Huawei, Tencent, Alibaba, Amazon, and Google while rising at Contabo, DigitalOcean, and ColoCrossing.
- Spamhaus publishes 'Botnet Spotlight: Pressure rises on botnets — but the fight is far from over,' documenting the H2 2025 findings.
Sources cited for Spamhaus H2 2025 Botnet Threat Update
- Botnet Spotlight: Pressure rises on botnets — but the fight is far from over
- End of the game for cybercrime infrastructure: 1025 servers taken down
- Police disrupts Rhadamanthys, VenomRAT, and Elysium malware operations
- Operation Endgame Dismantles Rhadamanthys, Venom RAT, and Elysium Botnet in Global Crackdown
- Operation Endgame targets malware networks in global crackdown
- Greek Police Arrest Alleged Mastermind of the Venom RAT Malware Network
- Security brief: VenomRAT is defanged
- Analyzing Latrodectus: The New Face of Malware Loaders
- Dutch police takes down bulletproof hosting hub linked to 80+ cybercrime cases
- Dutch police seizes 250 servers used by "bulletproof hosting" service
- Initial access brokers infected over 44 thousand IPs with Latrodectus malware
- Botnet Spotlight: Networks Hosting Botnet C&Cs — Same Players, Same Problems
More in malware
- Deceptive Android Apps Exploit Google Play Early Access to Reach Mobile Users
- Malspam campaign weaponizes business-complaint lures to deliver PureRAT and PureLogs
- Phishing campaign targeting Japanese/Korean orgs delivering PureRAT / PureLogs RATs via ZIP archives and diverse loaders (DLL side-loading, Donut, Python, process hollowing, BYOVD)
- SectopRAT (ArechClient2) Variant Hidden Inside Legitimate Italian Digital-Audio Software via FrameworkBase.dll Tampering
- Multi-Stage Abuse of Legitimate Remote Access Tools (ConnectWise, N-Able, SimpleHelp, Datto RMM, GoTo) by Initial Access Brokers
Detection coverage for TL-2026-2470
As of 2026-01-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2470 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.