Spamhaus H2 2025 Botnet Threat Update: VenomRAT Developer Arrest, Latrodectus Resurgence, and Shift Toward Domain-Based C2 Amid Bulletproof Hosting Crackdowns

Spamhaus H2 2025 Botnet Threat Update (TL-2026-2470), also tracked as Botnet Spotlight: Pressure Rises on Botnets, is a medium-severity malware campaign, first published 2026-01-27. It is attributed to TA577 - G1037 with medium confidence, affects Venom RAT (malware family, Quasar RAT derivative) Windows endpoints, maps to 15 MITRE ATT&CK techniques (T1027, T1053.005, T1059.001), and is covered by 9 detection rules and 25 indicators of compromise.

Key facts for TL-2026-2470

Threat ID
TL-2026-2470
Also known as
Botnet Spotlight: Pressure Rises on Botnets, Operation Endgame (November 2025 phase)
Severity
MEDIUM
Status
ACTIVE
Category
MALWARE
First published
2026-01-27
Last reviewed
2026-01-27
Attribution
TA577 - G1037
Attribution confidence
MEDIUM
Motivation
FINANCIAL
Target sectors
government administration, health, critical-infrastructure, finance, cryptocurrency, cloud-hosting
Target regions
Global, North America, Europe
Detection rules
9
Indicators of compromise
25

Malware and tooling in Spamhaus H2 2025 Botnet Threat Update

Malware and tooling: BackConnect, Brute Ratel C4, Elysium, IcedID, Latrodectus - S1160, Lumma Stealer - S1213, NJRat, Quasar RAT, Remcos, Rhadamanthys, Venom RAT, XWorm

Spamhaus's Botnet Spotlight for July-December 2025 documents steep declines in live botnet C2 servers at major cloud providers, driven by Europol's Operation Endgame (1,025 servers and 20 domains seized in November 2025, VenomRAT's principal developer arrested in Greece) and the dismantling of the Netherlands-based bulletproof hoster CrazyRDP. Despite this pressure, the Latrodectus loader resurfaced after a May 2025 takedown that produced no arrests, and rising botnet-controller counts at Contabo, DigitalOcean, and ColoCrossing show operators shifting toward domain-based C2 and less-cooperative hosting providers.

How Spamhaus H2 2025 Botnet Threat Update works

Spamhaus's semiannual Botnet Spotlight report (published 2026-01-27, authored by Jonas Arnold) tracks live and newly observed botnet command-and-control servers across the internet's largest hosting networks for the July-December 2025 period. It records sharp declines in live C2 counts at Huawei (-76%), Tencent (-54%), Alibaba (-46%), Amazon (-43%), and Google (-41%), attributing the drop primarily to sustained law-enforcement pressure rather than voluntary provider hardening -- Tencent and Alibaba, notably, still showed double-digit increases in newly observed controllers (+16% and +14% respectively), indicating the underlying abuse pipeline persists even as legacy infrastructure is cleaned up.

The dominant driver was Europol and Eurojust's Operation Endgame, whose November 2025 phase (coordinated 10-14 November from The Hague, with searches across 11 locations in Germany, Greece, and the Netherlands, and agencies from Australia, Belgium, Canada, Denmark, France, Germany, Greece, Lithuania, the Netherlands, the UK, and the US) took down 1,025 servers and seized 20 domains tied to three malware operations: the Rhadamanthys infostealer, the VenomRAT remote access trojan, and the Elysium proxy botnet. Rhadamanthys had infected hundreds of thousands of systems across 175 countries (per Shadowserver tracking, March-November 2025) and held several million stolen credentials, with its principal operator controlling access to over 100,000 victim cryptocurrency wallets; more than 60% of its C2 servers reportedly went undetected on VirusTotal. VenomRAT -- a Quasar RAT derivative sold for roughly $150/month and distributed chiefly via TA558 phishing campaigns (JavaScript downloader -> PowerShell -> payload, lures in Portuguese/Spanish/English) -- lost its principal developer to arrest in Greece on 2025-11-03, and both its advertising domain (remotesystem.in) and licensing domain (venomlicense.com) were seized; Proofpoint observed no further VenomRAT activity in its telemetry after September 2025. Elysium operated as a rentable proxy botnet, routing criminal traffic through hundreds of thousands of compromised residential devices to mask attacker origin, with observed links to campaigns against critical infrastructure, healthcare, and government targets. This November action followed the May 2025 Operation Endgame 2.0 phase, which took down roughly 300 servers and 650 domains and issued 20 international arrest warrants -- but produced no arrests tied to Latrodectus, whose over 44,000 infected IPs were only partially remediated. Separately, Dutch police dismantled the bulletproof hosting provider CrazyRDP on 2025-11-12, seizing roughly 250 physical servers (supporting thousands of VMs) from datacenters in The Hague and Zoetermeer; the no-KYC, no-logs provider had been implicated in more than 80 law-enforcement investigations spanning ransomware, botnets, phishing, and CSAM distribution.

Despite this pressure, the report's central warning is that takedowns without arrests are self-defeating: Latrodectus -- a loader attributed to the Lunar Spider group (also linked to IcedID) and distributed by TA577/TA578 via hijacked-email-thread malspam and, in tax-season waves, SEO-poisoned fake-IRS sites -- resurfaced after its arrest-less May 2025 takedown, again delivering Lumma Stealer, IcedID, BackConnect C2, and Brute Ratel C4 as follow-on payloads. Spamhaus also flags Contabo, DigitalOcean, and ColoCrossing as hosting providers with rising live and newly observed botnet-controller counts, and names smaller Western bulletproof hosters (virtualine.org, as210558.net, simplecarrier.net) operating on a 'separation of liabilities' model. Together these findings indicate botnet operators are structurally adapting: shifting from easily IP-blocklisted infrastructure toward domain-based C2 and toward hosting providers less willing or able to act on abuse reports, meaning IP-reputation blocking alone is no longer sufficient defense.

MITRE ATT&CK techniques used in TL-2026-2470

Defense Evasion

T1027 Obfuscated Files or Information; T1497 Virtualization/Sandbox Evasion; T1622 Debugger Evasion

Persistence

T1053.005 Scheduled Task/Job: Scheduled Task; T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder

Execution

T1059.001 Command and Scripting Interpreter: PowerShell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.001 User Execution: Malicious Link

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090 Proxy

Discovery

T1082 System Information Discovery

Credential Access

T1555 Credentials from Password Stores

Initial Access

T1566.002 Phishing: Spearphishing Link

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1583.003 Acquire Infrastructure: Virtual Private Server

Affected products and versions in Spamhaus H2 2025 Botnet Threat Update

  • Venom RAT (malware family, Quasar RAT derivative) — Windows endpoints infected via TA558 phishing delivery
    Vulnerable versions: All builds distributed prior to the November 2025 takedown
  • Rhadamanthys (malware family) — Windows endpoints infected via infostealer delivery
    Vulnerable versions: All builds active March-November 2025
  • Latrodectus (malware family, Lunar Spider) — Windows endpoints infected via malspam/SEO-poisoning loader delivery
    Vulnerable versions: v1.4 (2024-07) and later, active post-resurgence
  • Elysium (proxy botnet) — Compromised residential/IoT devices used as proxy exit nodes
    Vulnerable versions: All devices enrolled prior to November 2025 takedown
  • Multiple IaaS/hosting providers — Cloud/VPS hosting abused for botnet C2 (Huawei Cloud, Tencent Cloud, Alibaba Cloud, AWS, Google Cloud, Contabo, DigitalOcean, ColoCrossing, CrazyRDP)
    Vulnerable versions: Ongoing abuse as of H2 2025
    Fixed in: CrazyRDP dismantled 2025-11-12

Remediation for Spamhaus H2 2025 Botnet Threat Update

Immediate actions

  • Retrospectively hunt for historical connections to the seized VenomRAT infrastructure domains remotesystem.in and venomlicense.com
  • Audit outbound network connections to Contabo, DigitalOcean, and ColoCrossing IP ranges for anomalous RAT/loader beaconing given their rising botnet-controller share
  • Direct potentially compromised users toward politie.nl/checkyourhack and haveibeenpwned.com to check credential exposure from the Rhadamanthys takedown dataset

Workarounds

  • Restrict PowerShell execution policy and script-host (wscript/cscript) execution on endpoints to reduce loader-stage execution success
  • Apply email filtering tuned against hijacked-email-thread malspam and SEO-poisoning lures impersonating Microsoft Azure, Cloudflare, and IRS tax-form portals

Longer-term hardening

  • Shift botnet/C2 detection strategy from IP-reputation blocklists toward DNS- and domain-reputation-based detection given the industry-wide move to domain-based C2
  • Deploy behavioral detection for JavaScript-downloader-to-PowerShell execution chains characteristic of VenomRAT/TA558 delivery
  • Monitor for the full Latrodectus follow-on payload set (Lumma Stealer, IcedID, BackConnect, Brute Ratel C4) as a linked cluster rather than isolated single-family alerts

Timeline of Spamhaus H2 2025 Botnet Threat Update

  • Latrodectus loader first observed in the wild, attributed to the Lunar Spider group and linked to prior IcedID operations.
  • Latrodectus v1.4 released, adding AES256 encryption, new backdoor commands, and improved obfuscation.
  • Latrodectus activity surges through the US tax season, using SEO-poisoned fake-IRS sites to deliver W2-themed lures.
  • Operation Endgame 2.0 (coordinated by Europol/Eurojust, 19-22 May) takes down roughly 300 servers and 650 domains and issues 20 international arrest warrants, targeting Latrodectus infrastructure among others, but produces no Latrodectus-linked arrests.
  • Proofpoint records the last VenomRAT-associated campaign activity in its telemetry before a months-long lull.
  • Rhadamanthys reaches a peak of 535 active command-and-control servers and averages over 4,000 uniquely infected IPs per day, per Black Lotus Labs tracking.
  • The principal VenomRAT suspect, a 39-year-old Albanian national, is arrested in Greece.
  • Dutch police dismantle the bulletproof hosting provider CrazyRDP, seizing roughly 250 physical servers from datacenters in The Hague and Zoetermeer.
  • Europol publicly announces the latest Operation Endgame phase: 1,025 servers and 20 domains seized targeting Rhadamanthys, VenomRAT, and the Elysium proxy botnet, coordinated across 11 countries.
  • Close of the July-December 2025 reporting window covered by Spamhaus's Botnet Spotlight, during which live botnet C2 counts fell sharply at Huawei, Tencent, Alibaba, Amazon, and Google while rising at Contabo, DigitalOcean, and ColoCrossing.
  • Spamhaus publishes 'Botnet Spotlight: Pressure rises on botnets — but the fight is far from over,' documenting the H2 2025 findings.

Sources cited for Spamhaus H2 2025 Botnet Threat Update

More in malware

Detection coverage for TL-2026-2470

As of 2026-01-27, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2470 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats