HabrAugust 6, 2026🇷🇺Translated from Russian

DDoS-Guard Reports Record 540,000 L7 Attacks in June 2026 Amid Botnet Fragmentation

DDoS-Guard has published its Q2 2026 threat report, documenting an absolute record in the number of DDoS attacks and several notable shifts in attacker tactics.

Globally, the volume of terabit-class attacks doubled compared with the entire previous year. The two largest incidents reached 1.64 Tbps and 1.58 Tbps, generating 553 Mpps and 638 Mpps respectively. The largest overseas botnet observed contained approximately 2.09 million devices.

In March, authorities in the United States, Canada and Germany dismantled the infrastructure of four major IoT botnets: Aisuru, KimWolf, JackSkid and Mossad. Despite these takedowns, DDoS-Guard observed prolonged, highly distributed attacks throughout the quarter, indicating that attackers are compensating for smaller botnets by improving node efficiency and leveraging cloud resources.

Multiple vendors reported a rise in multi-vector campaigns that combine volumetric, protocol-exhaustion and application-layer techniques. At the same time, low-and-slow attacks designed to evade traditional filtering remain prevalent.

In April, Europol coordinated Operation PowerOFF across 21 countries, resulting in more than 75,000 warnings sent to users of DDoS-for-hire services, four arrests, infrastructure seizures and the closure of 53 domains.

On DDoS-Guard’s own network, L7 attacks increased 70% quarter-over-quarter, with the daily average nearly doubling. Median requests per second rose 270% to 75. The number of attacks lasting more than 24 hours grew by 380%. June set a new single-month record with 540,000 L7 attacks—236% more than April and 300% more than June 2025.

Attackers showed particular interest in job-search and HR platforms (+40%) as well as news outlets (+30%). Experts link the surge to the rapid expansion of public web services and APIs in Russia combined with the increasing use of browser automation and AI agents that make HTTP attacks harder to distinguish from legitimate traffic.

Related articles

BoletimSecMalware & Botnets

Casbaneiro Banking Trojan Targets Financial Institutions in Argentina, Peru, Colombia and Mexico

Fortinet researchers identified a Casbaneiro campaign in August that specifically targets bank customers across four Latin American countries. The infection begins with a PDF attachment that displays the recipient's own email address to build credibility and creates urgency around an unpaid invoice or judicial notice. The PDF link performs IP-based geofencing, redirecting non-target visitors to Google or YouTube while delivering a Base64-encoded ZIP only to victims in the selected countries. Inside the archive, an HTA file downloads the legitimate AutoIt interpreter along with a compiled script and compressed payload, helping evade binary-focused defenses. The malware stays dormant until the victim visits a monitored banking website, at which point it activates its C2 channel, exfiltrates Outlook contact data, and can display bank-specific credential-harvesting overlays. Additional remote-access capabilities allow operators to control the keyboard, manipulate the clipboard, and execute arbitrary commands on the infected system.

BoletimSecMalware & Botnets

Cybercriminals Distribute NJRAT, DCRAT and Chaos via Fake GTA 6 Downloads

Threat actors are leveraging anticipation around GTA 6 to spread multiple malware families through fake game downloads. Security researchers at Huntress identified campaigns that combine search-engine poisoning, gaming forums, torrent sites and social-media posts to deliver oversized fake ISO files exceeding 100 GB. Victims who execute the installer see Russian-language messages claiming an invalid crack or missing license, while remote-access tools and data stealers run silently in the background. The delivered payloads include NJRAT and DCRAT for keystroke logging, screen capture and webcam access, Mercurial Grabber for harvesting browser credentials and Discord tokens, and the Chaos wiper that encrypts small files and overwrites larger ones. The operation primarily targets Russian-speaking gamers, as indicated by the ransom note and error messages. Analysts recommend avoiding unofficial downloads and isolating any compromised systems immediately.

HabrMalware & Botnets

Smartphone Spyware: How Devices Collect and Exfiltrate Data Even Without Internet Access

Modern smartphones continue gathering sensor data including microphone, camera, gyroscope, and satellite navigation even when Wi-Fi and mobile data are disabled. Information is stored locally and transmitted only when connectivity is restored. The Find My Device feature from Google and Find My from Apple allow location reporting for hours after the device is powered off via a separate Bluetooth chip. In August 2026, ThreatFabric disclosed the Manic trojan that uses Wi-Fi Direct, Bluetooth RFCOMM, and BLE GATT to relay encrypted data through nearby infected devices when direct internet access is unavailable. The malware supports multi-hop routing of up to four intermediate devices. Everyday users face greater risk from over-privileged applications and pre-installed malware on gray-market devices than from sophisticated offline exfiltration techniques. A detailed checklist covers purchase hygiene, permission audits, and recovery steps after suspected compromise.

AntiMalwareMalware & Botnets

Reconstructed Stuxnet Source Code Published on GitHub with Build Instructions

An unknown researcher has released a reconstructed version of the Stuxnet worm source code on GitHub, including reverse-engineering results and assembly instructions. Stuxnet was discovered in 2010 and is widely attributed to the joint US-Israeli Olympic Games operation targeting Iran's Natanz uranium enrichment facility. The malware specifically attacked Siemens industrial controllers by altering frequency converter operations to physically damage centrifuge rotors while falsifying operator displays. Propagation relied on USB drives, network shares, and a Windows Print Spooler vulnerability, combined with stolen Realtek and JMicron driver-signing certificates. The worm also injected itself into Siemens WinCC and Step 7 software to intercept communications with programmable logic controllers. Due to a flaw in its environment checks, Stuxnet escaped the target network and spread publicly before its built-in June 2012 self-destruct date. Researchers are advised to analyze the code only inside fully isolated virtual machines without network access.