Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Why Burnout in Cybersecurity Demands Risk-Based Response

May 27, 2026

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

May 27, 2026

CrowdStrike, Google Take Down Glassworm Botnet

May 27, 2026
Facebook X (Twitter) Instagram
Wednesday, May 27
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»CrowdStrike, Google Take Down Glassworm Botnet
News

CrowdStrike, Google Take Down Glassworm Botnet

Team-CWDBy Team-CWDMay 27, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


An industry effort involving CrowdStrike, Google and the Shadowserver Foundation has led to the disruption of the Glassworm botnet.

Working together, the three organizations managed to simultaneously take down all four of Glassworm’s command-and-control (C2) channels, severing the operators from their infected machines and their ability to deliver new malicious payloads.

These channels included traditional C2 servers hosted on commercial virtual private servers (VPS).

The botnet also relied on less common and more stealthy assets, such as Google Calendar event titles which were used as dead-drop locations for Base64-encoded C2 paths, peer-to-peer networks and blockchain-based infrastructure, notably with C2 server addresses encoded in the memo fields of transactions on the Solana blockchain.

The Glassworm remote access tool queried the BitTorrent peer-to-peer network for configuration data stored against hardcoded public keys.

“The combination of blockchain, peer-to-peer, and legitimate web services as resolution layers was designed to be resilient against takedowns — a dynamic front protecting the actual C2 servers behind multiple layers of indirection,” CrowdStrike noted in a report published on May 26.

This is why the threat hunters had to disrupt all channels simultaneously.

“Taking down only one channel would have left the others operational, allowing the operators to quickly reconstitute,” CrowdStrike added.

Glassworm Tied to Poisonous VS Code Extensions, Npm and Python Packages

A household name in open-source software supply chain attacks, Glassworm has been a network of devices controlled by malicious operators since at least early 2025.

It had been used in several multi-pronged malicious campaigns targeting software developers by poisoning open-source packages they rely upon across Windows, macOS and Linux systems.

Some of the activities linked to Glassworm included trojanized extensions of Microsoft Visual Studio Code (VS Code), published to the OpenVSX marketplace, compromised npm and Python packages introducing malicious code through postinstall hooks and setup scripts and

More than 300 GitHub repositories were poisoned using stolen developer credentials harvested from earlier Glassworm infections, CrowdStrike added.

The company highlighted that Glassworm “marked a significant shift in the threat landscape” that should “serve as a wake-up call for every organization that ships or consumes software.”

“Adversaries are no longer just targeting products, they’re targeting the developers who build them. The barrier to poisoning a package or extension is low; the potential blast radius is enormous. As long as developer environments, build pipelines, and code repositories remain under-protected, every organization that consumes software inherits the risk of everyone who produces it,” CrowdStrike threat hunters warned.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleHow OAuth Consent Bypasses MFA
Next Article DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability
Team-CWD
  • Website

Related Posts

News

Why Burnout in Cybersecurity Demands Risk-Based Response

May 27, 2026
News

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

May 27, 2026
News

How OAuth Consent Bypasses MFA

May 27, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Chronology of a Skype attack

February 5, 2026

How to help older family members avoid scams

October 31, 2025

2025’s most common passwords were as predictable as ever

January 21, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.