'Adversaries are no longer just targeting products, they're targeting the developers who build them': CrowdStrike takes down major botnet targeting developers across the world
- CrowdStrike, Google, and Shadowserver jointly dismantled the Glassworm botnet on May 26, 2026, by disrupting all four of its resilient C2 channels simultaneously
- Active since early 2025, Glassworm spread via trojanized VSCode extensions, poisoned npm/Python packages, and compromised GitHub repos, stealing developer credentials and deploying GlasswormRAT across Windows, macOS, and Linux
- The takedown highlights a shift in threat focus from products to developers, with coordinated precision required to neutralize its blockchain, BitTorrent DHT, Google Calendar, and VPS‑based infrastructure
Cybersecurity researchers from CrowdStrike, Google, and the Shadowsever Foundation have teamed up to take down a major botnet targeting software developers all over the world.
In an announcement, the company said on May 26, 2026, the taskforce shut down the Glassworm botnet by simultaneously disrupting all four of its C2 channels.
Glassworm is a global botnet, active since at least early 2025, and operated by well-sourced, persistent criminals likely based...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE