Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GlassWorm Botnet Dismantled by Cybersecurity Experts

GlassWorm Botnet Dismantled by Cybersecurity Experts

Posted on May 27, 2026 By CWS

The GlassWorm botnet, a significant threat to the open source software ecosystem for over six months, has been effectively dismantled. Cybersecurity firm CrowdStrike, in collaboration with Google and the Shadowserver Foundation, successfully disrupted the botnet’s operations, limiting its impact on infected systems.

Coordinated Effort to Disrupt GlassWorm

The joint operation involved simultaneously taking down all four of GlassWorm’s command-and-control (C&C) channels. This strategic move prevented the botnet operators from accessing compromised machines and deploying new malicious payloads. The GlassWorm had been using sophisticated methods to maintain its C&C infrastructure, including the Solana blockchain and other platforms like Google Calendar and BitTorrent.

By employing the Solana blockchain, the operators encoded C&C addresses in immutable memo fields of transactions. This made it challenging to alter or remove these addresses. The BitTorrent network was utilized to host configuration data, while Google Calendar stored encoded C&C paths within event titles. Additionally, traditional servers on commercial VPS providers hosted payloads, creating a multi-layered defense against takedown attempts.

Technical Sophistication and Resilience

GlassWorm’s operators demonstrated technical prowess and adaptability. Since its discovery in October 2025, the botnet has employed Unicode variation selectors to obfuscate its code, making detection difficult. Initially spread via modified Visual Studio extensions on the OpenVSX marketplace, the malware later appeared on GitHub and targeted various open source platforms, including Python projects.

The operators behind GlassWorm are described as resourceful and persistent, continuously evolving their tactics. They adopted new programming languages and expanded their reach across multiple package ecosystems to ensure resilience against takedown efforts. This adaptability underscores the ongoing threat posed by such well-organized cybercrime operations.

Impact and Implications of the Takedown

Beyond its immediate disruption, the takedown of GlassWorm signifies a critical shift in the cybersecurity landscape. The botnet was designed to extract sensitive information, such as credentials and cryptocurrency funds, posing a significant risk to supply chains and end-users. CrowdStrike’s efforts to redirect infected machines to a benign IP address aim to aid organizations in identifying potential threats.

Evidence suggests that GlassWorm’s operators are likely of Russian origin, as the malware avoids systems in CIS countries and contains Russian-language comments. This operation serves as a crucial reminder to all organizations that the threat to developers and their environments is growing. Protecting developer ecosystems is now a vital component of cybersecurity strategy.

CrowdStrike emphasizes the need for enhanced protection of developer environments to mitigate risks. The GlassWorm incident illustrates that attackers are investing in robust infrastructure to maintain access to vulnerable developer ecosystems. This development highlights the necessity for organizations to adopt stronger security measures across all stages of software production and consumption.

Security Week News Tags:Botnet, CrowdStrike, Cybersecurity, GlassWorm, Google, Malware, Open Source, Shadowserver Foundation, Software Security, Solana blockchain

Post navigation

Previous Post: Enhancing SOC Risk Visibility for CISOs

Related Posts

Telecom Giant Orange Hit by Cyberattack Telecom Giant Orange Hit by Cyberattack Security Week News
Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Cyber Insights 2026: Threat Hunting in an Age of Automation and AI Security Week News
AI Agents Exploit Supply Chains in New Cyber Attacks AI Agents Exploit Supply Chains in New Cyber Attacks Security Week News
Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments Security Week News
Recent Langflow Vulnerability Exploited by Flodrix Botnet Recent Langflow Vulnerability Exploited by Flodrix Botnet Security Week News
Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Firm Andy Frain Says 100,000 People Impacted by Ransomware Attack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GlassWorm Botnet Dismantled by Cybersecurity Experts
  • Enhancing SOC Risk Visibility for CISOs
  • AI’s Growing Threat: UK’s Cyber Chief Warns of Russia
  • Malicious npm Package Targets Claude AI User Data
  • Critical ‘BadHost’ Flaw Threatens AI Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GlassWorm Botnet Dismantled by Cybersecurity Experts
  • Enhancing SOC Risk Visibility for CISOs
  • AI’s Growing Threat: UK’s Cyber Chief Warns of Russia
  • Malicious npm Package Targets Claude AI User Data
  • Critical ‘BadHost’ Flaw Threatens AI Server Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark