{"id":43439,"date":"2021-10-15T15:01:31","date_gmt":"2021-10-15T15:01:31","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32727\/Spamhaus-Botnet-Threat-Update-Q3-2021.html"},"modified":"2021-10-15T15:01:31","modified_gmt":"2021-10-15T15:01:31","slug":"spamhaus-botnet-threat-update-q3-2021","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/","title":{"rendered":"Spamhaus Botnet Threat Update: Q3-2021"},"content":{"rendered":"<p><!-- Intro -------------------------------------------------------- --><\/p>\n<p><strong>Q3 has seen a massive 82% rise in the number of new botnet command and controllers (C&amp;Cs) identified by our research team. They have observed an explosion in the use of backdoor malware with nefarious operators hiding behind FastFlux. In turn, this has caused several new countries and service providers to be listed in our Top 20 charts. Welcome to the Spamhaus Botnet Threat Update Q3 2021.<\/strong><\/p>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>FastFlux emerging again<\/h2>\n<div class=\"insetbox\" readability=\"12\">\n<h3>What is FastFlux?<\/h3>\n<p>FastFlux is a technique used by phishers, malware authors, and botnet operators to hide the actual location of their infrastructure behind a network of compromised hosts that are acting as a proxy, forwarding the malicious traffic to the real backend.<\/p>\n<\/p><\/div>\n<p>After analyzing this quarter\u2019s statistics, it is evident that FastFlux is once again rising in popularity. Here\u2019s a quick FastFlux refresher, including a deeper dive into how cybercriminals use it to make their infrastructure resilient against takedowns. <\/p>\n<h3>What makes FastFl to cybercriminals?<\/h3>\n<p>All FastFlux networks that are currently in business can be rented as a service on the dark web. This makes life easy for botnet operators. All they have to do is register domains required for the botnet C&amp;Cs and point them to the FastFlux operator\u2019s service. FastFlux takes care of the rest, ensuring that the A records rapidly change.<\/p>\n<p>Here\u2019s an example of a FluBot botnet C&amp;C domain hosted on a FastFlux botnet:\n<\/p>\n<pre>\n;; QUESTION SECTION:\n;gurbngbcxheshsj.ru. IN A ;; ANSWER SECTION:\nDomain TTL RecordType IP Address\ngurbngbcxheshsj.ru. 150 IN A 189.165.94.67\ngurbngbcxheshsj.ru. 150 IN A 124.109.61.160\ngurbngbcxheshsj.ru. 150 IN A 187.190.48.60\ngurbngbcxheshsj.ru. 150 IN A 115.91.217.231\ngurbngbcxheshsj.ru. 150 IN A 175.126.109.15\ngurbngbcxheshsj.ru. 150 IN A 175.119.10.231\ngurbngbcxheshsj.ru. 150 IN A 218.38.155.210\ngurbngbcxheshsj.ru. 150 IN A 179.52.22.168\ngurbngbcxheshsj.ru. 150 IN A 113.11.118.155\ngurbngbcxheshsj.ru. 150 IN A 14.51.96.70\n<\/pre>\n<p>As you can see, the botnet C&amp;C domain uses ten concurrent A records with a time to live (TTL) of only 150 seconds. Monitoring these A records reveals that the underlying FastFlux botnet consists of 100 to 150 active FastFlux nodes per day.<\/p>\n<p>Generally, these nodes are compromised devices, commonly Customer Premise Equipment (CPE), insecurely configured (e.g., running vulnerable software or using standard login credentials), and accessible directly from the internet.<\/p>\n<p>These kinds of devices are a soft target for cybercriminals. They simply need to conduct internet-wide scans to discover these vulnerable devices and compromise them. This whole process can all be automated, making it quick, easy, and effective.<\/p>\n<p> Operators of FastFlux botnets choose the geolocation of their target devices they use for FastFlux hosting carefully. As you will notice when reading through this report, many FastFlux C&amp;C nodes are hosted in places that are relatively well \u201cdigitized,\u201d i.e., have good internet connections but are not as advanced along the maturity curve in terms of cybersecurity. <\/p>\n<p>Latin America is commonly a target, e.g., Brazil, Chile, Argentina, Uruguay, and Asian countries such as Korea. The newcomers to the geolocation statistics in this update reflect this.<\/p>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Number of botnet C&amp;Cs observed, Q3 2021<\/h2>\n<p>In Q3 2021, Spamhaus Malware Labs identified 2,656 botnet C&amp;Cs compared to 1,462 in Q2 2021. This was an 82% increase quarter on quarter! The monthly average increased from 487 per month in Q2 to 885 botnet C&amp;Cs per month in Q3.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-01-number-of-new-botnet-c2s.png\" alt><\/td>\n<\/tr>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-02-quarterly-number-table.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Geolocation of botnet C&amp;Cs, Q3 2021<\/h2>\n<p>Given FastFlux\u2019s influence over the past quarter, it isn\u2019t surprising that there\u2019s a clear pattern to the newcomers entering the chart for Q3 2021. Many of the countries joining the charts were responsible for hosting a large percentage of TeamBot, and FluBot botnet C&amp;C servers &#8211; utilizing Fastflux &#8211; and fit the profile of countries with extensive internet coverage but less security-focused.<\/p>\n<h3>Significant increases in Russia<\/h3>\n<p>The number of botnet C&amp;Cs located in Russia has dramatically risen. This is the second increase quarter on quarter that Russia has experienced:\n<\/p>\n<ul>\n<li>Q1 to Q2 \u2013 19% increase<\/li>\n<li>Q2 to Q3 \u2013 64% increase<\/li>\n<\/ul>\n<p>Therefore, it comes as no surprise that in Q3 Russia overtook the United States for the #1 spot. <\/p>\n<h3>Continued increases across Europe<\/h3>\n<p>The trend that started in Q2 continued in Q3. Once again, there was an uptick in the number of botnet C&amp;C servers hosted in various European countries, including the Netherlands (+63%), Germany (+45%), France (+34%), and Switzerland (+34%).<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-03-c2s-geolocation-table.png\" alt><\/td>\n<\/tr>\n<\/table>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-04-c2s-geolocation-map.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Malware associated with botnet C&amp;Cs, Q3 2021<\/h2>\n<p>Here are the top malware families associated with newly observed botnet C&amp;Cs in Q3, 2021.<\/p>\n<h3>TeamBot and FluBot emerging<\/h3>\n<p>Have you ever heard of TeamBot? Probably not. While it is neither a new nor severe threat, TeamBot sits at the top of the charts with FluBot, both backdoors.<\/p>\n<p>Our threat hunters believe that TeamBot and FluBot are using the same FastFlux infrastructure, rotating the same botnet C&amp;C IP addresses every few minutes, hence the shared listing below.<\/p>\n<p>This quarter, there was an explosion in backdoor malware, making it the most prevalent type of malware associated with botnet C&amp;Cs in Q3 2021.<\/p>\n<h3>RedLine wins, Raccoon loses<\/h3>\n<p>In 2021, we\u2019ve been observing a battle for pole position between RedLine and Raccoon, both credential stealers, available for sale on the dark web. While we saw a huge increase (571%) of Raccoon botnet C&amp;C servers in Q2 2021, RedLine malware experienced a 71% increase in Q3 2021, displacing Raccoon from its top spot.<\/p>\n<h3>IcedID disappears<\/h3>\n<p>IcedID has been relatively inactivate this year, making a brief appearance at #18 in Q2 before disappearing again this quarter. The reason behind this is unknown. However, our researchers don\u2019t believe its silence will continue indefinitely. IcedID is one of the Trojans available to ransomware groups for purchase on the dark web.<br \/>These Trojans sell access to corporate networks &#8211; a very lucrative business.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-05-malware-table.png\" alt><\/td>\n<\/tr>\n<\/table>\n<table readability=\"1\">\n<tr readability=\"2\">\n<td>\n<h3>Malware type comparisons between Q2 and Q3 2021<\/h3>\n<p> <img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-06-malware-type.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Most abused top-level domains, Q3 2021<\/h2>\n<h3>No changes at the top of the chart<\/h3>\n<p>In Q3, .com and .xyz continued to stay at the top of our ranking. The situation deteriorated for these two TLDs, particularly .com, which experienced a 90% increase. We hope that VeriSign, the owner of this TLD, will take all necessary steps to improve this situation and increase their TLD\u2019s reputation.<\/p>\n<h3>Three new TLDs<\/h3>\n<p>Two new gTLDs and one ccTLD joined our Top 20: .club, .co and .monster. All have seen a significant increase in the number of new botnet C&amp;C domains registered through their service.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-07-tlds.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Most abused domain registrars, Q3 2021<\/h2>\n<p>We observed significant increases across most of the domain registrars listed in our Top 20. The United States is home to the largest percentage of domain registrars; however, their share has dropped quarter on quarter, while China, the United Kingdom, and Russia have increased.<\/p>\n<h3>In Q2 you saw Arsys, now you don\u2019t<\/h3>\n<p>A nod of approval to Arsys, who was a new entry at #5 in Q2. They appear to have taken positive steps to ensure their TLD remains as clean as possible and dropped off the Top 20 in Q3, along with HiChina, 1API, Name.com, and 55hl.com. Excellent work to all these registrars.<\/p>\n<h3>Reseller issues<\/h3>\n<p>In Q3, we saw the biggest increases in newly registered botnet C&amp;C domains at CentralNic (+488%), Tucows (+266%), RegRU (+252%), West263.com (+168%), and Network Solutions (+163%).<\/p>\n<p>The vast majority of fraudulent domain name registrations originate from poor resellers who have inappropriate or non-existent customer vetting in place.<\/p>\n<p>Registrars can struggle to penalize these dirty resellers for many reasons, including poorly written Terms of Services (ToS). However, other matters can also<br \/>\ncome into play, such as a vested financial interest or a fundamental lack of motivation to take responsibility for these issues.<\/p>\n<p>We hope that these registrars will improve their reputation quickly by implementing stricter measures on their resellers to ensure they strive to fight against the registration of fraudulent domain names.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-08-registrars.png\" alt><\/td>\n<\/tr>\n<\/table>\n<table readability=\"1\">\n<tr readability=\"2\">\n<td>\n<h3>Location of Most Abused Domain Registrars<\/h3>\n<p> <img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-09-registrars-location.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Networks hosting the most newly observed botnet C&amp;Cs, Q2 2021<\/h2>\n<p>As usual, there were many changes in the networks hosting newly observed botnet C&amp;Cs. Notably, there was an influx of networks hosting FastFlux botnet C&amp;Cs, used by cybercriminals to host backdoor malware.<\/p>\n<h3>Does this list reflect ho dealt with at networks?<\/h3>\n<p>While this Top 20 listing illustrates that there may be an issue with customer vetting processes, it doesn\u2019t reflect on the speed abuse desks deal with reported issues. See \u201cNetworks hosting the most active botnet C&amp;Cs\u201d to view networks where abuse isn\u2019t dealt with in a timely manner.<\/p>\n<h3>serverion.com<\/h3>\n<p>We have seen a 69% increase in the number of new botnet C&amp;C servers installed at the Dutch hosting provider serverion.com. Our researchers believe that this increase is predominantly due to their downstream customer des.capital, which tends to attract botnet operators.<\/p>\n<h3>Making positive changes<\/h3>\n<p>In last quarter\u2019s update, we reported that a botnet hosting operation had moved from Amazon to DigitalOcean, causing the latter\u2019s listings to rocket. We want to congratulate DigitalOcean for dropping off our Top 20 list in Q3 2021, along with other networks, including Google, who were at #2, HostSailor, Microsoft, M247, and Off Shore Racks.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-10-network-newly-observed.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Networks hosting the most active botnet C&amp;Cs, Q3 2021<\/h2>\n<p>Finally, let\u2019s take a look at the networks that hosted a large number of active botnet C&amp;Cs in Q3 2021. Hosting providers who appear in this ranking either have an abuse problem or do not take the appropriate action when receiving abuse reports.<\/p>\n<h3>An increase in botnet C&amp;C abuse<\/h3>\n<p>Sadly, the situation in terms of active botnet C&amp;C servers deteriorated for many ISPs who were on our Top 20 in Q2. Ipjetable.net (FR), microsoft.com (US), vietserver.vn (VN), and openvpn (SE) all have one thing in common: Instead of taking appropriate measures against the abuse on their infrastructure, the number of active botnet C&amp;C servers increased in these networks.<\/p>\n<h3>uninet.net.mx &amp; stc.com.sa<\/h3>\n<p>These two ISPs are new to our Top 20 this quarter and have taken #1 and #2 spots due to the vast number of FastFlux bots hosted on their networks.<\/p>\n<p>In fact, the majority of the newcomers to this chart are due to hosting FastFlux bots on their networks and not responding quickly to abuse reports. All these companies are providing a resilient botnet C&amp;C infrastructure for botnet operators.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/2021-q3-11-network-most-active-botnets.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p>That\u2019s all for now. Stay safe and see you in January!<\/p>\n<p><a href=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q3\/spamhaus-botnet-report-2021-q3.pdf\">Download the Spamhaus Botnet Report 2021 Q3 as PDF<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32727\/Spamhaus-Botnet-Threat-Update-Q3-2021.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":43440,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[60],"tags":[4453],"class_list":["post-43439","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-packet-storm","tag-headlinespambotnet"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Spamhaus Botnet Threat Update: Q3-2021 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Spamhaus Botnet Threat Update: Q3-2021 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-15T15:01:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/spamhaus-botnet-threat-update-q3-2021.png\" \/>\n\t<meta property=\"og:image:width\" content=\"639\" \/>\n\t<meta property=\"og:image:height\" content=\"554\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Spamhaus Botnet Threat Update: Q3-2021\",\"datePublished\":\"2021-10-15T15:01:31+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/\"},\"wordCount\":1667,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/spamhaus-botnet-threat-update-q3-2021.png\",\"keywords\":[\"headline,spam,botnet\"],\"articleSection\":[\"Packet Storm\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/\",\"name\":\"Spamhaus Botnet Threat Update: Q3-2021 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/spamhaus-botnet-threat-update-q3-2021.png\",\"datePublished\":\"2021-10-15T15:01:31+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/spamhaus-botnet-threat-update-q3-2021.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/spamhaus-botnet-threat-update-q3-2021.png\",\"width\":639,\"height\":554},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q3-2021\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,spam,botnet\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinespambotnet\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Spamhaus Botnet Threat Update: Q3-2021\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Spamhaus Botnet Threat Update: Q3-2021 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/","og_locale":"en_US","og_type":"article","og_title":"Spamhaus Botnet Threat Update: Q3-2021 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-10-15T15:01:31+00:00","og_image":[{"width":639,"height":554,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/spamhaus-botnet-threat-update-q3-2021.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Spamhaus Botnet Threat Update: Q3-2021","datePublished":"2021-10-15T15:01:31+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/"},"wordCount":1667,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/spamhaus-botnet-threat-update-q3-2021.png","keywords":["headline,spam,botnet"],"articleSection":["Packet Storm"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/","url":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/","name":"Spamhaus Botnet Threat Update: Q3-2021 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/spamhaus-botnet-threat-update-q3-2021.png","datePublished":"2021-10-15T15:01:31+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/spamhaus-botnet-threat-update-q3-2021.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/10\/spamhaus-botnet-threat-update-q3-2021.png","width":639,"height":554},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q3-2021\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,spam,botnet","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinespambotnet\/"},{"@type":"ListItem","position":3,"name":"Spamhaus Botnet Threat Update: Q3-2021"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43439","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=43439"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/43439\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/43440"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=43439"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=43439"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=43439"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}