{"id":44919,"date":"2022-01-21T15:20:59","date_gmt":"2022-01-21T15:20:59","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/33026\/Spamhaus-Botnet-Threat-Update-Q4-2021.html"},"modified":"2022-01-21T15:20:59","modified_gmt":"2022-01-21T15:20:59","slug":"spamhaus-botnet-threat-update-q4-2021","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/","title":{"rendered":"Spamhaus Botnet Threat Update: Q4-2021"},"content":{"rendered":"<p><!-- Intro -------------------------------------------------------- --><\/p>\n<p><strong>Q4 saw a 23% rise in the number of new botnet command and controllers (C&amp;Cs) identified by our research team. Despite this increase, our researchers are aware of botnet C&amp;C activity they cannot track due to communications being made via DNS over HTTPS (DoH). This is worrying and certainly tilts the scales in the cybercriminals\u2019 favor.<\/strong><\/p>\n<p><strong>Welcome to the Spamhaus Botnet Threat Update Q4 2021.<\/strong><\/p>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>The issues of DNS over HTTPS (DoH)<\/h2>\n<h3>Remember FluBot &amp; TeamBot from Q3?<\/h3>\n<p>Last quarter, we reported \u201can explosion in backdoor malware\u201d due to FluBot &amp; TeamBot. In Q4, from the perspective of botnet C&amp;C infrastructure Spamhaus observed, this malware family completely disappeared. However, this doesn\u2019t mean they weren\u2019t active. That is far from the truth \u2013 they were active!<\/p>\n<h3>Why are they not being detected by Spamhaus?<\/h3>\n<p>This malware isn\u2019t appearing in our listings because those miscreants responsible for them have changed their operating procedures. Instead of making C&amp;C communications using traditional HTTPS protocol, they use DNS over HTTPS (DoH) and abuse large DoH providers, including Google and Alibaba.<\/p>\n<h3>Preventing abuse on the internet gets harder<\/h3>\n<p>While DoH was heralded with fanfares and touted as the next best security development of the internet, some security professionals (including Spamhaus) sighed as they realized the good guys would lose even more visibility over what the bad guys were doing. And by \u201ceven more,\u201d we refer to other issues like <a href=\"https:\/\/www.spamhaus.org\/news\/article\/775\/how-has-gdpr-affected-spam\">losing visibility of WHOIS data<\/a>.<\/p>\n<h3>Why is DoH an issue?<\/h3>\n<p>DoH encrypts DNS traffic, making a resource private and secure that previously has always been public (unencrypted). You may be thinking that this has<br \/>\nto be a good thing, however as you can see, in this circumstance, our researchers have no visibility of FluBot &amp; TeamBot\u2019s DNS requests. Consequently, we can\u2019t list the IP addresses, and therefore this data can\u2019t be used to protect users. While DoH is meant to be protecting the internet community, it is also enabling cybercriminals. It\u2019s a double-edged sword.<\/p>\n<p>Not only does DoH make hunting down miscreants even more challenging, but it also means that security products based around DNS monitoring and filtering could be less effective, which is far from ideal. Security issues are compounded due to major DoH providers not filtering harmful DNS resolutions of botnet, phishing or malware domains.<\/p>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Number of botnet C&amp;Cs observed, Q4 2021<\/h2>\n<p>In Q4 2021, Spamhaus identified 3,271 botnet C&amp;Cs compared to 2,656 in Q3 2021. This was a 23% increase quarter on quarter. The monthly average increased from 885 in Q3 to 1,090 botnet C&amp;Cs per month in Q4.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-01-total-number-of-botnet-c2s-observed.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Geolocation of botnet C&amp;Cs, Q3 2021<\/h2>\n<h3>Russia continues with significant increases<\/h3>\n<p>We reported last quarter that the number of botnet C&amp;Cs in Russia had increased dramatically. However, this quarter saw even bigger increases:\n<\/p>\n<ul>\n<li>Q1 to Q2 \u2013 19% increase<\/li>\n<li>Q2 to Q3 \u2013 64% increase<\/li>\n<li>Q3 to Q4 \u2013 124% increase<\/li>\n<\/ul>\n<p>In Q4, almost 30% of botnet C&amp;C servers were located in Russia. <\/p>\n<h3>LatAm presence continues<\/h3>\n<p>Several countries from Latin America (LatAm) were new entries in Q3 and remained in the Top 20 in Q4, including Mexico, Dominion Republic, Brazil, and Uruguay. Uruguay had the largest percentage increase (181%) of all geos in Q4.<\/p>\n<h3>Ups and downs across Europe<\/h3>\n<p>After continuing increases across various European countries, we\u2019re pleased to report that several have reduced numbers; the Netherlands, France, Sweden and Romania. Meanwhile, Switzerland has dropped off the Top 20 List completely. However, Germany has moved into third place with a 35% increase, and Great Britain has experienced a 56% increase.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-02-top-20-locations-of-c2s-table.png\" alt><\/td>\n<\/tr>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-03-top-20-locations-of-c2s-map.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Malware associated with botnet C&amp;Cs, Q4 2021<\/h2>\n<p>Credential stealers were the most prevalent malware type associated with Botnet C&amp;Cs in Q4. This doesn\u2019t come as a surprise, given that the top two malware listed, RedLine &amp; Loki, are both Credential Stealers.<\/p>\n<h3>GCleaner emerging<\/h3>\n<p>We saw a considerable uptick in GCleaner activity, leading to it being placed at #4, despite being a newcomer to the Top 20. GCleaner is similar to Smoke Loader in its modus operandi, and it is utilized in a Pay-Per-Install (PPI) model, dropping other malware on already infected hosts. While this malware threat has been around for some time, it is the first time that GCleaner has made it onto our Top 20 listings.<\/p>\n<h3>FluBot\/TeamBot disappear<\/h3>\n<p>As discussed in our Spotlight section, this malware that had the #1 spot last quarter has disappeared from our listings; however, it is still operational having switched across to using DoH.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-04-top-20-malware-table.png\" alt><\/td>\n<\/tr>\n<\/table>\n<table readability=\"1\">\n<tr readability=\"2\">\n<td>\n<h3>Malware type comparisons between Q3 and Q4 2021<\/h3>\n<p> <img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-05-top-20-malware-type.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Most abused top-level domains, Q4 2021<\/h2>\n<h3>A new entry at #4<\/h3>\n<p>We don\u2019t often see new TLD entries within the top five of this Botnet C&amp;C Top 20; however, .xxx, an adult TLD, run by registry ICM, has entered at #4. With less than 10,000 active domains but a total of 223 domains associated with botnet C&amp;C activity in Q4 we can only assume that there are problems.<\/p>\n<h3>.de reappears<\/h3>\n<p>The ccTLD de (Germany) re-entered our quarterly ranking at #20, having dropped off the Top 20 in Q2.<\/p>\n<h3>Reductions and departures<\/h3>\n<p>We\u2019d like to congratulate all the registries that manage TLDs who departed from our listings along with those who significantly reduced the number of associated botnet C&amp;Cs using their TLDs, including .buzz and .net, who both saw an 80% reduction.<\/p>\n<h3>Q3 data inaccuracy<\/h3>\n<p>Apologies to Verisign for an error in our Q3 2021 statistic for .com. We misreported the number of botnet C&amp;Cs for the TLD, and the correct figure was 3,730. Various issues led to this error, but we are pleased to confirm that we have worked with Verisign to rectify these.<\/p>\n<h3>Interpreting the data<\/h3>\n<p>Registries with a greater number of active domains have greater exposure to abuse. For example, in Q4 2021, .net had more than 13 million active domain zones, of which 0.00103% were associated with botnet C&amp;Cs. Meanwhile, .xxx had just over 9,000 active domains, of which 2.4% were associated with botnet C&amp;Cs. Both are in the top ten of our listings, but one had a much higher percentage of active domains associated with botnet C&amp;Cs than the other.<\/p>\n<h3>Working together with the industry for a safer internet<\/h3>\n<p>Naturally, our preference is for no TLDs to have botnet C&amp;Cs associated with them, but we live in the real world and understand there will always be abuse.<br \/>\nWhat is crucial is that abuse is dealt with quickly. Where necessary, if domain names are registered with the sole purpose of distributing malware or hosting botnet C&amp;Cs, we would like registries to suspend these domain names. We appreciate the efforts of many registries who work with us to ensure these actions are taken, including .xyz and .top.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-06-tlds.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Most abused domain registrars, Q4 2021<\/h2>\n<p>Overall, we saw a decrease in fraudulent domain registrations in Q4 2021, which is positive news. But some countries\u2019 registrars are still clearly struggling.<\/p>\n<h3>Canadian based registrars<\/h3>\n<p>Registrars in Canada had the most fraudulent botnet C&amp;C registrations in Q4, overtaking China from Q3.<\/p>\n<h3>German based registrars<\/h3>\n<p>There was a noticeable increase (136%) in the number of botnet C&amp;Cs associated with registrars operating out of Germany. This was due to Key Systems experiencing a 74% increase and 1API re-entering our charts at #12, having dropped off the Top 20 in Q2.<\/p>\n<h3>Atak<\/h3>\n<p>This domain registrar appeared for the first time in our rankings. Atak operates out of Turkey and hasn\u2019t responded to any of our abuse reports to date. We have therefore filed a complaint against Atak with ICANN\u2019s policy enforcement. It is imperative that everyone who is part of the internet ecosphere work together to protect internet users.<\/p>\n<h3>Nicenic.net (China) &amp; PDR (India)<\/h3>\n<p>These registrars experienced significant increases in the number of botnet C&amp;C domains registered through them in Q4. However, while registrations are increasing for PDR their response times to abuse reports are excellent.<\/p>\n<h3>Thank you to those who\u2019ve departed from our listings<\/h3>\n<p>Last quarter we highlighted that CentralNic, West263, and Network Solutions had all experienced considerable increases in the number of newly registered botnet C&amp;C domains. In Q4, all three of these registrars, along with eName, Xin Net, 22net, and OVH, departed from our Top 20 this quarter, so we\u2019d like to applaud all their efforts in preventing fraudulent registrations.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-07-registrars.png\" alt><\/td>\n<\/tr>\n<\/table>\n<table readability=\"1\">\n<tr readability=\"2\">\n<td>\n<h3>Location of Most Abused Domain Registrars<\/h3>\n<p> <img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-08-registrars-location.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Networks hosting the most newly observed botnet C&amp;Cs, Q4 2021<\/h2>\n<p>As usual, there were many changes in the networks hosting newly observed botnet C&amp;Cs.<\/p>\n<h3>Does this list reflect how quickly abuse is dealt with at networks?<\/h3>\n<p>While this Top 20 listing illustrates that there may be an issue with customer vetting processes, it doesn\u2019t reflect on the speed abuse desks deal with reported issues. See \u201cNetworks hosting the most active botnet C&amp;Cs\u201d<br \/>\nto view networks where abuse isn\u2019t dealt with promptly. <\/p>\n<h3>A mixed bag<\/h3>\n<p>Uninet.net.mx (#1), serverion.com (#5) and cloudflare.com (#9) \u2013 all three appear within the Top 10 of our listings, but there are big differences between them.<\/p>\n<p>Uninet is a telecom and network operator in Mexico. All newly hosted botnet C&amp;Cs we identified in their IP space resulted from compromised customer equipment.<\/p>\n<p>Serverion is a hosting company based in the Netherlands. All botnet C&amp;Cs we identified on their network in Q4 resulted from fraudulent sign-ups.<\/p>\n<p>Last but not least, we have Cloudflare who is not hosting any content rather providing a reverse proxy service and DDoS protection to botnet C&amp;Cs, hiding their actual location.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-09-networks-newly-observed.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p> <!-- Section --------------------------------------------------------- --> <\/p>\n<h2>Networks hosting the most active botnet C&amp;Cs, Q4 2021<\/h2>\n<p>Finally, let\u2019s review the networks that hosted the largest number of active botnet C&amp;Cs at the end of 2021. Hosting providers who appear in this ranking either have an abuse problem, do not take the appropriate action when receiving abuse reports, or omit to notify us when an abuse problem has been dealt with.<\/p>\n<h3>Network operators in LatAm region need to get on top of abuse rapidly<\/h3>\n<p>Over 60% of active botnet C&amp;C listings are on networks located in the LatAm region. We implore these operators to quickly respond to abuse reports and work with Spamhaus to reduce botnet C&amp;C abuse on their networks.<\/p>\n<table>\n<tr>\n<td><img decoding=\"async\" src=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-10-networks-most-active-botnets.png\" alt><\/td>\n<\/tr>\n<\/table>\n<p>That\u2019s all for now. Stay safe and see you in April!<\/p>\n<p><a href=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/spamhaus-botnet-report-2021-q4.pdf\">Download the Spamhaus Botnet Report 2021 Q4 as PDF<\/a><\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/33026\/Spamhaus-Botnet-Threat-Update-Q4-2021.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":44920,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[9829],"class_list":["post-44919","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerspambotnet"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Spamhaus Botnet Threat Update: Q4-2021 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Spamhaus Botnet Threat Update: Q4-2021 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2022-01-21T15:20:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-01-total-number-of-botnet-c2s-observed.png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Spamhaus Botnet Threat Update: Q4-2021\",\"datePublished\":\"2022-01-21T15:20:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/\"},\"wordCount\":1725,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/spamhaus-botnet-threat-update-q4-2021.png\",\"keywords\":[\"headline,hacker,spam,botnet\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/\",\"name\":\"Spamhaus Botnet Threat Update: Q4-2021 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/spamhaus-botnet-threat-update-q4-2021.png\",\"datePublished\":\"2022-01-21T15:20:59+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/spamhaus-botnet-threat-update-q4-2021.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2022\\\/01\\\/spamhaus-botnet-threat-update-q4-2021.png\",\"width\":736,\"height\":234},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/spamhaus-botnet-threat-update-q4-2021\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,spam,botnet\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerspambotnet\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Spamhaus Botnet Threat Update: Q4-2021\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Spamhaus Botnet Threat Update: Q4-2021 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/","og_locale":"en_US","og_type":"article","og_title":"Spamhaus Botnet Threat Update: Q4-2021 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2022-01-21T15:20:59+00:00","og_image":[{"url":"https:\/\/www.spamhaus.org\/news\/images\/botnet-report-2021-q4\/2021-q4-01-total-number-of-botnet-c2s-observed.png","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Spamhaus Botnet Threat Update: Q4-2021","datePublished":"2022-01-21T15:20:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/"},"wordCount":1725,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/01\/spamhaus-botnet-threat-update-q4-2021.png","keywords":["headline,hacker,spam,botnet"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/","url":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/","name":"Spamhaus Botnet Threat Update: Q4-2021 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/01\/spamhaus-botnet-threat-update-q4-2021.png","datePublished":"2022-01-21T15:20:59+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/01\/spamhaus-botnet-threat-update-q4-2021.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2022\/01\/spamhaus-botnet-threat-update-q4-2021.png","width":736,"height":234},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/spamhaus-botnet-threat-update-q4-2021\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,spam,botnet","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerspambotnet\/"},{"@type":"ListItem","position":3,"name":"Spamhaus Botnet Threat Update: Q4-2021"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44919","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=44919"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/44919\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/44920"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=44919"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=44919"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=44919"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}