CrowdStrike, Google, and Shadowserver dismantle Glassworm botnet targeting open-source developers
By
Lorenzo Franceschi-Bicchierai
Hand-rolled, kettle-boiled, baked to perfection. Worth every minute at the bakery.
Summary
CrowdStrike, in collaboration with Google and Shadowserver, has taken down the Glassworm botnet, which cybercriminals used for two years to push malware and steal passwords from open-source software developers. The operation aimed to disrupt supply chain attacks targeting the broader open source software ecosystem.
Key quotes
· 3 pulledThe takedown operation had the goal of disrupting the activities of the cybercriminals behind the so-called Glassworm botnet, who have been targeting the broader open source software supply chain for two years, according to CrowdStrike.
CrowdStrike, working with Google and Shadowserver, a nonprofit organization that scans and monitors the internet for cyberattacks, took down a botnet that cybercriminals used to push malware and steal passwords from open-source software developers.
In recent months, several hacking groups have targeted developers and open source projects to push malware
You might also wanna read
Glassworm Threat Actor Returns with Unicode-Based Supply Chain Attacks on GitHub, npm, and VS Code
The Glassworm threat actor has returned with a new wave of supply chain attacks using invisible Unicode characters to compromise software re
aikido.dev·2mo agoGlassWorm: First Self-Propagating Worm Targets VS Code Extensions with Invisible Code
Researchers have discovered GlassWorm, the world's first self-propagating worm targeting VS Code extensions on the OpenVSX marketplace. This
Major Tech Companies Launch Project Glasswing to Secure Critical Software Against AI Cybersecurity Threats
Project Glasswing is a new cybersecurity initiative announced by Amazon Web Services, Anthropic, Apple, Broadcom, Cisco, CrowdStrike, Google
Project Glasswing: AI-assisted vulnerability detection finds over 10,000 critical software flaws
Project Glasswing is a collaborative effort launched to secure critical software against potential threats from increasingly capable AI mode
ClawdBot Open-Source Malware Framework Targets Cryptocurrency Platforms and Social Media
The article discusses ClawdBot, an open-source malware framework that uses malicious skills to target cryptocurrency platforms and social me
opensourcemalware.com·4mo agoKlarrio Uncovers Large-Scale Malware Network on GitHub
Klarrio discovered a large-scale malware network on GitHub through the research of their CTO, Bruno De Bus, exposing attempts to install mal
