< Back to all clusters
[TECHNOLOGY] · Germany, Italy · 2 sources

Glassworm botnet taken offline after coordinated takedown

On 26 May 2026 the Counter Adversary Operations team of CrowdStrike disabled the Glassworm botnet, cutting all four of its command‑and‑control (C2) channels in a coordinated action involving Google and The Shadowserver Foundation. The C2 infrastructure included a Solana blockchain address ledger, a BitTorrent distributed‑hash‑table, Google Calendar entries used as covert messaging, and traditional VPS servers.

Glassworm had uniquely targeted software developers, compromising supply‑chain components such as npm and Python packages, VS Code/OpenVSX extensions, and over 300 GitHub repositories. Infected workstations could harvest credentials, steal cryptocurrency, and install a remote‑access trojan, potentially affecting thousands of downstream organisations. The takedown leaves the botnet without communication pathways, and infected machines are now isolated.

Affected parties are advised to scrutinise network logs for lingering indicators of compromise and consider full system re‑imaging where necessary.

Sources

2 months ago