Advisory ID: NCC-CSIRT-2026-015
Summary:
The NCC-CSIRT has observed the following cyber threats in the communications sector: increased activities involving malware strains such as Andromeda, BruteForceBot, Win.AsyncRAT, Gamut, and StealRat are being leveraged to orchestrate Distributed Denial-of-Service (DDoS) attacks. These malware families are used to compromise systems and form botnets capable of launching large-scale volumetric and application-layer attacks.
Damage: High
Probability: High
Product(s):
- Network Infrastructure
- Endpoints
- Servers
- Customer Premises Equipment (CPE)
Version(s):
All versions
Platform(s):
- Windows
- Linux
- Network Devices
- IoT Devices
Description:
Recent threat intelligence indicates the use of the following malware:
Andromeda: Modular botnet malware used for system compromise and DDoS operations.
BruteForceBot: Used for credential brute-force attacks and botnet recruitment.
Win.AsyncRAT: Remote access trojan enabling remote control and DDoS deployment.
Gamut: Known for spam and botnet activity, also leveraged for DDoS campaigns.
StealRat: Supports credential theft and remote control, aiding botnet expansion.
These malware strains enable attackers to build distributed botnets used to generate high volumes of malicious traffic, resulting in denial-of-service conditions.
Impacts:
- Service disruption and degradation of telecommunications services
- Network congestion and bandwidth exhaustion
- Loss of availability of critical systems and services
- Compromise of infected systems leading to further propagation
- Reputational damage and potential regulatory implications
Threat Types:
- Botnet Malware
- DDoS (Volumetric and Application Layer)
- Remote Access Trojan (RAT),
- Credential Attacks
Solutions/Mitigations:
NCC-CSIRT recommends the following mitigation steps:
- Deploy DDoS mitigation solutions (traffic filtering, rate limiting).
- Monitor network traffic for anomalies.
- Patch and update systems regularly.
- Implement endpoint protection (EDR/AV).
- Enforce strong authentication (MFA, password policies).
- Block command-and-control (C&C) communications.
- Leverage threat intelligence and share IOCs.
- Develop and test incident response plans.
References: