Saturday July 11, 2026

Advisory ID: NCC-CSIRT-2026-015

Summary: 

The NCC-CSIRT has observed the following cyber threats in the communications sector: increased activities involving malware strains such as Andromeda, BruteForceBot, Win.AsyncRAT, Gamut, and StealRat are being leveraged to orchestrate Distributed Denial-of-Service (DDoS) attacks. These malware families are used to compromise systems and form botnets capable of launching large-scale volumetric and application-layer attacks.

Damage: High

Probability: High

Product(s): 

  • Network Infrastructure
  • Endpoints
  • Servers
  • Customer Premises Equipment (CPE)

Version(s): 

All versions

Platform(s): 

  • Windows
  • Linux
  • Network Devices
  • IoT Devices

Description: 

Recent threat intelligence indicates the use of the following malware:

Andromeda: Modular botnet malware used for system compromise and DDoS operations.

BruteForceBot: Used for credential brute-force attacks and botnet recruitment.

Win.AsyncRAT: Remote access trojan enabling remote control and DDoS deployment.

Gamut: Known for spam and botnet activity, also leveraged for DDoS campaigns.

StealRat: Supports credential theft and remote control, aiding botnet expansion.

These malware strains enable attackers to build distributed botnets used to generate high volumes of malicious traffic, resulting in denial-of-service conditions.

Impacts: 

  • Service disruption and degradation of telecommunications services
  • Network congestion and bandwidth exhaustion
  • Loss of availability of critical systems and services
  • Compromise of infected systems leading to further propagation
  • Reputational damage and potential regulatory implications

Threat Types: 

  • Botnet Malware
  • DDoS (Volumetric and Application Layer)
  • Remote Access Trojan (RAT),
  • Credential Attacks

Solutions/Mitigations:  

NCC-CSIRT recommends the following mitigation steps:

  • Deploy DDoS mitigation solutions (traffic filtering, rate limiting).
  • Monitor network traffic for anomalies.
  • Patch and update systems regularly.
  • Implement endpoint protection (EDR/AV).
  • Enforce strong authentication (MFA, password policies).
  • Block command-and-control (C&C) communications.
  • Leverage threat intelligence and share IOCs.
  • Develop and test incident response plans.

References: