- Cybersecurity Docket
- Posts
- Feds Dismantle Four IoT Botnets Behind a Series of DDoS Attacks
Feds Dismantle Four IoT Botnets Behind a Series of DDoS Attacks
Plus, FBI seizes Handala data leak site responsible for Stryker cyber-attack.

SPONSORED BY

Good morning! Here’s what’s up.

People
Adam Snukal has joined Honigman LLP as a partner in the firm’s Israel office. Snukal, who joins Honigman from Greenberg Traurig, will advise companies on technology-related legal matters, including fintech and cybersecurity.

Clips ✂️
Feds Disrupt IoT Botnets Behind Huge DDoS Attacks
The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million Internet of Things (IoT) devices, such as routers and web cameras.
The feds say the four botnets — named Aisuru, Kimwolf, JackSkid and Mossad — are responsible for a series of recent record-smashing distributed denial-of-service (DDoS) attacks capable of knocking nearly any target offline.
The Justice Department said the Department of Defense Office of Inspector General’s (DoDIG) Defense Criminal Investigative Service (DCIS) executed seizure warrants targeting multiple U.S.-registered domains, virtual servers, and other infrastructure involved in DDoS attacks against Internet addresses owned by the DoD.
The government alleges the unnamed people in control of the four botnets used their crime machines to launch hundreds of thousands of DDoS attacks, often demanding extortion payments from victims. Some victims reported tens of thousands of dollars in losses and remediation expenses.
FBI seizes Handala data leak site after Stryker cyberattack
The FBI has seized two websites used by the Handala hacktivist group after the threat actors conducted a destructive cyberattack on medical technology giant Stryker that wiped approximately 80,000 devices.
Both the hacktivist's handala-redwanted[.]to and handala-hack[.]to clearnet domains now display a seizure notice stating that the websites were seized under a seizure warrant issued by the District Court for the District of Maryland.
"This domain has been seized by the Federal Bureau of Investigation ("FBI") pursuant to a seizure warrant issued by a United States District Court for the District of Maryland as a part of a law enforcement action by the FBI. Law enforcement authorities determined this domain was used to conduct, facilitate, or support malicious cyber activities on behalf of, or in coordination with, a foreign state actor," reads the seizure message.
Health plan information for over 2.6 million stolen from third-party admin Navia
Navia Benefit Solutions said millions of people had health plan information, Social Security numbers and other sensitive data stolen during a security incident that began in December.
The company is a third-party administrator for more than 10,000 companies, managing company healthcare benefits like Health Reimbursement Arrangements (HRAs) and Flexible Spending Accounts (FSAs) as well as commuter benefits and other employee spending accounts.
Navia confirmed the breach in a notice on its website and with regulators in Maine, where the company said 2,697,540 people were affected.
The breach notification letters say names, dates of birth, Social Security numbers, phone numbers, email addresses and detailed health plan information was stolen during the cyberattack, which was discovered on January 23.
Navia said the health plans impacted include HRAs, FSAs and Consolidated Omnibus Budget Reconciliation Act (COBRA) plans.
Hacker says they compromised millions of confidential police tips held by US company
A hacker says they have broken into a U.S. platform for searching law enforcement hotline messages and compromised more than 8 million confidential tips.
In a statement posted online, the hacker - who used the name "Internet Yiff Machine" - said they had broken into tip intelligence platform P3 Global Intel, an arm of safety company Navigate360, and stolen 93 gigabytes of data.
The FBI declined comment. Navigate360 said in a statement that it was trying to determine "whether we have experienced an incident involving our computer network and, if so, the extensiveness of the incident and the information involved." It said it had hired a third party to investigate and would not be commenting further.
On its website, Navigate360 described itself as the "leading provider of innovative tips and leads solutions" for law enforcement, federal agencies, the military, and school safety initiatives.
Water utilities need hands-on cybersecurity help, not just free guidance, pilot program finds
Free cybersecurity training can help water and wastewater utilities protect themselves against hackers, but only when paired with hands-on assistance and incentives for employees to build cybersecurity skills, Microsoft said in a report published on Thursday.
The report — a summary of a 2023-2025 cybersecurity assistance pilot program that Microsoft ran in partnership with the Cyber Readiness Institute (CRI) and the Foundation for Defense of Democracies’ Center on Cyber and Technology Innovation (CCTI) — contains several recommendations for how the federal government and water industry associations can support utility operators as they harden their defenses.
“Strengthening the cybersecurity of the nation’s water sector requires shifting from information distribution to capacity building — embedding hands-on assistance, aligning cybersecurity with existing operator requirements, and leveraging trusted sector associations to scale participation,” the report said.
Our Threat Intelligence team has observed an emerging obfuscation technique, specifically used to make Natural Language Processing (NLP) detection capabilities less effective. Broadly, malicious actors are adding additional characters, break lines, and legitimate links to the end of a phishing email in an attempt to disguise their malicious payloads amongst the noise and evade NLP detection.
For this threat alert, our team analyzed 40 emerging attacks identified by KnowBe4 Defend that used this technique to understand how it works, why attackers are employing it, and its potential for success.
Of the analyzed attacks, the most common legitimate part of an email appended to the attack was the Bank of America email signature, while ‘Uber.com’ and ‘Bofa.com’ were the most frequently used legitimate links.

SPONSORED BY

Incident Response Forum D.C. 2026 is set for Wednesday, April 22, 2026 at the historic Mayflower Hotel in Washington, D.C.!
Incident Response Forum is the only conference of its kind, bringing together hundreds of cybersecurity and incident response attorneys, in-house counsel and compliance executives, and other top professionals in the field. It is focused solely on the field of Incident Response – the work that begins after a data breach that has quickly become the fastest growing practice area at law firms and consulting firms – and is geared specifically for the legal and compliance professionals who have emerged as critical players during the aftermath of a data security incident.
Join us in person or tune in virtually to hear from nearly 50 luminaries in the incident response field—including senior officials from the DOJ and FBI, and lawyers and consultants from the best firms and in the world.
👉 UNTIL FRIDAY, MARCH 27: Please use the codes below to get a 25% early-bird discount (regular in-person registration fee is $1,500; regular virtual registration fee is $750). Please register here:
In-person attendance: UPDATE909DC25
Virtual attendance: UPDATE909V25
