Tag: PowMix Botnet

Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic
News

Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic

Since at least December 2025, cybersecurity researchers have issued a warning about a malicious campaign that is actively targeting the Czech Republic's workforce using an undiscovered botnet known as PowMix. In a paper released today, Cisco Talos researcher Chetan Raghuprasad stated that PowMix uses randomized command-and-control (C2) beaconing intervals instead of a constant connection to the C2 server to avoid the network signature detections. PowMix mimics authentic REST API URLs by including the encrypted heartbeat data and the victim machine's unique identifiers into the C2 URL pathways. PowMix can dynamically update the botnet configuration file with the new C2 domain remotely. To start a multi-stage infection chain that releases PowMix, the attack chain starts with a mali...