Back to Intel

Intel Node

PowMix botnet targets Czech workforce

lowtradecraft2026-04-16T10:00:33+00:00source excerpt
malwaretradecraftwindowscloud

Source excerpt · The upstream feed supplied only part of this article.Read the original source →

Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call

Cisco Talos discovered an ongoing malicious campaign, operating since at least December 2025, affecting a broader workforce in the Czech Republic with a previously undocumented botnet we call “PowMix. ”  PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections.

  PowMix embeds the encrypted heartbeat data along with unique identifiers of the victim machine into the C2 URL paths, mimicking legitimate REST API URLs.   PowMix has the capability to remotely update the new C2 domain to the botnet configuration file dynamically.

Read Original Source