Observed Signal · May 27, 2026 · Takedown · Source: techcrunch · Impact: 3/5 · Sentiment: Positive

CrowdStrike and Google dismantle Glassworm developer botnet

Executive Signal Summary

CrowdStrike, working with Google and nonprofit Shadowserver, disrupted a botnet known as Glassworm that targeted open-source software developers to push malware and steal credentials. The takedown removed four command-and-control channels — which relied on the Solana blockchain, the BitTorrent peer-to-peer network, Google Calendar, and virtual private servers — cutting attackers’ access to infected machines and preventing further malware delivery. CrowdStrike says Glassworm operators have been targeting the open-source software supply chain for about two years and managed to poison over 300 GitHub repositories. The operation highlights attackers’ use of diverse C2 mechanisms and developer-targeted tactics such as malicious marketplace extensions, malvertising, and account hijacking using previously stolen credentials.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Disruption of a multi-year developer-focused supply-chain botnet reduces risk of widespread downstream compromises and highlights novel abuse of blockchain and decentralised channels for command-and-control.

SIGNAL RADAR

Track Google Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • CrowdStrike, Google and Shadowserver collaborated to disrupt the Glassworm botnet.
  • The takedown operation disabled four command-and-control channels used by Glassworm.
  • Glassworm targeted the open-source software supply chain for approximately two years.
  • Command-and-control mechanisms included the Solana blockchain, BitTorrent, Google Calendar, and virtual private servers.
  • CrowdStrike reported the group poisoned more than 300 GitHub repositories.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: May 27, 2026
Original Coverage Title: “CrowdStrike and Google take down botnet used by hackers to target software developers in supply chain attacks”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Supply Chain AttackJun 8, 2026

Microsoft GitHub Repos Injected with Password-Stealing Malware

Microsoft disabled access to dozens of its open-source GitHub repositories after security researchers flagged malware injected into project code that steals passwords and credentials when developers open the compromised tools in AI coding apps. Affected projects include Azure-related tools and developer integrations for AI coding environments such as Claude Code, Google’s Gemini CLI and VS Code. Security firms Cloudsmith and OpenSourceMalware were among the first to report the incident. At least 70 Microsoft-owned repositories were marked disabled on GitHub. The incident appears related to a recent mid-May compromise of Microsoft’s Durable Task project and has been described by researchers as a potential re-compromise or follow-on breach.

Read assessment
Advertising Quality (Fraud & Bot Mitigation)Mar 20, 2026

Authorities Take Down Two Major DDoS Botnets

German and North American law-enforcement agencies disrupted the infrastructure of two of the world’s largest botnets — Aisuru and Kimwolf — which were used to launch large-scale distributed-denial-of-service (DDoS) attacks. The Bundeskriminalamt (BKA) and Nordrhein‑Westfalen’s ZAC, together with Canadian and U.S. authorities, disabled the globally distributed technical infrastructure but did not make arrests. Authorities identified two suspected administrators and seized extensive evidence during searches in Germany and Canada, including data drives and five-figure sums in cryptocurrency. Aisuru is linked to massive IoT-based attacks (including an attributed 31.4 Tbps DDoS mitigated by Cloudflare); Kimwolf is closely related and focused more on Android and consumer devices such as TV boxes. The primary targets of past DDoS incidents have included public services and apps, for example Germany’s Deutsche Bahn and its DB Navigator app.

Read assessment
CybersecurityJun 24, 2026

Microsoft and BKA Disable 200 Hacker Servers Worldwide

Microsoft, Europol and the German Bundeskriminalamt (BKA) carried out an international operation that disabled more than 200 command-and-control servers and severed criminal control over over 18,000 identified victim computers. The takedown targeted two widely used malware families, Amadey and StealC. Investigators used artificial intelligence to accelerate reverse-engineering of complex code and Microsoft's legal team invoked the U.S. RICO statute to treat multiple actors as a single conspiracy, enabling a coordinated, large-scale attack on the shared infrastructure. German authorities and Europol’s EC3 participated in the effort, which builds on previous international actions such as Operation Endgame from May 2024.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.