Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A new botnet called Void has emerged on the cybercrime underground... Void Botnet routes its commands through Ethereum smart contracts... First advertised in March 2026 on a Russian-language cybercrime forum, the botnet is sold as a ready-to-use loader priced at $600 with an additional $50 fee charged per build.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
Instead of relying on traditional servers that authorities can seize or shut down, Void Botnet routes its commands through Ethereum smart contracts... At the heart of Void Botnet is a dual-mode command-and-control system packed into a single binary. In decentralized mode, the operator writes instructions to an Ethereum smart contract, and infected machines check that contract at regular intervals... The second mode connects machines directly to the operator’s web panel.
The threats this botnet enables span a wide range, including DDoS campaigns, credential theft, and proxy-as-a-service operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Rust-based botnet using Ethereum smart contracts for decentralized resilience while retaining a centralized web panel for real-time tasking.
A Rust-based botnet/loader for Windows that uses a dual-mode command-and-control design, including decentralized C2 via Ethereum smart contracts and a direct web-panel mode. It supports payload delivery, in-memory execution, reverse shell, PowerShell tasking, persistence, self-update, self-delete, credential theft, DDoS activity, and proxy-as-a-service operations.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.