Skip to content

Instantly share code, notes, and snippets.

View cerberim's full-sized avatar
💭
Watching the gates

cerberim

💭
Watching the gates
View GitHub Profile

CERBERUS-2026-001: skhqwensw SSH Worm/Cryptominer Botnet

Report ID: CERBERUS-2026-001

Classification: PUBLIC

Last Observed: 2026-01

Author: Cerberim Threat Intelligence

@cerberim
cerberim / CERBERUS-REPORT-profitable-negligence-2025.md
Created December 31, 2025 12:47
When your account gets hacked, the attack probably came from a Fortune 500 data center. A report on why cloud providers don't stop attacks they could easily detect.

The Gates Are Open On Purpose

A Report on Profitable Negligence in Cloud Infrastructure

Cerberus Security | <redacted> | December 31, 2025


TL;DR: Microsoft, Google, Amazon, and DigitalOcean rent servers to criminals who attack you. They could detect it easily. They could stop it. They choose not to. The gates are open on purpose.

@cerberim
cerberim / BadMDFK-Perl-IRC-DDoS-Botnet-Threat-Intelligence.md
Created December 20, 2025 16:00
Threat Intelligence: BadMDFK/flood.ro Perl IRC DDoS Botnet - IOCs, YARA rule, detection & remediation. C2: 86.122.140.30, printfly.go.ro

BadMDFK IRC DDoS Botnet - Threat Intelligence Report

Report ID: CERBERUS-2025-001

Classification: PUBLIC RELEASE

Author: Cerberim