{"id":233389,"date":"2026-04-16T13:52:00","date_gmt":"2026-04-16T17:52:00","guid":{"rendered":"https:\/\/news-you-need.com\/index.php\/2026\/04\/16\/newly-discovered-powmix-botnet-hits-czech-workers-using-randomized-c2-traffic\/"},"modified":"2026-04-20T12:10:10","modified_gmt":"2026-04-20T16:10:10","slug":"newly-discovered-powmix-botnet-hits-czech-workers-using-randomized-c2-traffic","status":"publish","type":"post","link":"https:\/\/news-you-need.com\/index.php\/2026\/04\/16\/newly-discovered-powmix-botnet-hits-czech-workers-using-randomized-c2-traffic\/","title":{"rendered":"Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic"},"content":{"rendered":"<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/newly-discovered-powmix-botnet-hits.html\">Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic<\/a><\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/newly-discovered-powmix-botnet-hits.html\">https:\/\/thehackernews.com\/2026\/04\/newly-discovered-powmix-botnet-hits.html<\/a><\/p>\n<p>Publish Date: <a href=\"publish_date]\">2026-04-16 13:52:00<\/a><\/p>\n<p>Source Domain: <a href=\"thehackernews.com\">thehackernews.com<\/a><\/p>\n<p><span class=\"p-author\">\ue804<span class=\"author\">Ravie Lakshmanan<\/span>\ue802<span class=\"author\">Apr 16, 2026<\/span><\/span><span class=\"p-tags\">Botnet \/ Cryptomining<\/span><\/p>\n<p>Cybersecurity researchers have warned of an active malicious campaign that&#8217;s targeting the workforce in the Czech Republic with a previously undocumented botnet\u00a0dubbed <strong>PowMix<\/strong> since at least December\u00a02025.<\/p>\n<p>&#8220;PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections,&#8221; Cisco Talos researcher Chetan Raghuprasad said in a report published\u00a0today.<\/p>\n<p>&#8220;PowMix embeds the encrypted heartbeat data along with unique identifiers of the victim machine into the C2 URL paths, mimicking legitimate REST API URLs.\u00a0PowMix has the capability\u00a0to remotely update the new C2 domain to the botnet configuration file dynamically.&#8221;<\/p>\n<p>The attack chain begins with a malicious ZIP file, likely delivered via a phishing email, to activate a multi-stage infection chain that drops PowMix. Specifically, it involves a Windows Shortcut (LNK) that&#8217;s used to launch a PowerShell loader, which then extracts the malware embedded within the archive, decrypts it, and runs it in\u00a0memory.<\/p>\n<p>The never-before-seen botnet is designed to facilitate remote access, reconnaissance, and remote code execution, while establishing persistence by means of a scheduled task. At\u00a0the same time, it verifies the process tree to ensure that another instance of the same malware is not running on the compromised\u00a0host.<\/p>\n<p>PowMix&#8217;s remote management logic allows it to process two different kinds of commands sent from the C2 server. Any\u00a0non #-prefixed response causes PowMix to shift to arbitrary execution mode, and decrypt and run the obtained\u00a0payload.\u00a0<\/p>\n<ul>\n<li>#KILL, to initiate a self-deletion routine and wipe traces of all malicious artifacts<\/li>\n<li>#HOST, to enable C2 migration to a new server URL.<\/li>\n<\/ul>\n<p>In parallel, it also opens a decoy document with compliance-themed lures as a distraction mechanism. The\u00a0lure documents reference legitimate brands like Edeka and include&#8230;<\/p>\n<p><a href=\"https:\/\/thehackernews.com\/2026\/04\/newly-discovered-powmix-botnet-hits.html\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Newly Discovered PowMix Botnet Hits Czech Workers Using Randomized C2 Traffic https:\/\/thehackernews.com\/2026\/04\/newly-discovered-powmix-botnet-hits.html Publish Date: 2026-04-16&#8230;<\/p>\n","protected":false},"author":1,"featured_media":233390,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjaSAtFbXFX7aYFcwPPrHEMwEZ4VJp2mJQuYo3B3Q2Zrot1co_ilMUWffYOUUFHFRO6zwHHjlMCMOJcbnc_iF69KLU_1LpMhcfFk5YV8A4cdIchhqR1NQGEvyzpHGidnbvqwq2Tg_Y77VwMCpeSSluD8sPRcusqiraqLMCvUCA-QvUv5nCuh2Ns1U2jxNR1\/s1600\/powmix.jpg","fifu_image_alt":"","footnotes":""},"categories":[15],"tags":[24,32,25],"class_list":["post-233389","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity","tag-malware","tag-phishing"],"_links":{"self":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/233389"}],"collection":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/comments?post=233389"}],"version-history":[{"count":1,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/233389\/revisions"}],"predecessor-version":[{"id":233391,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/posts\/233389\/revisions\/233391"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media\/233390"}],"wp:attachment":[{"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/media?parent=233389"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/categories?post=233389"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/news-you-need.com\/index.php\/wp-json\/wp\/v2\/tags?post=233389"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}