Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The Shadowserver Foundation

The Shadowserver Foundation Vendor Cyber Rating & Cyber Score

shadowserver.org

The Shadowserver Foundation is a non-profit watchdog group of security professionals that gather, track, and report on malware, botnet activity, and electronic fraud. It is the mission of the Shadowserver Foundation to improve the security of the Internet by raising awareness of the presence of compromised servers, malicious attackers, and the spread of malware. Join our Alliance - https://www.shadowserver.org/partner/


SF A.I CyberSecurity Scoring

SF
Company Information
Website:https://www.shadowserver.org
Employees number:27
Number of followers:10,854
NAICS:541514
Industry Type:Computer and Network Security
Homepage:shadowserver.org
SF Risk Score (AI oriented)
Between 700 and 749
logo
SFComputer and Network Security
Updated:
14/08/2026
718/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SF Global Score (TPRM)
xxxx
logo
SFComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SF
SFModerate
Current Score
718Ba (MODERATE)
01000
2 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
739Before Incident
Cyber Attack
12 Aug 2026SF
Shadowserver: Dysphoria Botnet Compromises 296,000 IoT Devices for DDoS and Residential Proxy Operations

Dysphoria Botnet Compromises Nearly 300,000 IoT Devices in Major Expansion

718After Incident
CRITICAL-21
THE1786703061
Dysphoria Botnet Compromises Nearly 300,000 IoT Devices in Major Expansion A recent report has uncovered a significant surge in activity from the Dysphoria botnet, which has compromised approximately 296,000 internet-connected IoT devices worldwide. The malware, known for its dual functionality, now poses a heightened threat by enabling both distributed denial-of-service (DDoS) attacks and residential proxy operations, allowing attackers to mask their origins and abuse legitimate network infrastructure. Dysphoria primarily targets vulnerable IoT systems, including routers, cameras, gateways, DVRs, and embedded Linux devices. Early variants focused on DDoS capabilities, but newer versions have evolved to convert infected hosts into proxy relay nodes, removing DDoS functionality in some cases. This shift allows compromised devices to serve as traffic relays, enabling attackers to bypass IP-based restrictions, conduct automated abuse, or blend malicious activity with residential or small-business network traffic. The botnet exploits weak Telnet and SSH credentials, unpatched firmware, exposed management interfaces, and unnecessary remote-access services. Notably, Dysphoria leverages Universal Plug and Play (UPnP) to create port-forwarding rules, exposing internal devices to inbound connections and enabling attackers to use infected hosts as externally reachable relays even behind network address translation (NAT). A key concern is Dysphoria’s resilient command-and-control (C2) infrastructure, which uses Ethereum Name Service (ENS) and Solana Name Service (SNS) records to help bots locate control servers. This blockchain-based approach complicates mitigation efforts, as defenders cannot rely solely on blocking traditional domains or IP addresses. The dataset, released as a Special Report by Shadowserver, provides retrospective visibility for affected network operators. Unlike standard daily reports, this one-time release aggregates historical data rather than a single 24-hour snapshot. While entries are timestamped August 12, 2026, defenders are advised to use the last_seen_time field to track recent activity from specific IP addresses. The expansion of Dysphoria underscores the growing sophistication of IoT botnets, which are increasingly used for both disruptive attacks and covert proxy operations, amplifying the risks for organizations and residential networks alike.
INCIDENT DETAILS -
TYPE
Botnet
MOTIVATION
DDoS attacksResidential proxy operationsTraffic relay for bypassing IP restrictionsAutomated abuseBlending malicious activity with legitimate traffic
IMPACT
Systems Affected: 296,000 IoT devicesOperational Impact: Compromised devices used for DDoS attacks and proxy operations
JULY 2026
739Before Incident
JUNE 2026
738Before Incident
MAY 2026
737Before Incident
APRIL 2026
737Before Incident
MARCH 2026
736Before Incident
FEBRUARY 2026
736Before Incident
JANUARY 2026
736Before Incident
DECEMBER 2025
735Before Incident
NOVEMBER 2025
735Before Incident
OCTOBER 2025
734Before Incident
SEPTEMBER 2025
734Before Incident
JUNE 2025
749Before Incident
Cyber Attack
06 Jun 2025SF
Shadowserver Foundation: FBI: BADBOX 2.0 malware victimization widespread

BADBOX 2.0 Malware Campaign

731After Incident
CRITICAL-18
THE1766992985
FBI Warns of Widespread BADBOX 2.0 Malware Infections Targeting Home IoT Devices The FBI has issued an alert regarding BADBOX 2.0, a sophisticated malware campaign compromising over 1 million internet-exposed home devices, primarily manufactured in China. The malware, downloaded during device setup, enables attackers to establish residential proxy networks, conduct credential stuffing attacks, and execute ad fraud. Compromised devices may exhibit deactivated Google Play Protect settings or unusual internet traffic, prompting the FBI to recommend immediate isolation and restricted network access. Users are advised to monitor network activity, download apps exclusively from official stores, and keep devices updated to mitigate risks. The advisory follows recent disclosures of other cyber threats, including the New Cosmali Loader, which infects Windows systems via typosquatted Microsoft Activation Scripts domains using malicious PowerShell scripts. Additionally, the Shai Hulud malware campaign has impacted over 25,000 repositories and hundreds of npm packages, automating developer environment compromises. Efforts to disrupt BADBOX 2.0 involved collaboration between the FBI, Google, Trend Micro, and the Shadowserver Foundation, while tools like Nezha—a post-exploitation remote access trojan—help attackers evade detection by blending with legitimate activity.
INCIDENT DETAILS -
TYPE
malwarebotnet
MOTIVATION
residential proxy networkscredential stuffingad frauddata exfiltration
IMPACT
Systems Affected: Over 1 million internet-exposed home devices
DATA BREACH
Data Exfiltration: Yes

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SF ?
?
What was SF's A.I Rankiteo Cyber Score in July 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in June 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SF's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SF's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SF's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SF's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on SF's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SF ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SF's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?