Find notable cyber news and cases, enriched with sources, timelines, and signals.

Underground DDoS sellers commoditize attack services with panels, API access, and reseller plans

Threat Actor Meta
First reported
Last updated
Happening score
H score 18
1 unique sources, 1 articles

Summary

Hide ▲

Underground DDoS sellers are shifting from scattered tools to packaged, resellable services, lowering the barrier for disruptive attacks and widening the buyer pool. Listings seen across 2023 to 2026 increasingly advertise panels, API access, monthly plans, customer support, and botnet-backed capacity instead of scripts or leaked tools. The market is now priced and marketed like a mature service business, with low-cost tests, premium tiers, and reseller options that make attacks easier to launch and redistribute.

Related Happenings

Triad Nexus expands fraud ecosystem and shifts into emerging markets after 2025 US sanctions

Threat Actor Meta
First: 14.04.2026 15:00 Last: 14.04.2026 15:00 Sources 1

About this happening: **Triad Nexus** expanded its fraud ecosystem after **US Treasury sanctions in 2025**, increasing operational scale and shifting into **emerging markets**. The network’s use of **U...

Venom Stealer subscription and affiliate malware-service ecosystem

Threat Actor Meta
First: 01.04.2026 16:30 Last: 01.04.2026 16:30 Sources 1

About this happening: **Venom Stealer** is being run as a **subscription-based** malware service with **Telegram licensing** and an **affiliate program**, signaling a more organized cybercrime ecosyste...

1Campaign-DuppyMeister ecosystem shift changes threat-actor operations

Threat Actor Meta
First: 24.02.2026 23:45 Last: 24.02.2026 23:45 Sources 1

About this happening: **1Campaign** is a long-running **cloaking service** that helps operators keep **malicious Google Ads** online while evading **researcher scrutiny** and automated inspection. The...

2025 DDoS surge targets telecommunications, service providers, and carriers

Trend
First: 05.02.2026 19:25 Last: 05.02.2026 19:25 Sources 1

About this happening: **Cloudflare** reports that the **2025 DDoS surge** has continued into **Q3 2025**, with the **Aisuru botnet** driving more than **1,300 attacks** in three months and a record pea...

Penguin Account-Heavenly Alliance-Overseas Alliance ecosystem shift changes threat-actor operations

Threat Actor Meta
First: 12.01.2026 09:34 Last: 12.01.2026 09:34 Sources 1

About this happening: A **PBaaS service-provider ecosystem** is packaging **pig butchering** operations as turnkey fraud, boosting scale and lowering entry costs across **Southeast Asia**. Providers se...

Timeline

  1. 29.05.2026 17:32 2 articles · 2h ago

    Flare compares underground DDoS listings and finds packaged service growth

    Technical Analysis Update

    Flare researchers compared underground DDoS-related activity from the first five months of 2023 with the first five months of 2026 and found a shift from scripts and leaked tools toward packaged DDoS-as-a-service listings with panels, API access, monthly plans, customer support, reseller options, and botnet-backed capacity. The 2026 listings more often bundled Layer 4 and Layer 7 claims, monitoring, uptime, slots, bypass language, and low-priced offerings, including short attacks, monthly plans, and tiered pricing for stronger targets.

    Show sources