CrowdStrike, Google Take Down Glassworm Botnet

CrowdStrike, Google Take Down Glassworm Botnet

A coordinated three-way takedown dismantled one of the most technically inventive botnets targeting open-source developers — and exposed just how far attackers will go to hide in plain sight.

Written by OutOfToken AI

June 8, 2026 · 4 min read · Synthesized from reporting by Infosecurity Magazine · How this works

AI Likely Accurate · 7/10

On May 26, 2026, CrowdStrike, Google, and the Shadowserver Foundation executed a simultaneous strike against all four command-and-control channels of the Glassworm botnet, cutting off its ability to deliver fresh malware payloads to compromised machines. The operation represents one of the most technically intricate botnet dismantlements in recent memory — not because of the scale of the infrastructure, but because of how cleverly Glassworm's operators weaponized legitimate, trusted services to stay invisible. At its core, Glassworm was a long-running campaign against open-source software developers, and by the time it was neutralized, attackers had breached at least 3,800 internal code repositories.

The Developer Supply Chain as the Attack Surface

Glassworm's operators understood that compromising the people who build software is far more leveraged than compromising the software itself. By targeting open-source developers — individuals with access to upstream repositories, package signing keys, and deployment pipelines — the botnet's handlers positioned themselves for potential supply-chain attacks of significant downstream reach. The initial infection vector was a malicious Visual Studio Code extension, a delivery mechanism that bypasses many traditional endpoint detection heuristics because VS Code's extension marketplace is broadly trusted within developer communities. Once installed, the extension established a foothold and enrolled the victim machine into the Glassworm network, where it awaited instructions from a C2 layer that was anything but conventional.

Hiding in Google Calendar and the Blockchain

What made Glassworm technically distinctive — and operationally difficult to neutralize — was its deliberate use of legitimate, high-availability platforms for command-and-control communications. Rather than relying on dedicated C2 servers that could be identified and sinkholed through standard domain takedown procedures, Glassworm's operators embedded instructions inside Google Calendar event fields and encoded directives into blockchain transaction metadata. Both channels are nearly impossible to block at the network perimeter without collateral damage: organizations cannot simply firewall Google Calendar without crippling legitimate productivity workflows, and blockchain data is by design immutable and globally distributed. The botnet maintained four distinct C2 channels in total, requiring the coordinated simultaneous takedown that CrowdStrike, Google, and Shadowserver ultimately delivered — severing any one channel independently would have allowed the others to keep the network operational.

"Glassworm's operators embedded malicious C2 instructions inside Google Calendar events and blockchain transactions — two channels that conventional network defenses cannot block without breaking legitimate workflows entirely."

The Takedown Architecture

Executing the operation required tight synchronization across three organizations with different technical jurisdictions. Google could act directly against the abuse of its own Calendar infrastructure, revoking the specific accounts and API access used to publish C2 data. Shadowserver, the nonprofit that continuously monitors internet-wide threat activity and maintains deep relationships with hosting providers and registrars globally, coordinated the broader infrastructure disruption. CrowdStrike provided the threat intelligence backbone — the company had been tracking Glassworm's behavioral patterns and malware lineage since at least early 2025, building the technical case for attribution and the operational map needed to identify all four C2 channels before executing. The simultaneity was non-negotiable: tipping off any single channel's disruption would have given operators time to spin up replacements.

The Glassworm takedown is a clear signal that botnet operators are no longer building discrete criminal infrastructure — they are parasitizing the legitimate internet itself, turning productivity tools and decentralized ledgers into covert communications networks. That evolution demands a corresponding shift in how defenders think about detection: perimeter firewalls and domain blocklists are insufficient when the C2 channel is a Google Calendar invite. The collaboration model demonstrated here — a security vendor, a platform company with skin in the game, and a nonprofit intelligence clearinghouse moving in lockstep — may be the only architecture capable of keeping pace. Expect more operations like this, because the developers who build the world's software have become too valuable a target for adversaries to ignore.

Editorial Note

Infosecurity Magazine is a reputable cybersecurity news outlet with established credibility. CrowdStrike and Google are legitimate security organizations that regularly coordinate takedown operations against botnets. However, the claim about targeting since 'early 2025' cannot be independently verified without access to the full report and technical indicators of compromise (IOCs).

Claim Tracker

AI-assessed

UnverifiedCrowdStrike, Google, and Shadowserver Foundation executed simultaneous strike against Glassworm on May 26, 2026

Future date (May 2026) makes this claim temporally impossible if written in 2024/2025. Either a typo or fictional scenario.

UnverifiedGlassworm targeted software developers since at least early 2025

No external sources provided to verify this timeline or attribution.

UnverifiedGlassworm breached at least 3,800 internal code repositories

Specific number lacks sourcing; no attribution to official investigation reports.

UnverifiedInitial infection vector was a malicious Visual Studio Code extension

Article cuts off mid-sentence; incomplete claim without supporting evidence.

UnverifiedGlassworm weaponized legitimate, trusted services to remain invisible

Technical characterization presented as fact without technical analysis details provided.

Ask AI about this story

// discussion

sign in to join the discussion