Today marks the 16th anniversary of KrebsOnSecurity.com. The outlet extends gratitude to its audience—both longtime followers and newcomers—for their engagement throughout the past year. A consistent thread in 2025 coverage centered on accountability for organizations facilitating sprawling, internationally-coordinated cybercriminal enterprises.
In May 2024, the site examined Stark Industries Solutions Ltd., a hosting provider offering bulletproof services that launched just before Russia's invasion of Ukraine and functioned as a key hub for Kremlin-directed cyberattacks and propaganda campaigns. Though the European Union imposed sanctions on Stark and its two proprietors a year later, investigation revealed the operators have sidestepped penalties by rebranding and shifting substantial network infrastructure to other operations under their control.
A December 2024 investigation profiled Cryptomus, a Canada-registered financial services company that became the primary payment processor for numerous Russian cryptocurrency platforms and marketplaces selling cybercrime tools to Russian-language audiences. Canadian financial authorities determined in October 2025 that Cryptomus had seriously breached anti-money laundering requirements, imposing a record $176 million penalty.
Research published in September 2023 demonstrated that six-figure theft campaigns targeting multiple victims stemmed from criminals obtaining master passwords compromised from the LastPass password manager during a 2022 breach. Federal investigators examining a dramatic $150 million cryptocurrency theft reached an identical conclusion in a March 2025 court document.
Phishing and Fraud Operations
Voice phishing gangs dominated coverage throughout the year, with reporting examining the operational practices of criminal groups executing intricate, persuasive cryptocurrency theft schemes. One feature, "A Day in the Life of a Prolific Voice Phishing Crew," detailed how a particular gang exploited legitimate Apple and Google infrastructure to distribute outbound communications—including emails, automated calls, and device-level alerts—to targeted users.
Multiple 2025 stories analyzed persistent SMS phishing, or "smishing," originating from China-based phishing kit distributors who facilitate the conversion of stolen payment card information into digital wallets from Apple and Google. Google has filed at least two John Doe lawsuits against these operations and numerous unidentified co-conspirators in response.
January reporting highlighted research on Funnull, a sprawling content delivery network that assisted China-based gambling and money laundering operations in distributing their infrastructure across multiple U.S. cloud providers. The U.S. government sanctioned Funnull five months later, designating it as a significant facilitator of investment and romance fraud schemes, commonly called "pig butchering."

Pakistan detained 21 individuals in May alleged to be members of Heartsender, a phishing and malware distribution operation first examined by KrebsOnSecurity in 2015. The arrests followed seizures of servers and domains by the FBI and Dutch law enforcement. Several detainees had been previously identified in a 2021 article describing how they had inadvertently compromised their own systems with malware that exposed their real identities.
The U.S. Department of Justice brought charges in April against operators of a Pakistan-based e-commerce enterprise for conspiring to traffic synthetic opioids into the United States. The following month, reporting revealed that these sanctioned operators are primarily recognized for orchestrating an extensive fraud scheme targeting Western clients seeking assistance with trademark registration, book publishing, mobile application creation, and graphic design services.
Earlier this month, the site examined an academic cheating operation amplified through Google Ads that generated tens of millions in revenue and maintains unexpected connections to a Russian oligarch with Kremlin ties whose university manufactures drones for Russia's military campaign in Ukraine.

Botnet Threats and DDoS Attacks
Monitoring of major botnets remained a priority, with these networks launching distributed denial-of-service attacks two to three times larger than previously documented record assaults.
In June, KrebsOnSecurity.com sustained what Google had identified as its largest-ever mitigated DDoS attack (the site operates under Google's Project Shield protection). Security researchers attributed the assault to Aisuru, an Internet-of-Things botnet that had expanded significantly since emerging in late 2024. A subsequent Aisuru attack on Cloudflare days later nearly doubled the magnitude of the June assault on this website. Further Aisuru-attributed DDoS activity again approximately doubled the previous record.
By October, operators of Aisuru appeared to have redirected the botnet away from DDoS attacks toward a more lucrative application: leasing hundreds of thousands of compromised IoT devices to proxy services enabling cybercriminals to mask their online activity.
Recent analysis suggests that at least some disruptive botnet and residential proxy operations previously linked to Aisuru were actually conducted by individuals developing and testing Kimwolf, a formidable botnet. Chinese security researcher XLab, which initially documented Aisuru's emergence in 2024, recently published analysis of Kimwolf as the planet's largest and most threatening collection of compromised devices, controlling approximately 1.83 million machines as of December 17.
XLab observed that the Kimwolf creator "shows an almost 'obsessive' fixation on the well-known cybersecurity investigative journalist Brian Krebs, leaving easter eggs related to him in multiple places."

Upcoming KrebsOnSecurity reporting in 2026 will examine Kimwolf's background and investigate the botnet's distinctive and deeply invasive propagation mechanisms. The initial installment will include a significant global security alert regarding the devices and residential proxy infrastructure inadvertently supporting Kimwolf's rapid expansion.
Support the Site
Readers who appreciate KrebsOnSecurity.com's content are encouraged to whitelist the domain in their ad blockers. The site displays only a limited number of static image advertisements served directly and reviewed personally, with no third-party content. This support helps sustain the weekly reporting.
Subscribing to the email newsletter is also recommended. The newsletter reaches 62,000 subscribers with plain text emails dispatched immediately upon publication of new stories. The outlet sends between one and two emails weekly, maintains strict privacy of its subscriber list, and does not conduct surveys or promotional campaigns.
Source: Krebs on Security