Botnets have been part of the Internet’s dark underbelly for more than a decade—powering DDoS attacks, spreading malware, and hijacking IoT devices by the millions. The industry detects them every day, yet infections keep coming back.
Detection alone isn’t the problem. Actionability is.
That’s why Abusix and Team Cymru are joining forces to change how the industry approaches botnet threats: from simply tracking them to systematically eliminating them. Together, we’re shifting from passive monitoring to active remediation.
A Partnership Focused on Real-World Cleanup
Team Cymru brings unparalleled visibility into global Internet malicious activity, through network telemetry from security minded ISPs and carriers around the globe, Cymru can pinpoint live infections and command-and-control infrastructure at scale..
Abusix complements that with the backbone needed to take action: our Global Reporting network, which automatically turns threat data into standardized, actionable abuse reports that reach the right operators—fast.
By combining our intelligence with Global Reporting, we are taking the first step to close the loop between seeing the problem and fixing it. The goal is simple: make the Internet measurably safer, one bot family at a time.
The First Initiative: Cleaning Up Mirai
As our first joint effort, we’re targeting Mirai—one of the most pervasive and long-lived IoT botnets in history.
The result will be a measurable reduction in infected hosts—a transparent demonstration that collaborative cleanup works. Mirai is only the starting point. This model can scale to dozens of other bot families over the coming months.
How It Works
- Detect – Team Cymru and Abusix identify compromised hosts and C2 servers through its global telemetry.
- Report – Abusix automatically generates standardized (XARF) abuse reports and delivers them to responsible network operators.
- Remediate – Operators act on these reports to remove or contain infections.
- Verify – Cleanup success is monitored and validated through follow-up data.
- Repeat – Insights feed back into detection and reporting for the next campaign.
This closed-loop workflow turns detection into tangible, verifiable remediation – a first for large-scale botnet mitigation.
Why It Matters for Everyone
For ISPs and hosting providers, this initiative delivers actionable intelligence that goes beyond “you have a problem.”
For the security community, it’s proof that collaboration can deliver measurable progress—not just more alerts.
And for everyone online, fewer infected devices mean fewer DDoS attacks, fewer compromised systems, and a healthier, more resilient Internet overall.
What Comes Next
Mirai is only the beginning. After evaluating cleanup results and sharing success metrics publicly, Abusix and Team Cymru will expand this model to other major bot families. Each new initiative will help build a clearer picture of which networks respond fastest, which require support, and where the global Internet community can improve.
We’ll continue to share progress updates, data insights, and real-world impact across our blog and social channels as the cleanup evolves.
Join the Effort
If you’re a network operator, join Abusix Global Reporting to start receiving actionable intelligence that helps protect your infrastructure.
If you’re a researcher or data provider, partner with us to expand the reach of this initiative.
And if you’re part of the wider security community, follow along as we publish the results—because detection is where security starts, but cleanup is where it matters most.
