Google Sues to Shutter Cryptojacking Botnet That Infected 1M+ Computers
The botnet used the Bitcoin blockchain to evade cybersecurity officials and remain online, Google alleged.

Google on Tuesday moved to shut down a sophisticated cryptojacking botnet that used the Bitcoin blockchain to evade cybersecurity officials.
Known as “Glupteba,” the botnet has infected more than 1 million machines worldwide, Google said in a civil complaint filed Tuesday against Dmitry Staroviko and Alexander Filippov, as well as 15 unknown individuals. Google alleged the defendants utilized this botnet to mine cryptocurrencies on victims’ computers, steal victims’ account information to sell to third parties, purchase goods and services using credit cards with insufficient funds and sell access to compromised machines to third parties.
Moreover, the botnet itself leveraged blockchain technology in a unique manner as an effort to secure it against traditional tools meant to disrupt these types of malicious activities. It effectively turned Bitcoin’s decentralization into an asset that made it “much harder to shut down,” Google executives wrote in a blog post.
The botnet weaponized the Bitcoin blockchain, according to Chainalysis, which said it helped Google’s investigation. By embedding command-and-control server addresses in the blockchain and then having the botnet turn to that data whenever an infected server was shuttered, it stays a step ahead of the cybersecurity whack-a-mole.
“This is the first known case of a botnet using this approach,” representatives for Chainalusis said in an email.
Google’s complaint went into more detail, saying that the “Glupteba Enterprise,” the entity controlled by the defendants, would use this method to direct the malware to new servers.
The botnet looked at three specific bitcoin addresses, according to a Google blog post.
Google said that while it has already taken some action to disrupt the botnet, the fact that it uses the Bitcoin blockchain means the operators can resurrect the network at any time.
“The Glupteba botnet cannot be eradicated entirely without neutralizing its blockchain-based infrastructure,” the complaint said.
Google filed fraud and racketeering allegations against the defendants in its suit.
More For You
Pudgy Penguins: A New Blueprint for Tokenized Culture

Pudgy Penguins is building a multi-vertical consumer IP platform — combining phygital products, games, NFTs and PENGU to monetize culture at scale.
What to know:
Pudgy Penguins is emerging as one of the strongest NFT-native brands of this cycle, shifting from speculative “digital luxury goods” into a multi-vertical consumer IP platform. Its strategy is to acquire users through mainstream channels first; toys, retail partnerships and viral media, then onboard them into Web3 through games, NFTs and the PENGU token.
The ecosystem now spans phygital products (> $13M retail sales and >1M units sold), games and experiences (Pudgy Party surpassed 500k downloads in two weeks), and a widely distributed token (airdropped to 6M+ wallets). While the market is currently pricing Pudgy at a premium relative to traditional IP peers, sustained success depends on execution across retail expansion, gaming adoption and deeper token utility.
More For You
Aero DEX aims to fix liquidity fragmentation and dethrone the incumbents

The rollout of Aero, targeted for the second quarter of 2026, will take direct aim at incumbents like Uniswap and Curve, the team told CoinDesk.
What to know:
- While much of the industry’s attention over the past year has gravitated toward stablecoins, tokenized treasuries and institutional onramps, the team behind Velodrome and Aerodrome says the real power struggle in crypto is unfolding elsewhere: in decentralized exchanges (DEXs).
- The team is getting ready to unveil Aero, a unified DEX that will merge its existing Aerodrome and Velodrome protocols under a single operating system, hoping to take direct aim at incumbents like Uniswap and Curve.











