Suped

Spamhaus adds enriched botnet C&C data to CERT Insight Portal

News
Published 15 Jun 2026
Updated 15 Aug 2026
11 min read
Summarize with
Editorial thumbnail about enriched Spamhaus botnet C&C intelligence for CERTs.
Updated on 15 Aug 2026: We added Spamhaus' full enrichment field set, clarified portal access workflows, and tightened the sender reputation guidance.
Spamhaus has updated its free CERT Insight Portal for government-funded national and regional CERTs and CSIRTs with enriched botnet C&C reporting, JSON and API access, and improved portal workflows. Spamhaus published the June 14 update in 2026. More than 100 CERTs and CSIRTs already use Spamhaus data to help remediate malware infections in their countries, and the new context can help them investigate command-and-control infrastructure within their own constituencies.
The update goes beyond a portal refresh. Spamhaus says botnet C&C activity it detected rose 56% in 2025, so national response teams need faster ways to turn raw listing data into owner notifications and cleanup tickets. The changes reduce manual lookup work, add usable context, and improve alerting paths before compromised infrastructure causes wider mail or network harm.
What changed
  1. Eligible teams: Government-funded national and regional CERTs and CSIRTs can use the free portal for their constituency.
  2. New data: The Botnet C&C report now includes enriched BCL metadata, including Spamhaus bot names and Malpedia malware-family mappings.
  3. Better access: CERT teams can view the enriched C&C report as JSON or use an API key to download its JSON file.
  4. Alert coverage: Portal alerts can cover BCL and SBL, with SBL covering IPs involved in sending or supporting spam operations.

What changed in the CERT Insight Portal

The CERT Insight Portal already gave qualified CERTs and CSIRTs access to regional reporting on bot activity. The important change is that Spamhaus has added richer context for botnet C&C infrastructure, not just the presence of an IP on a list. A single IP address by itself often creates a slow investigation: who owns it, which network is responsible, what malware family is involved, when it was last seen, and which team needs the escalation.
The updated portal supports watched resources that match a CERT's scope: ISO 3166-1 two-letter country codes, 16-bit or 32-bit ASNs, and IPv4 CIDR blocks. Once those resources are configured, teams can review relevant IPs in portal reports and export the data for internal tooling. That supports repeatable work such as daily triage queues, incident routing, owner notifications, and regional trend reviews.
Spamhaus botnet C&C detection index
Spamhaus says detected botnet C&C activity rose 56% in 2025. This index uses 2024 as the baseline.
2024 baseline
100 index
2025 detected activity
156 index
A 56% rise does not mean every network saw the same increase, but it helps explain the practical value of structured reporting for national and regional responders. When reporting volume increases, prioritization becomes the bottleneck. Teams must distinguish infected hosts from controller infrastructure and decide which cases need owner contact first. The new enrichment supports those decisions.

Report

Source

Data

Best use

Bot Report
XBL
Infected hosts
Endpoint cleanup
Botnet C&C
BCL
Controller IPs
Infrastructure takedown
Alerts
BCL, SBL
Watched assets
Fast triage
CERT Insight Portal report types

What the two reports mean

The two report types are not duplicates. They answer different questions and point to different remediation paths. The Bot Report is sourced from XBL, the Spamhaus Exploits Blocklist, and focuses on infected machines. An IP there usually points to a compromised host or device that needs containment and cleanup. The Spamhaus XBL explainer provides more background on that list.
The enriched Botnet C&C report is sourced from BCL, the Spamhaus Botnet Controller List. It points to infrastructure used to coordinate infected machines. Its context includes protocol, country code, ASN, the bot name assigned by Spamhaus, a corresponding Malpedia malware-family name, the C&C IP address, and the last-seen date. That helps a CERT place a recently observed controller in the right network and attach a consistent malware-family reference to the case.
Bot Report
  1. Source: XBL, based on Spamhaus observations of infected machines.
  2. Primary signal: A host in the watched resource appears to be infected.
  3. Typical action: Notify the network owner, clean the host, and verify the infection has stopped.
Enriched Botnet C&C report
  1. Source: BCL, based on infrastructure used for botnet command and control.
  2. Primary signal: A controller server appears inside the CERT's watched country, ASN, or CIDR.
  3. Typical action: Escalate to hosting, abuse, or network teams with metadata attached.
Example fields to normalizejson
{ "source": "BCL", "protocol": "TCP", "country_code": "US", "asn": 64500, "botname": "example-family", "botname_malpedia": "mapped-family", "ip_address": "192.0.2.10", "last_seen": "2026-06-14" }
That normalized shape is not a replacement for the official Spamhaus feed schema. Teams can map comparable case data into a ticket, SIEM event, abuse workflow, or network owner notification. The API and JSON access let the same evidence move through several teams without manual copying.

Why this matters for email security

Botnet C&C data is primarily a security operations signal, but it connects directly to email security and sender reputation. Compromised infrastructure and controller systems can drive spam, phishing, malware delivery, blocklist listings, and poor IP reputation. Once a sender's shared infrastructure or customer range is associated with abuse, mail acceptance can degrade even when its email authentication records are technically valid.
This is where blocklist and blacklist workflows matter. A mail server can have correct DNS records and still suffer if its IP space has a bad reputation. A hosting range can have one infected customer that triggers scrutiny for adjacent assets. An ESP can have authenticated mail that still lands poorly because the underlying IP reputation is damaged. Authentication asks whether mail is authorized. Reputation asks whether the infrastructure should be trusted now.
Diagram linking infected hosts and C&C servers to blocklist listings, mail rejection, and reputation repair.
Diagram linking infected hosts and C&C servers to blocklist listings, mail rejection, and reputation repair.
Email impact
A clean DMARC result does not cancel out IP reputation damage. If a sending IP or related network asset appears on a major blocklist (blacklist), receivers can still reject, defer, or filter the mail.
  1. Compromise risk: Infected hosts can send unwanted mail or support malicious traffic.
  2. Reputation risk: Shared ranges can suffer when abuse is not contained quickly.
  3. Delivery risk: Receivers can act on blocklist data before a sender sees complaints.
  4. Authentication gap: Passing email authentication does not prove that an IP has good behavior.
For security teams that own mail infrastructure, the Spamhaus update should feed into the same control loop as blocklists, DMARC reporting, and sender reputation monitoring. The value is not only seeing a listing. Teams need to find and fix its source before receivers change how they treat legitimate mail.

Who needs to act

CERTs and CSIRTs are the direct audience. Spamhaus says the free portal is available to government-funded teams responsible for a national or regional constituency. The operating model is to watch defined resources, receive relevant list activity, export reports, and coordinate remediation with the people who can remove an infected host or controller system.
Network operators, hosting providers, ESPs, mailbox and security teams, and abuse desk owners form the indirect audience. They need the data to move quickly once a CERT escalates a case. Waiting until mail is rejected turns an infrastructure incident into a customer-facing delivery problem. The better workflow begins when the infected host, controller server, or spam-supporting infrastructure first appears in the intelligence stream.
  1. CERTs and CSIRTs: Configure watched resources and use the reports to drive national or regional remediation.
  2. Network operators: Map alerts to customers, routers, servers, or hosting segments and remove the cause.
  3. Hosting providers: Use BCL context to identify controller systems and suspend or clean abusive resources.
  4. ESPs: Watch sending pools for reputation damage before it becomes a mail acceptance problem.
  5. Security teams: Tie bot and C&C signals to incident response, customer notification, and abuse handling.
The SBL alert is especially relevant for mail teams. Spamhaus describes SBL as covering IPs involved in sending or supporting spam operations. If your infrastructure or a provider you depend on is listed, receivers that use Spamhaus data can change their acceptance decisions. The Spamhaus SBL background page explains the list when an alert moves into sender reputation remediation.
Operational priority bands
A practical way to prioritize alerts from watched resources.
Monitor
Low
Older signal with no current mail impact.
Triage
Medium
Recent infected host or unknown owner.
Escalate
High
Active C&C or SBL-listed mail asset.
Close
Done
Owner confirms cleanup and reputation recovers.

Practical next steps for CERTs and operators

Eligible CERTs should start by checking portal access and confirming that watched resources match their actual responsibility. A country code can be too broad for some teams, while ASNs and CIDR ranges can support direct owner routing. The strongest setup maps cleanly to the teams that can fix affected assets.
Flowchart showing resource monitoring, JSON intake, list triage, owner routing, remediation, and reputation checks.
Flowchart showing resource monitoring, JSON intake, list triage, owner routing, remediation, and reputation checks.
The API and JSON export are paths to consistent handling, not only conveniences. A manual portal check can help during an investigation, but recurring alerts need a repeatable queue with ownership, priority, status, and closure evidence.
  1. Access review: Confirm the CERT or CSIRT account, users, API key handling, and escalation contacts.
  2. Resource setup: Add the watched country, ASN, and CIDR resources that match the team's mandate.
  3. Data intake: Use the Bot Report API and the enriched C&C JSON download in the existing incident workflow.
  4. Alert triage: Separate BCL, XBL, and SBL items because each one points to a different fix path.
  5. Owner contact: Coordinate with network owners, hosting providers, ESPs, and abuse desks.
  6. Reputation check: Verify that cleanup changes the visible mail and IP reputation state.
For any team handling mail, the final step should include a reputation check, not just a host cleanup note. Use domain health check workflows to review authentication, DNS, and reputation signals together, then use email testing when the question is whether a real message passes the checks receivers apply.
?

What's your domain score?

Deep-scan SPF, DKIM & DMARC records for email deliverability and security issues.

If an affected IP is part of a sending pool, act before customer complaints arrive. Check whether the same IP, adjacent ranges, or sending domains have visible blacklist exposure. Tie that finding to the cleanup ticket so the team can tell whether the fix restored mail trust or only removed the initial security symptom.

Where Suped fits for sender reputation

Spamhaus' portal is built for eligible CERT and CSIRT workflows. Suped's product supports the mail-side work around those cases by combining DMARC reporting, authentication visibility, blocklist monitoring, and sender reputation alerts. This helps mail teams connect an infrastructure incident with changes in authentication or delivery.
Blocklist monitoring page showing domain and IP checks across blocklists with importance and status
Blocklist monitoring page showing domain and IP checks across blocklists with importance and status
CERT or security teams use the Spamhaus portal to identify infected hosts, controller infrastructure, and SBL alerts in their constituency. Mail operations teams can use Suped to monitor whether sending IPs or domains show reputation trouble, whether DMARC failures are rising, and whether authentication changes are needed. That gives both sides a shared view of cause and impact.
Suped's blocklist monitoring is useful after a BCL, XBL, or SBL alert because remediation is complete only when the underlying problem is fixed and reputation risk is under control. Automated detection and alerts help security and mail operations track the work without losing ownership.
Suped workflow
  1. Monitor authentication: Track email authentication health across active sending domains.
  2. Watch reputation: Monitor domain and IP listings across major blocklists and blacklists.
  3. Manage DNS changes: Use Suped's hosted authentication and transport-policy controls when DNS work slows a response.
  4. Scale operations: Manage many domains through multi-tenant dashboards when several clients or brands are involved.

What to watch next

The Spamhaus update puts threat intelligence closer to the teams that can remediate infrastructure. Enrichment reduces the time between detection and ownership. API access turns occasional review into a repeatable process. Alerts make timing part of the response before an incident affects mail delivery.
CERTs and CSIRTs should configure resources, pull reports, triage BCL, XBL, and SBL signals, and coordinate with the right network owners. Mail teams should treat those signals as early warnings for sender reputation. A compromised machine, controller system, or spam-supporting IP can become a blocklist event without appearing as a DMARC failure.
Bottom line
Spamhaus has made the CERT Insight Portal more useful for incident response with enriched Botnet C&C reporting and easier machine access. Fix compromised infrastructure early, then verify that authentication and reputation signals are healthy.

Frequently asked questions

DMARC monitoring

Start monitoring your DMARC reports today

Suped DMARC platform dashboard
What you'll get with Suped
Real-time DMARC report monitoring and analysis
Automated alerts for authentication failures
Clear recommendations to improve email deliverability
Protection against phishing and domain spoofing