Team Cymru and Abusix Partner to Eradicate Botnets
A Mission Shared
At Team Cymru, our mission has always been clear, though never easy: to save and improve lives by making the internet safer for everyone. We do this by building trusted partnerships with like-minded organizations, working together to strengthen collective defense.
Over the years, we’ve learned that our mission resonates most with organizations that share our values. Like-minded organizations look to partner with us because they believe in something bigger than themselves. They recognize that you can’t secure the internet by standing alone.
I’m excited to share in this blog that we’ve forged a new partnership with Abusix — a company that shares this same belief and is putting it into practice every day with their network operator partners.
The Persistent Problem: Botnets Aren’t Going Away
Botnets continue to be one of the most stubborn and persistent challenges for network operators. Families like Mirai have been around for years, infecting IoT devices, launching DDoS attacks, and quietly consuming bandwidth from inside provider networks, and impacting a lot of bottom lines in the process.
The frustration is universal: detecting a botnet is one thing; getting it eradicated is another. Too often, detection ends with a warning that may or may not reach the right person, and infections linger. Cleanup is fragmented, reinfections happen, and the cycle continues.
That gap isn’t just frustrating, it’s dangerous. Detection alone isn’t enough. We need to close the loop — from identifying malicious hosts, to reporting them, to verifying that they’re actually cleaned up.
A Shared Goal From Two Perspectives
Abusix has spent years helping ISPs and hosting providers automate abuse management. They’ve built the infrastructure that gets reports into the right hands — and makes sure those reports actually get acted on. Their Global Reporting Project already sends millions of abuse notifications daily, in formats (like XARF) that operators trust and use.
We realized that Abusix and Team Cymru were working toward the same goal from different angles. They had the automation and reporting infrastructure. We had the visibility, threat intelligence, and detection methods. By establishing this partnership, we can complement each other’s strengths in ways that benefit the wider community.
Complementary Strengths, Proven in Testing
As part of this partnership, we’ve opened multiple Team Cymru threat intelligence feeds that are trusted by so many to Abusix:
Working with Abusix’s team of experts, we confirmed what we suspected: our data complements theirs in ways that make both stronger. In just one week of testing, they pulled more than 43 million records from our feeds and compared them to their own observations. The outcome of leveraging data at that scale means abuse reporting gets sharper when enriched with our feeds.
Dismantling Botnets One by One — Beginning with Mirai
Our partnership begins by confronting one of the most notorious threats: Mirai.
Here’s how it works:
- Team Cymru provides detections of IPs tied to Mirai activity.
- Abusix distributes daily reports to affected ISPs and hosting providers through their established reporting pipelines.
- Operators receive clear, actionable notifications in a format they already use.
- Goal: Reduce Mirai infections, measure the cleanup rate, and strengthen network security for everyone.
This is a systematic approach: tackle one botnet family at a time, measure the progress, and then expand - that’s real teamwork.
The Technical Edge
The power of this partnership lies in the distinct value each side brings.
- Team Cymru
- Exclusive access to internet telemetry from partner ISPs and carrier partners.
- Enriched telemetry data from an originator — no vendor aggregation, interpretation, no bias, no filtered views.
- Up to 90 days of historical telemetry, allowing us to provide unmatched context over time
- Threat intelligence built from 25 years of trust and collaboration.
- Exclusive access to internet telemetry from partner ISPs and carrier partners.
- Abusix
- Battle-tested reporting infrastructure, already proven at scale.
- Standardized formats (XARF) that operators know and act on.
- Direct relationships with the ISPs and hosting providers who can actually remediate infections.
- Proven workflows that go beyond alerts to verified cleanup.
- Battle-tested reporting infrastructure, already proven at scale.
Together, this creates a closed loop:
Detection → Reporting → Cleanup → Verification → Improved Detection.
That loop is how we move from passive monitoring to active eradication, together, as a community.
Building the Feedback Loop
Our approach is rooted in reciprocity: when you find value in the data, you should also be able to give back and strengthen the community.
That’s why Abusix is offering operators this Mirai service powered by Team Cymru’s feeds. When operators find value in this service, the next step is simple: join the community of network operators who are shaping a more secure Internet.
This feedback loop benefits everyone:
- Operators clean up infections and protect their customers.
- Team Cymru provides everyone with broader visibility into malicious activity.
- Abusix enhances the effectiveness of its reporting infrastructure.
- The entire community gets safer as the intelligence improves.
Why This Matters
This is more than a partnership between security companies. It’s a sign of something greater: our mission is uniting partners who share our values.
For us, partnerships are purposeful. We choose them only when they strengthen our mission. Abusix is one of those partners. Their infrastructure reaches thousands of ISPs and hosting providers worldwide, including some of the largest Tier 1 operators. By embedding Team Cymru’s data into that ecosystem, the impact is immediate and global.
For operators, this isn’t abstract. It means:
- Actionable notifications they can trust.
- Verified cleanup of infected hosts.
- Stronger network reputation.
- A chance to contribute back to the community by sharing NetFlow.
What Comes Next
Our goal with this partnership is clear: eradicate bots in networks by cleaning them up one botnet family at a time. We’re starting with Mirai because of their prevalence across the internet. These infections drain bandwidth, compromise devices, and create ongoing security risks for network operators. By working together, Abusix and Team Cymru can help affected networks wipe them out systematically.
For me, personally, this partnership elevates above and beyond mere commercials. It’s a reminder that our mission is working.
With Abusix, I see two organizations with different strengths, working alongside each other because they share the same mission — defending the community at scale. And to me, that’s what makes this worth sharing.
If you’re an operator and want to be part of this effort, you can start here: go.teamcymru.com/abusix



