Cyber Threat Map Screensaver
The Cyber Threat Map screensaver is a security-operations view of active botnet command-and-control servers, pulled live from the abuse.ch Feodo Tracker and plotted on a world map by country, with a scrolling feed of each server's IP, malware family and network. It only displays public threat intel — nothing is attacked — and it's free, runs in your browser, and ESC exits.
How the Cyber Threat Map screensaver works
A background job downloads abuse.ch's Feodo Tracker — a free public feed of IP addresses currently acting as command-and-control (C2) servers for banking-trojan botnets like Emotet, Dridex and QakBot — and saves it to a data file. (The feed isn't readable from a browser, so it's fetched server-side.)
Each C2 server carries a country code. The saver looks that up in a built-in table of country centroids and drops a marker there — nudged slightly so several servers in one country don't overlap — pulsing like a radar ping.
Underneath, a ticker scrolls the live indicators (IP address, malware family, country and hosting network) the way a security operations centre dashboard would, while a header tallies the total active servers and the top countries.
It is purely a visualisation of public threat intelligence: it reads a list and draws it. Nothing is scanned, contacted or attacked.
A worked example
On a typical day the map shows a scatter of pulsing markers — often concentrated in the United States and Europe where much cloud hosting lives — while the feed scrolls entries like 185.x.x.x · Emotet · DE · HETZNER. The active-C2 count rises and falls as abuse.ch confirms new servers and retires dead ones, so the picture genuinely changes through the day.
Settings & tips
- Threat color sets the marker and feed colour — classic red, or your own.
- Turn the feed ticker off for a pure map, or speed it up with feed speed.
- Pulse speed controls how fast the radar-style markers ping.
Frequently asked questions
- Is this real threat data?
- Yes. It comes from abuse.ch's Feodo Tracker, a respected public feed of active botnet command-and-control servers, refreshed on a schedule.
- Does this screensaver attack anything or get me hacked?
- No. It only reads and displays a public list of known-bad servers. It never scans, contacts or attacks anything — it is a visualisation, like a dashboard.
- What are botnet C2 servers?
- Command-and-control servers are the machines criminals use to control malware-infected computers. Tracking and blocking them is a normal part of cyber defence.
- Why does the number of threats change?
- The feed lists servers that are currently active. As abuse.ch confirms new ones and retires inactive ones, the count and the map update accordingly.
- Is the cyber threat map screensaver free?
- Yes, free and browser-based with no key or download. Run it fullscreen and press ESC to exit.