Tag: denial-of-service (DDoS)

New Evooo1Bot Linux botnet turns routers into traffic relay nodes
News

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

Evooo1Bot is a new modular Linux botnet malware based on Mirai that targets internet-facing gateway devices and transforms them into SOCKS5 traffic relay nodes. The malware can perform distributed denial-of-service (DDoS) attacks, SSH brute-forcing, and password theft in addition to converting computers into proxy nodes. Evooo1Bot has been using known vulnerabilities to target devices from Alcatel, NETGEAR, Tenda, Mitsubishi Electric, Telesquare, and D-Link in different locations since at least July. Fortinet researchers discovered that the malware extends the original framework with many features, such as encrypted C2 communications, an SSH brute-force scanner, a SOCKS relay module, a credential sniffer, and an integrated exploit arsenal targeting multiple known vulnerabilities,...
Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet
News

Microsoft Mitigates Record 15.72 Tbps DDoS Attack Driven by AISURU Botnet

A distributed denial-of-service (DDoS) assault that targeted a single endpoint in Australia and measured 15.72 terabits per second (Tbps) and nearly 3.64 billion packets per second (pps) was automatically discovered and neutralized by Microsoft on Monday. The IT company claimed that it was the biggest DDoS attack ever seen in the cloud and that AISURU, an Internet of Things (IoT) botnet of the TurboMirai class, was the source. Who was the aim of the attack is presently unknown. According to Microsoft's Sean Whalen, the assault featured exceptionally high-rate UDP floods that were generated from more than 500,000 source IPs in different countries and targeted a specific public IP address. Because these abrupt UDP bursts used random source ports and had little source spoofing, prov...
Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks
News

Two Distinct Botnets Exploit Wazuh Server Vulnerability to Launch Mirai-Based Attacks

Two distinct Mirai botnet variants are being dropped by threat actors using a now-patched serious security vulnerability in the Wazur Server to launch distributed denial-of-service (DDoS) assaults. The malicious campaign targets CVE-2025-24016 (CVSS score: 9.9), an unsafe deserialization vulnerability that permits remote code execution on Wazuh servers, according to Akamai, which initially learned about the exploitation activities in late March 2025. In February 2025, 4.9.1 was released to fix the security flaw that impacts all server software versions, including and beyond 4.4.0. Concurrent with the fixes' release, a proof-of-concept (PoC) exploit was made public. "as_wazuh_object" in the framework/wazuh/core/cluster/common.py code is used to deserialize arguments that are seria...
Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet
News

Hackers Exploit Samsung MagicINFO, GeoVision IoT Flaws to Deploy Mirai Botnet

To launch distributed denial-of-service (DDoS) assaults, threat actors have been seen actively taking advantage of security holes in GeoVision end-of-life (EoL) Internet of Things (IoT) devices to ensnare them in a Mirai botnet. The Akamai Security Intelligence and Response Team (SIRT) first noticed the activity in early April 2025. It entails taking advantage of two operating system command injection vulnerabilities (CVE-2024-6047 and CVE-2024-11120, CVSS scores: 9.8) that allow arbitrary system commands to be executed. Kyle Lefton, a researcher at Akamai, told The Hacker News that the attack injects commands into the szSrvIpAddr parameter and targets the /DateSetting.cgi endpoint of GeoVision IoT devices. The botnet was discovered injecting commands to download files as part of...
Experts Uncover New XorDDoS Controller, Infrastructure as Malware Expands to Docker, Linux, IoT
News

Experts Uncover New XorDDoS Controller, Infrastructure as Malware Expands to Docker, Linux, IoT

Given that the United States was the victim of 71.3 percent of the distributed denial-of-service (DDoS) assaults between November 2023 and February 2025, cybersecurity researchers are cautioning about the ongoing threats posed by the XorDDoS malware. According to a Thursday investigation by Joey Chen, a researcher at Cisco Talos, the XorDDoS trojan has become much more common between 2020 and 2023. The XorDDoS trojan's extensive global dispersion and an increase in malicious DNS requests connected to its command-and-control (C2) infrastructure are both contributing factors to this development. The virus has spread to Docker servers, turning compromised systems into bots, in addition to frequently exposed Linux computers. The United States is home to over 42% of the infected devic...
New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks
News

New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks

An active attempt has been made to use a medium-severity security hole affecting Mitel phones to entangle them in a network that may launch distributed denial-of-service (DDoS) assaults using a Mirai botnet variation known as Aquabot. CVE-2024-41710 (CVSS score: 6.8) is the vulnerability in question, which is a case of command injection in the boot process that might enable a malevolent actor to carry out arbitrary operations within the context of the phone. The Mitel 6970 Conference Unit, 6800 Series, 6900 Series, and 6900w Series SIP phones are all impacted. In mid-July 2024, Mitel addressed it. In August, a proof-of-concept (PoC) exploit for the vulnerability was made accessible to the general public read more about New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for D...
Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13000+ IoT Devices
News

Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13000+ IoT Devices

Cloudflare, a web infrastructure and security business, announced on Tuesday that it had identified and stopped the largest distributed denial-of-service (DDoS) attack to history, which was 5.6 Terabit per second (Tbps). On October 29, 2024, the attack, which was based on the UDP protocol, targeted one of its clients, an unidentified Eastern Asian internet service provider (ISP). A botnet using a Mirai variant was the source of the activity. According to a research by Omer Yoachimik and Jorge Pacheco of Cloudflare, the attack lasted under 80 seconds and came from more than 13,000 IoT devices. However, the average contribution of each IP address per second was approximately 1 Gbps read more about Mirai Botnet Launches Record 5.6 Tbps DDoS Attack with 13000+ IoT Devices. Get up ...
Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations
News

Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations

As part of a multi-year worldwide experiment called PowerOFF, a global law enforcement operation has taken 27 stresser services offline and failed them to withstand distributed denial-of-service (DDoS) attacks. Several booter and stresser websites, such as zdstresser.net, orbitalstress.net, and starkstresser.net, were taken down by the Europol-led, 15-nation effort. These services usually use botnet malware that has been installed on hacked devices to attack targets of their choosing on behalf of paying clients. Furthermore, more than 300 individuals have been identified for planned operational actions, and three administrators connected to the illegal sites have been arrested in Germany and France read more about Europol Dismantles 27 DDoS Attack Platforms Across 15 Nations. Ge...