Skip to content

XorDDoS

XorDDoS is a Linux-targeting distributed denial-of-service (DDoS) trojan and botnet malware family first identified in 2014.

Profile source: Mallory opens in a new tab

XorDDoS

Family profile

XorDDoS is a Linux-targeting distributed denial-of-service (DDoS) trojan and botnet malware family first identified in 2014. It compromises Linux systems, including exposed servers and Docker servers, and turns them into zombie bots for high-capacity DDoS operations; reporting cited in the content notes attacks exceeding 150 Gbps. The malware commonly gains initial access through SSH brute-force attacks to obtain valid credentials, after which attackers execute scripts with root privileges to download and install the malware. Persistence is maintained through init scripts and cron job scripts on compromised hosts.

The malware uses XOR-based encryption to conceal communications and to decrypt embedded configuration data; Cisco Talos reported recent versions still using the XOR key "BB2FA36AAA9541F0" for configuration decryption. The decrypted configuration contains URLs or IP addresses used for command-and-control communication. XorDDoS is also described as having rootkit capabilities to evade detection. Talos documented encrypted phone-home traffic that includes a CRC header, uname release and machine strings, a magic string, and a hardcoded version string; after successful connection establishment, the CRC header changes to "5343f096000000000200000000000000000000000000000000000000". Talos also observed controller and sub-controller traffic using incrementing message numbers and commands to start or stop SYN DDoS attacks against IP or domain targets.

Cisco Talos observed XorDDoS continuing to spread globally between November 2023 and February 2025, with nearly 50% of successfully compromised victims in the United States and more than 70% of observed attack attempts targeting the U.S. Talos assessed with high confidence that the operators are Chinese-speaking individuals based on simplified Chinese interfaces and instructions found in the builder, sub-controller, and controller-binding tools. Talos also identified a newer "VIP" sub-controller and a previously unreported central controller capable of managing multiple sub-controllers simultaneously via a controller binder that injects a DLL into controller processes. The content indicates these tools are likely part of a product suite sold on underground markets, supported by embedded feature descriptions, version references, and a Tencent QQ contact left by the creator.

XorDDoS is referenced in multiple Linux detection and hunting contexts focused on ingress tool transfer, cron-based persistence, and credential-file access. High-confidence defensive indicators mentioned in the content include unusual network traffic, spikes in CPU usage, unexpected Linux processes, unauthorized SSH access attempts, cron/init persistence artifacts, and the CRC header value observed after C2 connection establishment.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 26, 2026
Last activity
Jul 26, 2026
Feed role
C2 / Distribution
Host form
2 IP / 7 hostnames

Leading locations

  • LT4
  • US2
  • AL1
  • CN1

Leading providers

  • UAB Host Baltic4
  • Amazon.com, Inc.1
  • CHINANET BACKBONE1
  • Google LLC1
  • ONE ALBANIA SH.A.1

Infrastructure traits

  • Hosting 6
  • Vpn 1

Samples

Recent associated samples

MITRE ATT&CK

XorDDoS in ATT&CK

14 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.