Last seven days
- First activity
- Jul 26, 2026
- Last activity
- Jul 26, 2026
- Feed role
- C2 / Distribution
- Host form
- 2 IP / 7 hostnames
XorDDoS is a Linux-targeting distributed denial-of-service (DDoS) trojan and botnet malware family first identified in 2014.
Profile source: Mallory opens in a new tabXorDDoS
XorDDoS is a Linux-targeting distributed denial-of-service (DDoS) trojan and botnet malware family first identified in 2014. It compromises Linux systems, including exposed servers and Docker servers, and turns them into zombie bots for high-capacity DDoS operations; reporting cited in the content notes attacks exceeding 150 Gbps. The malware commonly gains initial access through SSH brute-force attacks to obtain valid credentials, after which attackers execute scripts with root privileges to download and install the malware. Persistence is maintained through init scripts and cron job scripts on compromised hosts.
The malware uses XOR-based encryption to conceal communications and to decrypt embedded configuration data; Cisco Talos reported recent versions still using the XOR key "BB2FA36AAA9541F0" for configuration decryption. The decrypted configuration contains URLs or IP addresses used for command-and-control communication. XorDDoS is also described as having rootkit capabilities to evade detection. Talos documented encrypted phone-home traffic that includes a CRC header, uname release and machine strings, a magic string, and a hardcoded version string; after successful connection establishment, the CRC header changes to "5343f096000000000200000000000000000000000000000000000000". Talos also observed controller and sub-controller traffic using incrementing message numbers and commands to start or stop SYN DDoS attacks against IP or domain targets.
Cisco Talos observed XorDDoS continuing to spread globally between November 2023 and February 2025, with nearly 50% of successfully compromised victims in the United States and more than 70% of observed attack attempts targeting the U.S. Talos assessed with high confidence that the operators are Chinese-speaking individuals based on simplified Chinese interfaces and instructions found in the builder, sub-controller, and controller-binding tools. Talos also identified a newer "VIP" sub-controller and a previously unreported central controller capable of managing multiple sub-controllers simultaneously via a controller binder that injects a DLL into controller processes. The content indicates these tools are likely part of a product suite sold on underground markets, supported by embedded feature descriptions, version references, and a Tencent QQ contact left by the creator.
XorDDoS is referenced in multiple Linux detection and hunting contexts focused on ingress tool transfer, cron-based persistence, and credential-file access. High-confidence defensive indicators mentioned in the content include unusual network traffic, spikes in CPU usage, unexpected Linux processes, unauthorized SSH access attempts, cron/init persistence artifacts, and the CRC header value observed after C2 connection establishment.
C2 tracking
Derp observations, rolling seven-day window
Samples
12013662c71da69de977c04cd7021f13a70cf7bed4ca6c82acbc100464d4b0ef 1e87a5dba16588bf91144de1b34a524bc70c39c88bca63f79dd95d3087253d72 2964bfe2584b43a0c53a3482a0f44c5d150130ba344ca538e8aebbe446d7363d 4082a7e2b44c63b458434e9e1607a1a1bc0e44d3e28315127dbc0ba5e37fbcea 96fc528ca5e7d1c2b3add5e31b8797cb126f704976c8fbeaecdbf0aa4309ad46 MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.