Matrix is a financially motivated threat actor associated with large-scale distributed denial-of-service operations built on the compromise of internet-exposed IoT devices and enterprise servers. Reporting characterizes the operation as low sophistication but operationally effective, relying heavily on publicly available tooling, open-source scripts, Mirai-derived botnet components, and commodity automation to scan for vulnerable systems, exploit known vulnerabilities, brute-force weak or default credentials, deploy malware, and monetize attack capacity as a DDoS-for-hire service. Matrix has targeted routers, IP cameras, DVRs, telecom equipment, and exposed enterprise services, including misconfigured SSH, Telnet, Hadoop, and graph database environments. Observed tradecraft includes vulnerability exploitation for initial access, brute-force activity against administrative services, botnet enrollment of compromised devices, and use of multiple DDoS utilities to conduct both network-layer and application-layer flooding. The actor has also been linked to tooling intended to impair endpoint defenses on Windows systems, indicating some limited defense-evasion capability beyond pure IoT botnet operations. Victimology indicates especially heavy targeting in China and Japan, with additional activity affecting cloud-hosted infrastructure and smaller enterprises in other countries. The campaign has been assessed by researchers as likely originating from a Russian-speaking or Russian-origin operator, though attribution remains limited to that level. Matrix is notable less for bespoke malware development than for demonstrating how accessible exploit code, credential abuse, and commodity botnet frameworks can be combined into disruptive, globally scalable DDoS operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Matrix employs a variety of initial access techniques, including: Router Exploits: Leveraging vulnerabilities such as CVE-2017-18368 (command injection)...
Router Exploits: Leveraging vulnerabilities such as CVE-2017-18368 (command injection) and CVE-2021-20090 (Arcadyan firmware).
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Matrix is conducting a large-scale DDoS campaign by exploiting vulnerabilities in IoT devices, routers, telecom equipment, and enterprise systems. The group uses publicly available tools and frameworks to build and manage a botnet, offering DDoS-for-hire services via Telegram.
Runs a DDoS campaign/botnet operation that scans for and exploits known IoT vulnerabilities and misconfigurations (including default/weak credentials), leverages misconfigured Telnet/SSH/Hadoop and targets cloud-provider IP ranges; deploys Mirai and other DDoS tooling and appears to offer DDoS-for-hire via a Telegram bot with cryptocurrency payments.
Matrix is conducting a large-scale DDoS campaign targeting IoT devices and enterprise servers by exploiting vulnerabilities, weak credentials, and misconfigurations to build a botnet. The group leverages publicly available tools and scripts to compromise devices and offers DDoS-for-hire services via Telegram.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.