AncientNET is a Vietnam-hosted DDoS-as-a-Service operation associated with the Zyre, or zyreBot, Gafgyt-derived botnet family. The operation has been observed running a live command-and-control environment branded AncientNET and managing a bot population primarily composed of compromised VPS and cloud-hosted Linux systems rather than predominantly consumer IoT devices. Reported bot payloads support multiple CPU architectures, indicating broad Linux targeting across heterogeneous server environments. AncientNET’s malware and infrastructure support large-scale distributed denial-of-service activity using multiple attack methods, including UDP floods, SYN floods, HTTP floods, game-platform-focused floods, Source Engine query floods, spoofed-packet attacks, and API-mediated attack delivery through upstream stresser services. The malware includes process-killing logic aimed at removing competing botnets from infected systems, as well as a distinctive single-instance locking mechanism over TCP. Observed infrastructure and operator artifacts indicate an organized multi-operator service model. Known aliases and associated identifiers include AncientNET, Zyre, and zyreBot, with attribution links reported to the online handles zyreeeee3 and BaconXD. The operation has been tied to targeting of competing stresser services, mainstream online platforms, and LGBTQ+ organizations. Based on the observed service model, tooling, and attack patterns, AncientNET is best characterized as a financially motivated cybercriminal operation focused on DDoS-for-hire activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.