SenNight is a Mirai-derived botnet and DDoS operation associated with a Chinese-speaking operator ecosystem. The operation has been linked to the handle angelalk21 and the Chinese handle 王从天降, and available attribution points to likely origin in mainland China. Operational evidence indicates the infrastructure changed hands across multiple operators since late 2024, including brianshaw, xin, and angela, with angela taking over in January 2026 and rebuilding core services in early 2026. The botnet used the Succubus Mirai management framework and functioned as a DDoS-as-a-service operation with a web dashboard, multi-operator support, attack management features, and a dedicated amplification API. Recorded activity shows hundreds of DDoS attacks between January 2025 and March 2026. Targets included gaming-related infrastructure, major Chinese technology companies, Vietnamese internet service providers, Israeli hosting infrastructure, and cloud-hosted systems. SenNight employed a modified Mirai malware variant supporting multiple CPU architectures. Reported bot behavior included self-deletion on execution, signal ignoring, termination of competing malware, and communication with a dedicated bot command channel. The operation also used scanners and backend services to sustain botnet growth and attack orchestration. A notable technical characteristic was a DNS byte-swap anti-analysis technique. After DNS resolution, the malware transformed the returned address bytes to derive the actual command-and-control destination, causing passive DNS and automated enrichment systems to misattribute activity to decoy infrastructure rather than the real servers. The infrastructure also included encrypted command-and-control tunneling via a Go-based SSH forwarder. Overall, SenNight is best characterized as a financially motivated DDoS botnet operation centered on Mirai-based malware, attack-for-hire functionality, anti-analysis tradecraft, and multi-operator administration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.