DDoSTF is a cross-platform DDoS botnet first identified around 2016 and reported to have been developed in China. It has Windows PE and Linux ELF variants and is designed to conduct targeted distributed denial-of-service attacks, including SYN, ICMP, TCP, UDP, and HTTP request floods. The Linux variant checks for root privileges, establishes persistence, profiles compromised hosts, and communicates with command-and-control infrastructure using a distinctive protocol marker. The Windows variant persists by copying itself under a randomized name and registering a service; it collects operating-system, CPU, hostname, language, network-performance, and resource-usage information for command-and-control reporting. DDoSTF can start and stop attacks, receive DDoS commands from alternate command-and-control infrastructure, and download and execute additional payloads. It has been deployed against exposed MySQL servers after attackers obtain access through weak credentials or exploitation of unpatched services, including through malicious MySQL user-defined-function components that provide command execution and payload download capability. It has also been observed as a payload following exploitation of Apache ActiveMQ CVE-2023-46604.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Apache issued a critical advisory addressing CVE-2023-46604, a vulnerability involving the deserialization of untrusted data in Apache. CISA added CVE-2023-46604 to its known exploited list, and Fortiguard Labs reported active exploitation. Technical details and proof-of-concept code are publicly available, and threat actors are exploiting it to disseminate malware including GoTitan, PrCtrl Rat, Sliver, Kinsing, and Ddostf. | Meanwhile, Ddostf, with a history dating back to 2016, continues to exhibit its proficiency in executing targeted Distributed Denial of Service (DDoS) attacks.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Threat actors will identify potential targets for their attacks via scans. Among the systems that are publicly accessible, scanners search for systems using the 3306/TCP port, which is used by MySQL servers.
Afterward, it decrypts the encrypted C&C server URL string ... to obtain and connect to the actual C&C server URL. Upon initial connection, it collects basic pieces of information from the infected system and sends them to the C&C server.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Ddostf is a DDoS botnet malware used to conscript infected systems into distributed denial-of-service attacks. It is often delivered alongside other RATs and malware in server-targeted attacks.
A Linux DDoS malware family deployed via CVE-2023-46604 in this campaign. It installs dependencies, attempts persistence, verifies privileges, communicates with C2 using hard-coded identifiers, and supports numerous flood attack methods such as SYN, ICMP, GET, POST, TCP, and UDP floods.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.