XorDDoS, also known as XOR.DDoS, is a Linux DDoS botnet malware family first identified in 2014. It primarily compromises Linux servers and other Linux devices through SSH credential brute-forcing, including exposed Docker environments, and installs an ELF payload after obtaining privileged access. It has targeted x86, x64, and ARM systems.
The malware establishes durable execution through System V init/runlevel services and cron jobs. Variants copy themselves to alternative locations, delete installation artifacts and logs, alter process names, terminate competing malware, and modify binary content to impede hash-based detection. XorDDoS uses XOR-obfuscated configuration and command-and-control communications, and gathers host, processor, memory, operating-system, network, and process information.
Many variants include or retrieve a kernel-version-specific loadable-kernel-module rootkit, with code lineage linked to Suterusu and Rooty. The rootkit can conceal the malware's processes, module, network ports, and TCP/UDP connections. XorDDoS can receive commands to launch SYN, ACK, and DNS flooding attacks; download and execute additional payloads; update itself; report system information; and remove competing processes or files.
Recent analysis attributes the operators with high confidence to Chinese-speaking individuals based on language artifacts in associated builder and controller tooling. XorDDoS activity has been globally distributed, with substantial observed targeting and victim concentration in the United States during late 2023 through early 2025.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We uncovered key similarities between RedXOR and previously reported malware associated with Winnti umbrella threat group. These malware are PWNLNX backdoor and XOR.DDOS and Groundhog, two botnets attributed to Winnti by BlackBerry.
29 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware also tries to persist itself using cron... Recent variants have created two shell script files, "/etc/cron.hourly/cqqbnzzu.sh" and "/etc/cron.hourly/obidhyb.sh", which are executed every hour.
This is done by creating symbolic links or executable scripts in the following directories: • (AS1) /etc/init.d/ ... • (AS2) /etc/cron.<S>/ ... • (AS3) /etc/rc<N>.d/
The malware creates a symlink for the init script dropped at the location /etc/init.d/<base_file_name> with the directories associated with runlevels 1 through 5 at /etc/rc<run_level>.d/S90<base_file_name>.
The malware also tries to persist itself using cron... Recent variants have created two shell script files, "/etc/cron.hourly/cqqbnzzu.sh" and "/etc/cron.hourly/obidhyb.sh", which are executed every hour.
Once XorDdos identifies valid SSH credentials, it uses root privileges to run a script that downloads and installs XorDdos on the target device.
The malware first attempts to persist itself using the System V runlevels... This ensures that the malware is automatically started during the boot process.
This is done by creating symbolic links or executable scripts in the following directories: • (AS1) /etc/init.d/ ... • (AS2) /etc/cron.<S>/ ... • (AS3) /etc/rc<N>.d/
The malware creates a symlink for the init script dropped at the location /etc/init.d/<base_file_name> with the directories associated with runlevels 1 through 5 at /etc/rc<run_level>.d/S90<base_file_name>.
The malware also tries to persist itself using cron... Recent variants have created two shell script files, "/etc/cron.hourly/cqqbnzzu.sh" and "/etc/cron.hourly/obidhyb.sh", which are executed every hour.
Once XorDdos identifies valid SSH credentials, it uses root privileges to run a script that downloads and installs XorDdos on the target device.
The rootkit component with a complicated server-assisted installation is where Xorddos differs from all the other Linux trojans.
In order to obfuscate its malicious code, the malware encodes its data using XOR. It encrypts its data using RC4 PRGA... The malware contains obfuscated stackstrings.
A bot running this type of execution is called as the /usr/bin/bsd-port/getty file.
The installation process can consist of several steps: • killing competing time-consuming processes
To avoid detection, the malware deletes its installer scripting and files after completing its attack phases.
Once XorDdos identifies valid SSH credentials, it uses root privileges to run a script that downloads and installs XorDdos on the target device.
The malware may attempt to detect it is running on a VM; where artifact strings found in memory can reveal that the system is virtual.
Distribution starts with either an automated SSH brute-forcing of various Windows and Linux servers or vulnerability scanning and exploiting using the hacking tools and password lists mentioned below.
The malware enumerates processes within the "proc" file system to gather information about the system.
The malware reads system information from the proc file system to determine the system's kernel version. It uses the "uname" system call to query kernel version information. It queries for a number of processors.
Iterates the following folders to find a writable directory: /bin /home /root /tmp /usr /etc
112 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named Linux botnet malware family included in the report tags related to SSH server attacks.
Mentioned only as previously associated implant activity on IPs involved in the first DDoS attack; the report does not connect it directly to Zhadnost or attribute the campaign to it.
Linux-targeting DDoS malware that compromises x86, x64, and ARM hosts and uses them as zombie nodes for distributed denial-of-service attacks. This variant persists through System V runlevels and cron jobs, writes shell scripts, removes installer artifacts after deployment, downloads additional files over HTTP, uses XOR and RC4 PRGA for obfuscation/encryption, and performs host, process, kernel, CPU, and potential virtual-machine checks.
Linux malware associated with persistence and scheduled task abuse; the content references it as relevant to cron-based persistence detection on Unix-like systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.