Fodcha is a multi-architecture DDoS botnet first observed in 2022 that targets internet-exposed devices through a combination of known vulnerabilities and Telnet/SSH weak-credential attacks. It has been associated with large-scale distributed denial-of-service operations against organizations in sectors including healthcare, communications, and cloud services, and has shown substantial scale with tens of thousands of active bots and terabit-class attack capacity. Victimology has been concentrated in China and the United States, while infections and attack activity have also been observed across other global regions.
The malware targets Linux-based embedded and server environments across architectures including MIPS, ARM, and x86. It has been documented exploiting exposed services and multiple device and application vulnerabilities, including Android Debug Bridge exposure, GitLab CVE-2021-22205, Realtek Jungle SDK JAWS Webserver CVE-2021-35394, and remote code execution flaws affecting DVRs and routers. Operators have also used a dedicated brute-force component to identify devices accessible via weak Telnet credentials.
Fodcha evolved across multiple versions while retaining its core botnet role. Early and later variants differed mainly in command-and-control handling and infrastructure resilience. Later versions adopted encrypted command-and-control communications and more distributed backend infrastructure to complicate analysis and takedown. The malware decrypts embedded configuration data at runtime, performs a staged registration handshake with its controllers, and can disguise its process name. It has also been observed exiting when launched without expected parameters, consistent with a simple anti-analysis measure.
Its primary operational capability is DDoS attack execution, with command support also including heartbeat and termination control. Later reporting indicates the botnet expanded its monetization model by embedding extortion demands directly into attack traffic, demanding payment to halt attacks. Fodcha has also been assessed as a rentable DDoS-for-hire capability. The botnet’s infrastructure and protocol design emphasize resilience, scale, and defense evasion, making it a persistent threat to exposed internet-connected systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
漏洞列表: Vulnerability Affected Device/Service Android ADB Debug Server RCE [[URL_d7d8be78_11]] Android CVE-2021-22205 [[URL_d7d8be78_12]] GitLab CVE-2021-35394 [[URL_d7d8be78_13]] Realtek Jungle SDK JAWS Webserver unauthenticated shell command execution | 由于该僵尸网络最初使用的C2域名folded.in,以及使用chacha算法来加密网络流量,我们将其命名为Fodcha。
漏洞列表: Vulnerability Affected Device/Service Android ADB Debug Server RCE [[URL_d7d8be78_11]] Android CVE-2021-22205 [[URL_d7d8be78_12]] GitLab | 由于该僵尸网络最初使用的C2域名folded.in,以及使用chacha算法来加密网络流量,我们将其命名为Fodcha。
The Broadside malware infects TBK DVR devices impacted by CVE-2024-3721, an OS command injection flaw that can be exploited remotely for arbitrary code execution.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
我们发现Fodcha主要通过以下NDay漏洞和Telnet/SSH弱口令传播... 漏洞列表: Android ADB Debug Server RCE, CVE-2021-22205 GitLab, CVE-2021-35394 Realtek Jungle SDK JAWS Webserver unauthenticated shell command execution, MVPower DVR, LILIN DVR RCE, TOTOLINK Routers Backdoor, ZHONE Router Web RCE
Fodcha uses a multiple-Xor encryption method to protect its key configurations such as C2 data ... After decryption, we will get the Fodcha's C2: fridgexperts.cc
最后和C2建立通信,等待执行C2下发的指令... 当成功和C2建立连接后,Bot与C2必须经过5轮交互,才能真正和C2建立通信。
72 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Fodcha is a botnet malware family that infects IoT devices, such as TBK DVRs, to build a botnet for DDoS attacks and persistent access.
Mentioned only as a comparison point for network protocol structure.
Referenced only as a comparison point for network-protocol state-machine (switch/case) handling; no additional functional details provided in the content.
Fodcha is mentioned only as a comparison point for similar protocol handling structure in the analyzed botnet sample.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.