Frost is a DDoS botnet malware with integrated spreader functionality. It has been observed being delivered via exploitation of ICTBroadcast CVE-2025-2611, where attackers use a shell-script stager to download and execute architecture-specific frost binaries. Reported supported architectures include armv7, armv6, armv5, mips, mipsel, aarch64, x86, and x86_64.
The malware combines DDoS tooling with propagation logic covering fourteen exploits for fifteen CVEs. Its notable characteristic is selective exploitation: Frost checks targets for specific indicators in HTTP responses and only attempts exploitation when the expected fingerprint is present. Each exploit path reportedly has its own match conditions, which helps the campaign avoid many honeypots and generic detection systems.
The campaign was observed by VulnCheck on November 28, 2025, targeting ICTBroadcast canaries. The ICTBroadcast exploit used to deliver Frost is reportedly not present in the binary itself, indicating the operator has additional exploitation capability outside the malware sample. The overall operation has been described as relatively small and targeted because fewer than 10,000 internet-exposed systems were assessed as vulnerable to the exploited CVEs.
Associated infrastructure includes IP address 87.121.84.52, reported as the primary hosting and exploitation server, with domains krebs.strangled.net, mreow.jumpingcrab.com, and xlab.ignorelist.com. A secondary potentially related IP, 176.65.148.246, was also noted. The operator serves stager scripts and Frost binaries over HTTP, and the stagers and binaries are reportedly deleted after execution to reduce forensic evidence. Frost has been associated in reporting with exploitation patterns overlapping vulnerabilities commonly used by botnets such as Mirai, Moobot, and Zerobot.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DDoS botnet malware that combines denial-of-service attack capabilities with spreader logic leveraging multiple exploits for propagation.
frost is a multi-architecture DDoS and spreader tool that propagates by exploiting a set of known vulnerabilities in IoT and network devices. It uses strict fingerprinting to selectively exploit targets, avoiding honeypots and indiscriminate scanning. Once a target is exploited, a stager script downloads and executes the appropriate frost binary for the device architecture, which then attempts to further propagate and participate in DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.