LOIC (Low Orbit Ion Cannon) is a denial-of-service tool referenced in the provided content as being used for DDoS attacks, including by AnonOps-associated participants against perceived "enemies of Anon." The content specifically associates LOIC with flooding-based DDoS activity and notes that a compared payload design was inspired by LOIC and used UDP flooding to perform denial-of-service attacks. In the cited Spamhaus reporting, LOIC and related *OIC tools are described as tools distributed to low-skill operators or "script kiddies" for DDoS operations. The same reporting also states that a 2.1 Gbps attack against Spamhaus did not match the traffic profile of LOIC or other *OIC tools, instead consisting of UDP and SYN flood packets attributed more likely to a criminal botnet environment. High-confidence details in the content are limited to LOIC’s role as a DDoS tool, its association with AnonOps-linked activity, and its recognition as "Low Orbit Ion Cannon."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In addition to the LOIC and *OIC tools issued to dimwitted script kiddies to DDoS "enemies of Anon" with, AnonOps appears to be now escalating its DDoS attacks using dedicated criminal botnets...
3 distinct techniques documented for this family, organized by ATT&CK tactic.
The Anonymous team has modified the Low Orbit Ion Cannon DDoS tool to include a new “hive mind” feature, which allows anyone using the software to turn their computer into a voluntary bot simply by inputting the correct IRC C&C server into the program. Once the C&C is set, the software will then automatically connect to the channel, receive commands (What URL/IP to attack), and start attacking automatically.
Anonymous has been conducting the attacks using a tool called LOIC that allows people to bombard a site of their choosing with data. The tool launches what is known as a distributed denial of service (DDoS) attack, which tries to knock a website offline by bombarding it with so much data that it cannot respond.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.