Trinoo, also written as trin00, is an early distributed denial-of-service (DDoS) malware toolkit/botnet used to launch coordinated UDP flood attacks from compromised systems. The provided content describes it as a set of computer programs written in C that runs on Linux and Solaris and uses a master-daemon (master-agent) architecture: attackers compromise hosts, use scripts and largely automated discovery to identify additional vulnerable machines, convert them into masters or daemons, and then issue commands from masters to daemons to flood a specified victim IP address with UDP traffic. One master can control multiple daemons, and networks of Trinoo-infected systems were reportedly established on thousands of Internet-connected hosts compromised via remote buffer overflow exploits. The content links Trinoo to early documented DDoS activity, including CERT Incident Note IN-99-04 in 1999 and a Trinoo network associated with the February 2000 attack on Yahoo!. Detection and operational details mentioned in the content include masters listening on TCP/UDP port 27655 and master-to-agent communications targeting UDP port 27444 containing the string "l44". Trinoo is also referenced as a precursor or related tool to later DDoS malware including TFN, TFN2K, and Stacheldraht.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
One Master can control multiple Daemons... The DDoS attack is launched when the attacker issues a command on the Master hosts. The Masters instruct every Daemon to start a DoS attack against the IP address specified in the command.
Using client/server technology, the master program can initiate hundreds or even thousands of agent programs within seconds.
In a typical DDoS attack, the army of the attacker consists of master zombies and slave zombies... the attacker sends an attack command to master zombies... Then, master zombies... send attack commands to slave zombies
Communications between TFN master programs and agent programs use ICMP echo reply packets, where the actual instruction to be carried out is embedded in the 16-bit ID field in binary format.
A Distributed Denial of Service (DDoS) attack uses many computers to launch a coordinated DoS attack against one or more targets.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as an earlier DDoS malware/tool whose features were combined into Stacheldraht.
A DDoS botnet toolkit used to coordinate distributed denial-of-service attacks via a master/daemon architecture. Masters control multiple daemons on compromised Linux and Solaris systems, which launch UDP flood attacks against victim hosts.
A distributed denial-of-service tool using master and agent programs to flood targets with UDP packets. Masters communicate with agents over UDP, and attackers typically connect to masters over TCP to launch attacks.
A DDoS attack tool used to build and control distributed attack networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.