Stacheldraht is a distributed denial-of-service (DDoS) malware/tool first released in 1999. The provided content describes it as having evolved from or combining features of Trinoo and Tribe Flood Network (TFN), using the same master/agent architecture in which a master program communicates with large numbers of compromised agent systems. It is attributed in the content to "Thomas Stacheldraht," identified there as a member of the Austrian hacker group TESO, and another source in the content describes it as developed by Mixter. Stacheldraht is notable for adding encrypted attacker-to-master communications, including a Blowfish-encrypted control channel, and for supporting automated agent updates via rcp. Reported attack capabilities include ping floods, UDP floods, TCP SYN floods, and Smurf attacks, and the content states it can detect and automatically enable source address spoofing. The content lists it as written in C and running on Linux and Solaris. Detection indicators directly mentioned in the content include ICMP packets with ID 666 and string "skillz", ICMP packets with ID 667 and string "ficken", and spoofing tests using source address 3.3.3.3 with the string "spoofworks".
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Stacheldraht (German for "barbed wire") is malware which performs a distributed denial-of-service (DDoS) attack. It was written by "Thomas Stacheldraht", a member of the Austrian hacker group TESO. It was first released in 1999.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The TFN master program reads a list of IP addresses containing the locations of the agents programs. This list of addresses may be encrypted, using 'Blowfish' encryption.
Like other file-transfer mechanisms, this mechanism commonly uses HTTP, FTP, and remote-procedure call (RPC) protocols.
Using client/server technology, the master program can initiate hundreds or even thousands of agent programs within seconds.
In a typical DDoS attack, the army of the attacker consists of master zombies and slave zombies... the attacker sends an attack command to master zombies... Then, master zombies... send attack commands to slave zombies
Communications between TFN master programs and agent programs use ICMP echo reply packets, where the actual instruction to be carried out is embedded in the 16-bit ID field in binary format.
A Distributed Denial of Service (DDoS) attack uses many computers to launch a coordinated DoS attack against one or more targets.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A DDoS malware/botnet tool designed to perform distributed denial-of-service attacks using methods including ping flood, UDP flood, TCP SYN flood, and Smurf attacks. It can also detect and automatically enable source address forgery and combines features of Trinoo and Tribe Flood Network with added encryption.
A DDoS tool based on TFN and Trinoo concepts, adding encrypted attacker-to-master communications and automated agent updates via rcp. It supports multiple flood types and spoofed source IP addresses.
A DDoS tool derived from Trinoo and TFN, notable for full-control features and a Blowfish-encrypted control channel; later evolved into additional variants.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.