Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to malware
MalwareUsed by 1 actor

Low Orbit Ion Cannon

Low Orbit Ion Cannon (LOIC) is a distributed denial-of-service (DDoS) tool used by participants associated with the Anonymous collective during Operation Payback in 2010. The provided content describes LOIC being used to flood targets such as RIAA.org and RIAA.com with traffic, contributing to service outages against entertainment industry, anti-piracy, and government-related websites including the RIAA, MPAA-related infrastructure, IFPI, Hadopi, the U.S. Copyright Office, Aiplex, and other anti-piracy entities in Spain, Italy, Finland, and the UK. The tool was used in publicly coordinated volunteer-driven attacks, including by users with limited technical knowledge. The content specifically notes that LOIC was modified to include a "hive mind" feature, allowing a user to turn their computer into a voluntary bot by entering the correct IRC command-and-control server, enabling automated participation in attacks. High-confidence behavior described in the content is limited to DDoS traffic generation and IRC-based coordination for the hive-mind mode. The malware/tool is closely associated in the content with Anonymous and Operation Payback. No file-based indicators of compromise are provided in the supplied material.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Anonymous

The Anonymous users signed on to the Low-Orbit Ion Cannon (LOIC) tool, and began trying to access the RIAA site at 5 PM ET, instead of at 4 PM as the organizers originally planned.

via pcmagpcmag.com
MITRE ATT&CK

Techniques & procedures

4 distinct techniques documented for this family, organized by ATT&CK tactic.

Command and Control

1 technique
T1071.001Web ProtocolsEvidence1

The Anonymous team has modified the Low Orbit Ion Cannon DDoS tool to include a new “hive mind” feature, which allows anyone using the software to turn their computer into a voluntary bot simply by inputting the correct IRC C&C server into the program. Once the C&C is set, the software will then automatically connect to the channel, receive commands (What URL/IP to attack), and start attacking automatically.

Impact

3 techniques
T1498Network Denial of ServiceEvidence6

Low Orbit Ion Canon, a voluntary denial-of-service tool used last year to protest Visa, Paypal and Mastercard’s decisions to cut off donations to Wikileaks. LOIC is a point-and-click piece of software that bombards a targeted website with useless traffic.

T1498.001Direct Network FloodEvidence1

Spanish security firm Panda Security estimates 200 Spaniards are among the 700 protesters flooding the SGAE's sgae.es website with useless traffic, much of its generated using LOIC (Low Orbit Ion Cannon) DDoS software.

T1499Endpoint Denial of ServiceEvidence1

Gleich an mehreren Stellen kritisiert wurde die „Ionenkanone“ der Anonymous-Gruppe, mit der sich jeder Amateur an den Angriffen auf Paypal und Mastercard beteiligen konnte.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping4

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.