WireX was an Android-based botnet malware operation active in 2017 that used malicious mobile applications to conscript large numbers of compromised devices into application-layer distributed denial-of-service attacks. The malware was embedded in seemingly benign Android apps, including utilities and media-themed applications, some of which were distributed through Google Play. These apps continued to provide expected user-facing functionality while covertly running background components that connected infected devices to command-and-control infrastructure and awaited attack instructions.
WireX generated web traffic that resembled legitimate mobile browsing activity by using Android WebView components as its attack engine. Infected devices could continue participating in attacks while the device was powered on and the screen locked, and the malware used Android service mechanisms to maintain background execution. Attack directives included parameters such as the target web resource and browser metadata, enabling the botnet to issue large volumes of HTTP requests against victim sites. Researchers also assessed that WireX likely evolved from click-fraud malware before being repurposed for DDoS operations.
The botnet was used in August 2017 in major attacks against content providers, CDNs, and hospitality-sector websites. At its peak, it was associated with tens of thousands of infected Android devices, with activity observed from more than 100 countries. Its browser-like traffic profile and ability to blend into normal mobile web behavior made mitigation more difficult than many conventional botnet floods. WireX was ultimately disrupted through coordinated action by multiple security companies, infrastructure providers, Google, and law enforcement. Public reporting also linked the botnet to criminal charges against Izzet Mert Ozek for allegedly using WireX in a DDoS attack against a multinational hospitality company.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
The second header is the X-Requested-With header; although the WebView would usually have a default value,it is overwritten with a blank value. Typically this header coming from an embedded WebView would contain information about the Android application such as com.[app_author].app . It’s likely that this Header was blanked specifically to obfuscate who or what was generating the attack traffic that would be seen by the target.
The applications that housed these attack functions, while malicious, appeared to be benign to the users who had installed them.
At the launch of the applications, the nefarious components begin their work by starting the command and control polling service which queries the command and control server, most commonly g[.]axclick[.]store, for attack commands.
WireX is a volumetric DDoS attack at the application layer. The traffic generated by the attack nodes is primarily HTTP GET requests, though some variants appears to be capable of issuing POST requests.
6 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A botnet made up of compromised Android devices used to launch distributed denial-of-service (DDoS) attacks by flooding targeted websites with traffic.
WireX was an Android-based botnet built from malicious apps that infected smartphones and then used those devices to generate large volumes of traffic for distributed denial-of-service attacks against public-facing web services.
Android-based botnet malware distributed through roughly 300 trojanized Google Play apps. It infected tens of thousands of devices, connected them to command-and-control servers, and was repurposed from click-fraud activity to launch large-scale DDoS attacks using headless browser capabilities and SSL-encrypted traffic.
Android-based botnet delivered through malicious apps that persist in the background, poll axclick[.]store command-and-control infrastructure, parse attack directives, and generate application-layer HTTP GET/POST DDoS traffic using WebView instances with spoofed headers and user agents.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.