Dofloo, also known as AESDDoS, is a Linux-focused DDoS botnet malware family first identified in 2014. It is used to construct large-scale botnets capable of conducting SYN, UDP, TCP, and related flood attacks. Dofloo variants collect host-system information and transmit it to command-and-control infrastructure, enabling operators to profile compromised systems and select follow-on activity. Some variants have also been associated with deployment of cryptocurrency-mining payloads. Dofloo has been deployed to improperly exposed Docker environments by enumerating running containers and executing the malware within them through the Docker API. It has also been observed among payloads delivered through exploitation of vulnerable server software, including Atlassian Confluence. A Linux Dofloo/AESDDoS variant has been linked to campaigns targeting Internet-exposed, unauthenticated Docker services.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On August 25, 2021 a security advisory was released for a vulnerability identified in Confluence Server titled “CVE-2021-26084: Atlassian Confluence OGNL Injection”. The vulnerability allows an unauthenticated attacker to perform remote command execution... various POC/Exploits were published online... attempts at executing them were already detected on our systems... attackers’ attempts to exploit this vulnerability in order to install and run the XMRig cryptocurrency miner on affected Confluence servers. | VirusTotal identified the following payloads as: ... Dofloo Trojan
Attackers are actively scanning for exposed Docker APIs on port 2375 and use them to deploy a malicious payload which drops a Dofloo Trojan variant, a malware known as a popular tool for building large scale botnets.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks begin with an Internet scan for vulnerable Docker hosts by sending TCP SYN packets to port 2375 — the Docker daemon communication port which allows for unencrypted and unauthenticated communication
the data being packed and sent to its command-and-control (C&C) server allowing its masters to decide what the next course of action will be
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Named trojan payload identified among other exploit attempts against the Confluence vulnerability.
A Linux botnet malware variant associated here through the same attacker-linked URL and previously observed targeting exposed Docker APIs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.