Dofloo, also known as AESDDoS, is a Linux botnet malware family used to build distributed denial-of-service infrastructure at scale. First observed in 2014, it has been repeatedly associated with campaigns targeting exposed or misconfigured internet-facing services, particularly Docker environments with unauthenticated remote API access, and has also appeared in exploitation chains involving server-side remote code execution vulnerabilities such as CVE-2021-26084 affecting Atlassian Confluence. In observed Docker-focused intrusions, operators scan for exposed Docker APIs, enumerate running containers, and use container execution features to launch Dofloo inside compromised containers. The malware supports multiple flooding methods, including SYN, LSYN, UDP, UDPS, and TCP floods, enabling volumetric and protocol-based DDoS attacks. After execution, it profiles the infected system and transmits host information to command-and-control infrastructure so operators can determine follow-on actions based on victim hardware characteristics. Some variants have also been reported to deploy cryptocurrency miners on infected systems, indicating secondary monetization beyond botnet use. Dofloo primarily targets Linux systems and containerized workloads and is commonly seen in opportunistic campaigns abusing weakly secured cloud and container administration surfaces.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On August 25, 2021 a security advisory was released for a vulnerability identified in Confluence Server titled “CVE-2021-26084: Atlassian Confluence OGNL Injection”. The vulnerability allows an unauthenticated attacker to perform remote command execution... various POC/Exploits were published online... attempts at executing them were already detected on our systems... attackers’ attempts to exploit this vulnerability in order to install and run the XMRig cryptocurrency miner on affected Confluence servers. | VirusTotal identified the following payloads as: ... Dofloo Trojan
Attackers are actively scanning for exposed Docker APIs on port 2375 and use them to deploy a malicious payload which drops a Dofloo Trojan variant, a malware known as a popular tool for building large scale botnets.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks begin with an Internet scan for vulnerable Docker hosts by sending TCP SYN packets to port 2375 — the Docker daemon communication port which allows for unencrypted and unauthenticated communication
the data being packed and sent to its command-and-control (C&C) server allowing its masters to decide what the next course of action will be
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named trojan payload identified among other exploit attempts against the Confluence vulnerability.
A Linux botnet malware variant associated here through the same attacker-linked URL and previously observed targeting exposed Docker APIs.
Dofloo is malware used to build large-scale botnets from compromised machines. In this campaign it is deployed via exposed Docker APIs, collects system information, communicates with a C2 server, can execute remote shell commands, and enables multiple DDoS attack types including SYN, LSYN, UDP, UDPS, and TCP flood. Some variants can also load cryptocurrency miners onto infected systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.