Hoaxcalls is a Linux-based DDoS botnet malware family and an offshoot of the Bashlite/Gafgyt lineage that targets internet-exposed embedded and edge devices. It communicates with command-and-control infrastructure over IRC and supports multiple flood types, including UDP, DNS, HTTP-method, and TCP flag-based attacks. Variants have also added operational features such as traffic proxying, update mechanisms, persistence across restarts, and watchdog disabling to prevent device reboots or facilitate continued control.
Hoaxcalls is notable for aggressive self-propagation through exploitation of known remote code execution vulnerabilities in network and communications appliances. Reported exploitation includes CVE-2020-8515 in DrayTek devices, CVE-2020-5722 in Grandstream UCM systems, Netlink GPON Router 1.0.11 remote code execution, and a post-authentication remote code execution flaw in Symantec Secure Web Gateway 5.0.2.8. Some variants launch scanning and exploitation only when directed by the operator, while others begin infecting vulnerable devices immediately upon execution.
Observed functionality includes scanning for susceptible targets, remote command execution for propagation, DDoS attack execution, proxying, update retrieval, persistence, and anti-administration or anti-recovery actions. Commands to interfere with Telnet access and uninstall or terminate components have been documented, as has logic interacting with watchdog facilities on Linux-based devices. The malware uses XOR-obfuscated strings and retains code and configuration similarities across variants, indicating iterative development rather than a wholly distinct family.
Hoaxcalls has been associated with campaigns against routers, IP PBX systems, secure web gateways, and other Linux-based network-connected devices. Its tradecraft reflects the broader Bashlite/Gafgyt ecosystem: rapid adoption of newly disclosed vulnerabilities, emphasis on botnet growth through opportunistic exploitation, and use of compromised devices primarily for distributed denial-of-service operations and related post-compromise utility functions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
It can propagate by scanning and infecting vulnerable devices using CVE-2020-8515 and CVE-2020-5722 exploits... UCM scan and infect other Grandstream UCM devices by exploiting CVE-2020-5722... Hoaxcalls, a new DDOS botnet, is actively exploiting two vulnerabilities... they are also easily exploited and lead to remote code execution; as such we advise everyone to patch as soon as possible. | Hoaxcalls is a DDoS bot that communicates with its C2 server over IRC. It has various DDoS attack capabilities based on the choice of the C2 operator. Upon reception of a proper C2 command, It can propagate by scanning and infecting vulnerable devices using CVE-2020-8515 and CVE-2020-5722 exploits.
It can propagate by scanning and infecting vulnerable devices using CVE-2020-8515 and CVE-2020-5722 exploits... DRAYTEK scan and infect other Draytek devices by exploiting CVE-2020-8515... Hoaxcalls, a new DDOS botnet, is actively exploiting two vulnerabilities... they are also easily exploited and lead to remote code execution; as such we advise everyone to patch as soon as possible. | Hoaxcalls is a DDoS bot that communicates with its C2 server over IRC. It has various DDoS attack capabilities based on the choice of the C2 operator. Upon reception of a proper C2 command, It can propagate by scanning and infecting vulnerable devices using CVE-2020-8515 and CVE-2020-5722 exploits.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Hoaxcalls is a DDoS bot that communicates with its C2 server over IRC... The bot then connects to its C2 server 178[.]32[.]148[.]5 on TCP port 1337 over IRC. The C2’s IRC channel is #hellroom.
142 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Bashlite/Gafgyt variant mentioned as having exploited the Netlink GPON Router 1.0.11 RCE vulnerability.
An offshoot of the Bashlite/Gafgyt family that exploits exposed devices, adds persistence, can proxy traffic, download updates, prevent reboots, and launch multiple DDoS flood types.
IRC-controlled DDoS botnet malware that launches multiple flood attacks and propagates by scanning for and exploiting vulnerable DrayTek and Grandstream UCM devices. Variants either trigger exploitation via C2 flooder commands or automatically begin infecting vulnerable devices on execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.