AESDDoS is an ELF-based Linux DDoS malware family of Chinese origin that is widely characterized as an evolution of MrBlack. It extends the simpler MrBlack codebase by encrypting command-and-control communications with AES and has been observed establishing persistence through Linux startup mechanisms such as rc.local-style boot scripts. The malware is associated with the broader Chinese DDoS botnet ecosystem that includes MrBlack and ChinaZ-linked activity, and it has been deployed against Linux servers, containers, and embedded Unix-like environments.
AESDDoS is primarily designed to provide remote botnet control and launch distributed denial-of-service attacks. Documented attack methods include SYN, LSYN, UDP, UDPS, and TCP flooding. Reporting also links some AESDDoS variants to post-compromise activity beyond flooding, including remote command execution and cryptocurrency-mining operations. In containerized environments, attackers have deployed AESDDoS by abusing exposed Docker APIs, enumerating running containers, and executing the payload inside them, effectively turning misconfigured Docker hosts into botnet nodes.
Observed intrusion activity tied to AESDDoS deployment includes internet-wide scanning for exposed services, especially Docker daemons reachable without proper access controls. Once access is obtained, operators can execute commands in running containers and potentially gain host-level control because the Docker daemon commonly runs with elevated privileges. This makes AESDDoS relevant not only as a DDoS bot but also as a post-exploitation payload used after successful compromise of poorly secured Linux infrastructure.
AESDDoS has been discussed alongside campaigns targeting vulnerable server software and internet-facing infrastructure, including container platforms and enterprise applications. Its operational use fits the long-running pattern of Linux botnets aimed at building attack capacity for service disruption, with likely financially motivated targeting of online services. The family is best understood as a Linux DDoS trojan/backdoor within the Chinese ELF botnet ecosystem, notable for encrypted C2, persistence on Unix-like systems, and flexible deployment through exposed administrative surfaces.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
15 distinct techniques documented for this family, organized by ATT&CK tactic.
The attacks begin with an Internet scan for vulnerable Docker hosts by sending TCP SYN packets to port 2375 — the Docker daemon communication port which allows for unencrypted and unauthenticated communication
Docker.exe then deploys the AESDDoS botnet malware, which allows attackers to launch several types of DDoS attacks, such as SYN, LSYN, UDP, UDPS, and TCP flood.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux botnet malware deployed into exposed Docker containers via misconfigured Docker API access. It provides remote access and supports multiple DDoS flood methods, and the article also notes prior use for remote code execution and cryptocurrency-mining activities.
An ELF DDoS tool of Chinese origin described as the predecessor or basis for MrBlack.
A MrBlack-related trojan subfamily that adds AES-encrypted C2 communications and persistence via boot scripts and rc.local modifications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.