MrBlack is a minimalistic DDoS malware family and botnet associated primarily with Linux and embedded-device ecosystems, with reported Windows variants as well. It has been documented as part of the broader Chinese DDoS malware landscape and has shown code and hosting overlaps with ServStart and infrastructure linked to the ChinaZ ecosystem, suggesting either shared development lineage, operational collaboration, or circulation within the same underground tooling market. Technical descriptions characterize the family by a main control thread commonly identified as _ConnectServer and an attack-handling routine named DealwithDDoS.
MrBlack has been observed in multi-architecture Linux builds targeting x86, x86_64, ARM, and MIPS systems, which is consistent with deployment against servers and internet-exposed embedded devices such as routers and DVR-class hardware. Its primary purpose is distributed denial-of-service activity, especially SYN flooding, and it has been grouped with other ELF DDoS trojans used in campaigns against online gaming, e-commerce, and online casino services. Reporting on the family places it within financially motivated DDoS operations, including extortion-oriented disruption.
The malware has appeared alongside other botnet tooling on transient hosting infrastructure, including HFS-based distribution servers used to stage malware and operational utilities. Researchers have noted that a Win32 MrBlack sample shared code with ServStart, including an identical SYN flood implementation with only minor variations, and Linux MrBlack samples have been hosted together with ServStart variants. These overlaps indicate that MrBlack is best understood not only as a standalone family but also as part of an interconnected DDoS malware ecosystem affecting both Linux and Windows environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct techniques documented for this family, organized by ATT&CK tactic.
17 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as an example of botnets previously hosted on abused HFS panels.
An IoT-focused DDoS botnet with Windows variants, observed hosted alongside ChinaZ malware and sharing code relationships with ServStart.
A Linux-focused DDoS malware family supporting multiple architectures and centered on C2 connectivity and attack execution. It also has related subfamilies that add persistence and encrypted communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.