The Hoaxcalls malware family has been observed building a DDoS botnet by exploiting remote code execution flaws in internet-exposed DrayTek and Grandstream UCM devices. Palo Alto Networks Unit 42 reported that the malware targets CVE-2020-8515 in DrayTek equipment and CVE-2020-5722 in Grandstream UCM systems, allowing infected devices to be enrolled into a botnet that supports multiple flood techniques, including UDP, HEX, and DNS attacks.
Researchers identified several Hoaxcalls variants with broadly similar capabilities but different propagation behavior: some begin exploiting vulnerable systems immediately after execution, while others wait for operator commands. The malware communicates with command-and-control servers over IRC, including infrastructure at 178[.]32[.]148[.]5:1337, and joins the #hellroom channel using randomized nick, ident, and user strings prefixed with XTC|. The activity shows active weaponization of widely exposed edge-device vulnerabilities, increasing the urgency for organizations to patch affected systems and review exposed voice and networking appliances.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Unit 42 documented three Hoaxcalls variant groups, including differences in whether exploitation was triggered by command or began automatically on execution. The report also disclosed command-and-control and hosting infrastructure, including 178[.]32[.]148[.]5:1337, 18[.]185[.]109[.]135:1337, and irc[.]hoaxcalls[.]pw.
Unit 42 reported that the Hoaxcalls DDoS botnet was actively propagating by exploiting CVE-2020-8515 in DrayTek devices and CVE-2020-5722 in Grandstream UCM devices. The malware used IRC-based command-and-control and supported multiple flood attack types.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 103 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.