Securelist’s analysis of Trojan.Heloag found that the malware does not use peer-to-peer command-and-control as previously suspected. Instead, the examined samples rely on a straightforward TCP-based C2 protocol that lets operators launch multiple DDoS attack modes, download and execute payloads from a URL, send the infected host’s computer name, stop an active attack, and redirect bots to a new command server.
The report says the presence of multiple C2 servers is more consistent with server hand-off, load balancing, or bot rental than with decentralized resilience. Researchers also noted code inconsistencies that may indicate collaboration between two developers or reuse of external code, and assessed the malware as likely originating from China, citing coding traits and a hardcoded Chinese IP address that the bot is explicitly configured not to attack.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The same analysis assessed Heloag as very likely originating from China, citing coding characteristics and a hardcoded Chinese IP address that the malware is explicitly prevented from attacking. The author also noted code inconsistencies suggesting either collaboration between developers or reuse of purchased source code.
A Securelist analysis of Trojan.Heloag concluded that the examined samples do not implement peer-to-peer command-and-control. Instead, the malware uses a simple TCP-based command protocol with DDoS, download-and-execute, host identification, stop, and C2 hand-off functions.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.