XOR.DDoS has been used to compromise Linux servers through SSH brute-force attacks, install a malicious ELF payload, and turn infected hosts into botnet nodes for distributed denial-of-service activity. Reporting shows the malware can launch SYN flood, ACK flood, and DNS amplification attacks, while maintaining command-and-control communications through a custom protocol and a hard-coded XOR key. Investigations also linked some intrusions to deployment of a second payload, Groundhog, a backdoor that provides reverse shell access, file download capability, configuration updates, and persistent remote control, suggesting both tools were operated as related modules in the same campaign.
The malware is notable for its stealth and persistence on Linux systems. It can tailor installation to the victim's kernel, deploy or build a loadable kernel module rootkit to hide processes and TCP ports, and survive reboots through files and scripts placed in /boot, /etc/init.d, cron, and other system paths. Researchers also observed the malware killing competing processes, reinstalling itself under deceptive filenames, and in some cases being followed by additional payloads such as the Tsunami backdoor and XMRig miner. Microsoft reported a sharp rise in XorDdos activity, underscoring continued risk to internet-exposed Linux devices with weak SSH credentials.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
In July 2015, Check Point's Incident Response team investigated a customer's Linux-based DNS BIND server after suspicious file activity was observed. Check Point determined the server had been compromised through an SSH brute-force attack earlier that month, with attackers gaining root access within a few days.
Check Point reported that Groundhog had not been previously reported and assessed with high probability that Groundhog and XOR.DDoS were different modules of the same malware family created by the same actor. The report also noted attackers had shifted brute-force infrastructure from a HEE THAI LIMITED netblock to CHINANET Jiangsu province backbone.
MalwareMustDie! reported the Linux DDoS malware family XOR.DDoS at the end of September 2014. Later reporting also described the malware as first discovered in 2014 by MalwareMustDie.
Microsoft reported a 254% increase in observed XorDdos activity over the previous six months. Its analysis described continued SSH brute-force propagation, rootkit-enabled stealth, persistence mechanisms, and post-infection deployment of additional malware such as Tsunami and XMRig on some devices.
Avast analyzed XOR.DDoS as a Linux botnet malware family used for DDoS attacks, detailing SSH brute-force access, tailored installation, persistence, and an embedded loadable kernel module rootkit. The analysis also documented ARM support, a newer 32-bit variant, and file-based indicators of compromise.
Check Point's forensic analysis found files related to the Groundhog malware were created on day 36 of the observed 2015 attack timeline. The compromise ultimately involved both XOR.DDoS and the previously unreported Groundhog malware.
Check Point's forensic analysis found files related to XOR.DDoS were created on day 12 of the observed 2015 attack timeline. This marked deployment of the XOR.DDoS payload on the compromised Linux server.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
fireeye.com
Open sourcemicrosoft.com
Open sourcebartblaze.blogspot.com
Open sourceblog.avast.com
Open sourceblog.malwaremustdie.org
Open sourceblog.checkpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.