Researchers have identified the ShadowV2 botnet, which exploits misconfigured Docker containers on AWS to deploy Go-based malware and conscript systems into a DDoS-for-hire network. The campaign uses a sophisticated Python-based C2 framework, advanced DDoS techniques like HTTP/2 Rapid Reset, and attempts to bypass Cloudflare's Under Attack mode. The infrastructure is designed for modularity and operator control, highlighting the evolution of cybercrime-as-a-service.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Darktrace publicly reported the ShadowV2 campaign, detailing its abuse of exposed Docker daemons and cloud-native tooling to build a DDoS botnet. The company also noted that the botnet domain displayed a seizure notice on its root page while still exposing a functional login panel, suggesting the seizure page was deceptive and the backend remained active.
Darktrace emulated the implant and observed it receiving commands and initiating an HTTP/2 rapid reset attack against a target domain hosted by an Amsterdam VPS provider. The analysis also documented evasion features including randomized query strings, spoofed forwarding headers, and a Cloudflare clearance-cookie bypass using ChromeDP.
After compromise, ShadowV2 dropped an unstripped Go ELF binary that registered with a RESTful command-and-control server, maintained heartbeat and polling loops, and accepted attack tasks. Researchers found the infrastructure resembled a multi-tenant DDoS-as-a-service platform with authentication, roles, attack limits, and support for HTTP flood and HTTP/2 rapid reset attacks.
Operators of the ShadowV2 botnet used a Python spreader hosted on GitHub CodeSpaces and the Python Docker SDK to target externally accessible Docker APIs, primarily on AWS EC2 systems. The malware created customized containers on victim infrastructure to establish initial access and deploy the botnet implant.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcescworld.com
Open sourcedarktrace.com
Open sourcedarkreading.com
Open sourceisc.sans.edu
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.