ES EN

Family

KHserver

A booter for hire, built to drop other people's matches. A descendant of SBIDIOT: it inherited the 2021 skeleton, the commands — and something you'd never guess.

The honeypot, right now live console view →

Botnet (DDoS for hire) first seen 2021 (as SBIDIOT) 2 chapters

KHserver has no name in any repository: antivirus engines file it as gafgyt/tsunami and that is where its record ends. I name it after the two marks its own author left compiled inside the binary, KHserverHACKER and KHcommSOCK, because those survive even when the files it hands out are renamed.

What sets it apart from Mirai or XorDDoS is not the technique — the skeleton is the usual one — but the business. Its command list includes FORTNITE, COD, R6, RUST and VSE, plus two commands aimed at OVH and NFOservers, the two big game-server hosts. This is not used for whatever comes up: it is rented by the hour so that somebody’s match goes down.

Its other face is the arsenal. It carries fifteen functions named after exploits, most with a CVE number, from 2016 to 2025 — among them React2Shell, the React Server Components code execution that scored a perfect 10 this year and had half the internet patching in a hurry. On paper, a router botnet capable of taking down modern web servers.

On paper. In chapter 12 I open them one by one.

It is not original either. It shares with SBIDIOT — documented back in 2021 — part of its vocabulary and, above all, the exact same string inside the packets it fires. What landed in the honeypot is no creation: it is a descendant, with new exploits glued on top of a five-year-old skeleton. What that string actually says, and what it gives away about whoever copied it, is in chapter 12.