ES EN

Family

XorDDoS

Walks in over SSH on guessed passwords, poses as a system service and XOR-encrypts its command servers. Behind it sits a product for sale, with its own builder and versions.

The honeypot, right now live console view →

Botnet (DDoS) first seen 2014 3 chapters

XorDDoS surfaced in 2014, exposed by MalwareMustDie. It’s a denial-of-service trojan for Linux: it guesses its way in over SSH, installs itself as if it were a system service and sits there waiting for orders.

Its birthmark is the one that gives it its name: the list of command servers travels XOR-encrypted inside the binary, with a sixteen-byte key that hasn’t changed since 2014. That key is what cracks the case open — and what, by turning up somewhere unexpected, led all the way to the operator behind it.

What you can’t see from the binary is that there’s no hobbyist behind it: there’s a product for sale, with its builder, its Chinese-language control panel and its versions. That’s what pulling the thread is after.