logo

GorillaBot Emerged As King For DDoS Attacks With 300,000+ Commands

ID: 44a5eafd-dbef-5f59-8f43-bac6ef6f3887

STIX ID: report--44a5eafd-dbef-5f59-8f43-bac6ef6f3887

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2024-09-30

Date Updated: 2026-04-21

Author: Varshini Senapathi

...
...

NSFocus identified 'GorillaBot,' a Mirai-derived botnet that in September 2024 launched an extensive DDoS campaign issuing 300,000+ commands across 113 countries and targeting sectors including universities, government, telecommunications, banks, and gaming; the report details supported CPU architectures (ARM, MIPS, x86_64, x86), predominant attack methods (UDP Flood, ACK BYPASS, VSE), exploitation of a Hadoop YARN RPC vulnerability, persistence mechanisms (systemd, inittab, init.d scripts), C2 infrastructure, anti-honeypot checks, linkage to the KekSec group, and provides multiple IOC hashes and a malicious download URL.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.