logo

Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

ID: 7c22ed67-8880-5581-a8ad-b4284282fc74

STIX ID: report--7c22ed67-8880-5581-a8ad-b4284282fc74

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-19

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A publicly exposed staging server hosted on Iranian-registered infrastructure revealed 449 files across 59 directories that fully expose a live botnet operation: a 15-node relay network, mass SSH deployment tooling (ohhhh.py), credential lists, on-host compilation of a C-based bot client (cnc.c compiled to a binary named 'hex'), DDoS source and binaries, a hardcoded C2, and management scripts including a remote kill-switch; researchers advise blocking tied IPs, monitoring filenames and hashes, hardening SSH, and alerting on unexpected gcc compilation activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.