New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers
ID: aec6abed-2a54-5723-b6ee-7c807dd5fddc
STIX ID: report--aec6abed-2a54-5723-b6ee-7c807dd5fddc
Feed Name: cybersecurityNews.com
Security researchers observed a new cross-platform DDoS botnet that exploits poorly protected Jenkins instances to install malware targeting Valve Source Engine game servers (e.g., Counter-Strike, Team Fortress 2). The malware achieves persistence by masquerading as kernel processes, double-forking, ignoring termination signals, and setting Jenkins environment variables to avoid termination; it supports multiple DDoS vectors including a Valve-specific amplification technique and communicates with a C2 at 103.177.110.202 over TCP port 5444. Operators are advised to restrict public Jenkins access, enforce strong authentication, monitor outbound traffic, block the listed IP and port, and review published IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
