logo

New DDoS Malware Exploits Jenkins to Attack Valve Source Engine Game Servers

ID: aec6abed-2a54-5723-b6ee-7c807dd5fddc

STIX ID: report--aec6abed-2a54-5723-b6ee-7c807dd5fddc

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Tushar Subhra Dutta

...
...

Security researchers observed a new cross-platform DDoS botnet that exploits poorly protected Jenkins instances to install malware targeting Valve Source Engine game servers (e.g., Counter-Strike, Team Fortress 2). The malware achieves persistence by masquerading as kernel processes, double-forking, ignoring termination signals, and setting Jenkins environment variables to avoid termination; it supports multiple DDoS vectors including a Valve-specific amplification technique and communicates with a C2 at 103.177.110.202 over TCP port 5444. Operators are advised to restrict public Jenkins access, enforce strong authentication, monitor outbound traffic, block the listed IP and port, and review published IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.