DDoS Malware Abuses Jenkins Infrastructure In Attacks On Valve Source Engine Servers
ID: 34d99e57-4187-5393-8357-421e4a8838de
STIX ID: report--34d99e57-4187-5393-8357-421e4a8838de
Feed Name: Cyber Press
Darktrace observed a DDoS botnet (seen March 18, 2026) that exploited a weakly protected Jenkins instance via the scriptText endpoint to run a malicious Groovy payload, establish C2 communication, and recruit systems into a botnet; the malware supported multiple flood commands (large and small UDP floods, TCP connection floods, HTTP GET bursts) and included a TSource Engine Query routine specifically designed to amplify attacks against Valve Source Engine game servers, demonstrating opportunistic exploitation of exposed developer services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
