Kamasers DDoS Botnet With Loader Capabilities Attacking Organizations to Deploy Ransomware
ID: b2864ab5-3073-505a-bf36-2954fd8b4919
STIX ID: report--b2864ab5-3073-505a-bf36-2954fd8b4919
Feed Name: Cyber Press
Kamasers is a sophisticated multi-vector DDoS botnet that also operates as a loader, enabling operators to push and execute arbitrary PE payloads (ransomware, infostealers, RATs) on compromised hosts. The report details distribution via GCleaner and Amadey, a Dead Drop Resolver (DDR) mechanism abusing GitHub Gist, Telegram, Dropbox, Bitbucket and even Etherscan for C2 retrieval, fallback domains and hardcoded C2s, links to Railnet/Virtualine hosting, geographic targeting (Germany, US, Poland, LATAM) and sectors (education, telecoms, technology), a list of SHA-256 hashes and C2 URLs, and detection/hunting recommendations for SOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
