logo

Kamasers DDoS Botnet With Loader Capabilities Attacking Organizations to Deploy Ransomware

ID: b2864ab5-3073-505a-bf36-2954fd8b4919

STIX ID: report--b2864ab5-3073-505a-bf36-2954fd8b4919

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Balaji

...
...

Kamasers is a sophisticated multi-vector DDoS botnet that also operates as a loader, enabling operators to push and execute arbitrary PE payloads (ransomware, infostealers, RATs) on compromised hosts. The report details distribution via GCleaner and Amadey, a Dead Drop Resolver (DDR) mechanism abusing GitHub Gist, Telegram, Dropbox, Bitbucket and even Etherscan for C2 retrieval, fallback domains and hardcoded C2s, links to Railnet/Virtualine hosting, geographic targeting (Germany, US, Poland, LATAM) and sectors (education, telecoms, technology), a list of SHA-256 hashes and C2 URLs, and detection/hunting recommendations for SOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.