Unmasking the new XorDDoS controller and infrastructure
ID: 260c73f6-2bab-593d-bc24-2369c707879a
STIX ID: report--260c73f6-2bab-593d-bc24-2369c707879a
Feed Name: Cisco Talos
Threat Score
Cisco Talos details active XorDDoS Linux DDoS malware activity (Nov 2023–Feb 2025), describing a new “VIP” trojan builder, a central controller and controller binder that enable large-scale coordinated attacks; it documents SSH brute-force infection, persistence mechanisms, phone-home/C2 protocols, wide victimology (notably heavy targeting of the United States), and provides IOCs and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
