DDoS Botnet Leveraging Jenkins Misconfigurations for Initial Access (Campaign)
ID: 5b77f567-c6ba-57e5-b2ea-f278b0e2a16a
STIX ID: report--5b77f567-c6ba-57e5-b2ea-f278b0e2a16a
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2026-05-10
Date Updated: 2026-05-21
Author: [email protected] (Wiz Threat Research)
**Executive Summary:** Threat actors abuse exposed or weakly secured Jenkins instances (via the scriptText Groovy endpoint) to execute platform-specific payloads that establish a persistent, evasive botnet with a single C2; infected hosts are instructed to perform UDP/TCP/HTTP floods and gaming-server attacks, and Windows payloads alter firewall rules and remove security flags. The campaign leverages remote code execution for initial access, cross-platform payload delivery, and sustained DDoS operations, with potential data exfiltration noted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
