logo

Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network

ID: 3ffd48b0-54b3-5a36-a1ec-55cbe25c15ac

STIX ID: report--3ffd48b0-54b3-5a36-a1ec-55cbe25c15ac

Feed Name: GBHackers

Threat Score
60/100

Date Published: 2026-03-19

Date Updated: 2026-05-11

Author: Mayura Kathir

...
...

A misconfigured open directory exposed a 15-node censorship-bypass relay and SSH-based botnet tied to *.server21.org; researchers found Paqet KCP tunnel configs used for Iranian censorship circumvention, DDoS tools (MHDDOS and C-based flooders), and Python scripts that automate mass SSH sessions to compile and deploy a bot client — with multiple Hetzner/OVH and Iranian IPs listed as IoCs. Defenders should watch for Paqet-style KCP tunnels, high-concurrency SSH activity, anomalous gcc/screen usage, and block or monitor the provided IPs and certificates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.