Iran-Linked Botnet Exposed After Open Directory Leak Reveals 15-Node Relay Network
ID: 3ffd48b0-54b3-5a36-a1ec-55cbe25c15ac
STIX ID: report--3ffd48b0-54b3-5a36-a1ec-55cbe25c15ac
Feed Name: GBHackers
A misconfigured open directory exposed a 15-node censorship-bypass relay and SSH-based botnet tied to *.server21.org; researchers found Paqet KCP tunnel configs used for Iranian censorship circumvention, DDoS tools (MHDDOS and C-based flooders), and Python scripts that automate mass SSH sessions to compile and deploy a bot client — with multiple Hetzner/OVH and Iranian IPs listed as IoCs. Defenders should watch for Paqet-style KCP tunnels, high-concurrency SSH activity, anomalous gcc/screen usage, and block or monitor the provided IPs and certificates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
