logo

DDoS Malware Targets Jenkins to Hit Valve Game Servers

ID: c5056e94-3435-593b-beec-4a6ca9c068e4

STIX ID: report--c5056e94-3435-593b-beec-4a6ca9c068e4

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-05-01

Date Updated: 2026-05-01

Author: Mayura Kathir

...
...

Darktrace observed a campaign leveraging misconfigured Jenkins scriptText RCE to deploy a cross-platform DDoS botnet (payload and C2 tied to 103.177.110.202) that performs volumetric UDP/TCP floods and application-layer attacks — including Valve Source Engine query amplification — against online game servers; the malware persists, daemonizes, reports system architecture to C2, and supports command-driven attacks and self-updates. Operators should lock down CI servers, remove weak credentials, and apply DDoS protections on game ports (e.g., 27015).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.