Report on DDoSia Malware Launching DDoS Attacks Against Korean Institutions
ID: 0b3b6fad-adba-5fd6-ba40-1597181bd81a
STIX ID: report--0b3b6fad-adba-5fd6-ba40-1597181bd81a
Feed Name: ASEC
Threat Score
The report documents NoName057 and allied pro‑Russian hacktivist groups conducting politically motivated DDoS campaigns (November 2024) against South Korean government sites using the DDoSia bot, detailing its Go-based architecture, C2 authentication and target retrieval flows, supported commands (http/http2), evasion behaviors (random User-Agent), and providing MD5 and IP indicators linked to observed attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
