logo

Weaponizing gcc: Inside the Stealthy ‘Hex’ Botnet’s On-Host Compilation Strategy

ID: 8386a329-5279-5b48-b352-36fefb225c49

STIX ID: report--8386a329-5279-5b48-b352-36fefb225c49

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-21

Date Updated: 2026-04-23

Author: Ddos

...
...

Hunt Intelligence uncovered a 15-node 'Hex' botnet that pushes source code to infected Linux hosts and compiles a DDoS client on-host using gcc to evade binary detection; propagation is automated via a Python deployment script (ohhhh.py) that abuses stolen SSH credentials to open hundreds of concurrent sessions, and the infrastructure leverages Iranian hosting and Finnish KCP exit nodes for C2 and censorship-bypass—defenders are advised to harden SSH, monitor compiler usage, and look for indicators like the 'hex' binary and config-client.yaml.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.