New DDoS Botnet Exploits Jenkins to Target Gaming Servers
ID: 999a8f13-e006-595d-ae00-e40756d5977f
STIX ID: report--999a8f13-e006-595d-ae00-e40756d5977f
Feed Name: securityonline.info
Darktrace analysts identified a new distributed denial-of-service (DDoS) botnet campaign that leverages misconfigured, internet-facing Jenkins servers by abusing the scriptText endpoint to obtain remote code execution and deploy a multi-platform payload. The botnet can perform UDP/TCP floods, application-layer attacks, and game-specific DoS techniques, uses evasion and encrypted/obfuscated C2 communications, and was first observed against a Jenkins honeypot on March 18, 2026; organizations using Jenkins are advised to audit and harden their CI/CD exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
