logo

Iranian Botnet Exposed via Open Directory: 15-Node Relay Network and Active C2

ID: f455a378-ef3f-5cd0-b10a-daa3cbd6a7dd

STIX ID: report--f455a378-ef3f-5cd0-b10a-daa3cbd6a7dd

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-03-18

Date Updated: 2026-04-28

...
...

*Executive summary:* Hunt.io researchers discovered an exposed open directory that revealed a 15-node relay/tunnel network (Iranian ingress, Hetzner exit nodes) and a credential-driven SSH botnet that compiles and launches a C-based DDoS client on victim hosts; the collection includes deployment scripts, bash history documenting tunnel deployment, DDoS testing, iterative botnet development, compiled binaries with reconnection logic, and multiple IPs/domains and file hashes that can be used as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.