logo

Chaos malware expands from routers to Linux cloud servers

ID: de556368-75ec-5201-b094-1b5478d14204

STIX ID: report--de556368-75ec-5201-b094-1b5478d14204

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-28

Author: Mirko Zorz

...
...

Darktrace’s CloudyPots honeypot captured a new x86-64 Linux build of the Go-based Chaos botnet that exploited a misconfigured Apache Hadoop resource manager to retrieve and execute a binary. The sample includes persistence via systemd, DDoS modules (HTTP, TLS, TCP, UDP, WebSocket) and a newly added SOCKS5 proxy capability allowing attackers to route traffic through compromised cloud servers; delivery and infrastructure connect to domains previously tied to Chinese-language campaigns and ValleyRAT distribution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.