logo

Revealing the Zergeca Botnet: A New Era in DDoS Attacks

ID: f931dceb-bdb0-5c31-a2d8-29629e604357

STIX ID: report--f931dceb-bdb0-5c31-a2d8-29629e604357

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-07-05

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

Zergeca is a sophisticated Golang-based botnet detected in May 2024 that conducts DDoS (ackFlood, synFlood) and provides secondary capabilities such as proxying, scanning, self-updating, file transfer, reverse shell, and device information theft; its C2 uses domains (ootheca.pw, ootheca.top), shares IPs linked to Mirai, employs evasion techniques including DNS-over-HTTPS and Smux encryption, and has been observed across multiple countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.