logo

New Golang-Based Zergeca Botnet Capable of Powerful DDoS Attacks

ID: 344c4fa4-97a2-5ab5-b65e-67c8112b59b7

STIX ID: report--344c4fa4-97a2-5ab5-b65e-67c8112b59b7

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-07-05

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

### Executive Summary Security researchers identified Zergeca, a Golang-based botnet family that conducts ACK flood DDoS attacks and provides modular capabilities (persistence, proxying, scanning, self-upgrade, file transfer, reverse shell, and sensitive data collection). The malware uses DoH for C2 resolution, the Smux library for communications, string obfuscation and packer modifications for evasion, and has been observed active against targets in Canada, Germany, and the U.S.; investigators link a reused C2 IP (84.54.51.82) to prior Mirai activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.