logo

Chinese Actor SecShow Conducts Massive DNS Probing on Global Scale

ID: 9c0cefa6-747f-5aae-8514-6f3348e0cc8e

STIX ID: report--9c0cefa6-747f-5aae-8514-6f3348e0cc8e

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-11

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers identified a China-linked actor called SecShow conducting large-scale DNS probing via CERNET nameservers since mid-2023—using randomized DNS responses and measurement techniques that can be abused for amplification and triggered amplification loops with security products—and reported a separate financially motivated Mirai-based DDoS-for-hire botnet named Rebirth targeting game servers and advertised via Telegram/online storefronts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.