A new Gorilla Botnet, inspired by the Mirai botnet, has launched massive DDoS attacks, targeting more than 100 countries, according to cybersecurity NSFOCUS.

This botnet, which uses the Mirai botnet source code and advanced techniques, is a growing and global threat.
The NSFOCUS Global Threat Hunting System has identified a new cyber threat, the Gorilla Botnet, which launched a massive series of DDoS attacks in September 2024 targeting over 300,000 devices in more than 100 countries.
Read more: GorillaBot has emerged as the "king" of DDoS attacks
Inspired by the well-known Mirai botnet, the Gorilla Botnet leverages compromised IoT devices to carry out large-scale attacks, overwhelming targeted systems with traffic and restricting user access
Its threat comes from its use of encryption to hide critical data and its support for a variety of CPU architectures, making it compatible with many devices. The Gorilla Botnet manages its operations through a distributed C&C network and uses various attack methods, such as UDP Flood and ACK Bypass Flood. Within a month, the botnet has carried out more than 300,000 attacks, with an average of 20,000 per day.
This series of attacks targeted more than 100 countries, including economic powerhouses such as:
China
Canada
Germany
United States
See more: US says Chinese Botnet compromises 260,000 SOHO devices
Additionally, critical infrastructure, such as universities, government websites, telecommunications, banks, and gaming platforms, have been targeted by these attacks.
According to the NSFOCUS report, the sophistication of the Gorilla Botnet surpasses traditional attack methods. The malware incorporates cryptographic algorithms often used by the notorious hacking Keksec, making it difficult to detect and analyze.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The botnet also shows strong persistence. By exploiting vulnerabilities, such as the Apache Hadoop YARN RPC flaw, and by installing automatic services at system startup, Gorilla becomes a persistent adversary that demands eradication.
Organizations should strengthen their cybersecurity to address the growing threat of the Gorilla Botnet. Firewalls help prevent suspicious traffic, while intrusion detection systems (IDS) can detect unusual activity and alert security teams.
Read also: Quad7 botnet targets more VPN routers, media servers
Additionally, using cloud-based DDoS protection can help reduce large attacks, minimizing downtime for critical systems.
Source: hackread
