A significant development in the field of DDoS has been identified, as the latest version of the XorDDoS malware continues to spread globally as of November 2023.
See also: New Mirai botnet behind rise in TVT DVR exploit

This trojan, which targets Linux systems, turns infected machines into “zombie bots” that can be coordinated to perform powerful DDoS attacks against specific targets. The malware spreads primarily through brute-force attacks on the SSH protocol, trying a multitude of root credential combinations on thousands of servers until it gains access to vulnerable Linux devices. Once inside a system, the XorDDoS malware installs sophisticated persistence mechanisms, ensuring its automatic launch at system startup and effectively avoiding detection by security products.
Cisco Talos researchers found that over 70% of attacks using XorDDoS targeted the United States during the monitoring period.
Analysis of the language settings in the malware's multi-layered controller, creation tool, and login functions suggests that the operators are Chinese speakers.
See also: Eleven11bot botnet has infected 86,000 devices for DDoS attacks
This central controller allows cybercriminals to simultaneously manage multiple individual controllers of the XorDDoS malware, significantly enhancing their ability to coordinate large-scale attacks. The geographic impact extends beyond the United States, as infected systems attempt to target and attack several countries, including Spain, Taiwan, Canada, Japan, Brazil, and several European countries.

The infection process begins when XorDDoS manages to compromise a Linux device via brute-force attacks on SSH. Once it gains access, it installs a malicious shell script, which implements strong persistence mechanisms on the system via init files and cron jobs. The malware ensures its continuous operation by installing init scripts in multiple boot levels and adding a cron job that runs every three minutes.
Once the URLs or IPs are decrypted, they are added to a remote list that is used to establish communication with the command-and-control servers. This advanced encryption mechanism helps the malware evade detection while maintaining constant communication with its operators.
See also: Vo1d malware botnet targets more and more Android TVs
Based on the above, it is clear that the XorDDoS malware has a highly organized and resilient ecosystem of malicious operation, which allows it to remain active for long periods of time without being easily detected. The use of remote lists to communicate with command and control servers, combined with encryption and persistent presence mechanisms, makes it one of the most sophisticated botnets targeting Linux systems.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
