A new botnet family dubbed HTTPBot has emerged as a serious threat to the Windows ecosystem, leveraging sophisticated distributed denial-of-service (DDoS) attacks over HTTP to target critical, high-value targets.
See also: What are DDoS botnets and how to avoid them

It was first detected in August 2024, while its activity increased sharply in April 2025, mainly targeting the gaming, technology companies, and educational institutions.
Developed in GoLang, this malware has a modular design that allows it to bypass traditional security measures, using random HTTP headers, dynamic URL paths, and cookie to evade detection. Its “surgical” precision in attacking critical business interfaces – such as payment gateways and login systems – marks a shift from brute-force attacks to targeted resource depletion.
According to researchers at NSFOCUS's Fuying Lab, HTTPBot operates through a multi-layered attack strategy, using unique “attack IDs” to orchestrate and terminate campaigns in a planned manner.
Unlike conventional botnets that primarily aim to saturate bandwidth, HTTPBot seeks to paralyze transaction systems by exploiting vulnerabilities at the application layer.
See also: AkiraBot targets 420,000 websites with spam content
For example, it dynamically switches between HTTP and HTTPS protocols, adjusts the rate of requests based on server responses, and can even launch browser-based attacks using headless Chrome instances. These tactics allow it to mimic legitimate traffic while exhausting server resources.

NSFOCUS analysts noted that HTTPBot operators have adopted a “ low-traffic, high-impact ” approach, focusing on areas that rely on real-time interaction.
Over 80 independent targets were affected over a 15-day period, including gaming platforms such as m.doyo.cn and 28jh.com, as well as educational portals such as Tongji Education.
The botnet's ability to bypass rules-based defenses has raised serious concerns, leading to calls for an upgrade in countermeasures – combining behavioral analysis and dynamic infrastructure.
See also: Ballista botnet targets TP-Link Archer routers
The emergence of HTTPBot marks a new era in DDoS attacks, where “smart” targeting and adaptability outweigh brute force. Unlike classic saturation attacks, HTTPBot focuses on surgically paralyzing critical systems, using techniques that mimic normal usage and bypass classic lines of defense.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
