HomeSecurityL7 Botnet compromised 5.76 million devices for mass attacks

L7 Botnet compromised 5.76 million devices for mass attacks

In early March 2025, security teams first observed the L7 DDoS botnet , which targeted web applications across multiple domains.

L7 botnet DDoS

The botnet, which expanded rapidly, starting with 1.33 million compromised devices, used HTTP GET floods to exhaust server resources and bypass traditional rate limits. By mid-May, the threat escalated as the botnet grew to 4.6 million nodes, leveraging compromised IoT devices and poorly secured endpoints. By September, this sprawling network had mobilized 5.76 million IP addresses for a coordinated attack on a government organization, generating tens of millions of requests per second.

Qrator Labs analysts noted significant changes in geographic distribution, with Brazil, Vietnam, and the United States emerging as the main sources of malicious traffic.

See also: ZynorRAT targets Windows and Linux systems

The latest attack evolved into two waves: an initial outbreak involving about 2.8 million devices, followed an hour later by an additional 3 million nodes. HTTP headers in the second wave revealed random User-Agent strings designed to evade simple traffic filtering.

Researchers at Qrator Labs identified key adaptations to the botnet’s control that facilitated its rapid scale. The malware communicates over encrypted channels with a decentralized command and control (C2) infrastructure, which attackers frequently change to avoid blacklisting. Signature-based mitigation struggled to keep up as each C2 endpoint was active for only a few hours before rotation.

L7 Botnet compromised 5.76 million devices for mass attacks

DDoS L7 botnet: Infection mechanism and Persistence

The infection is primarily based on brute-force exploitation of default credentials and unpatched vulnerabilities in IoT device firmware. Once inside a device, the malware deploys a lightweight rootkit that attaches to network interfaces and interferes with firmware update routines.

This approach ensures that malicious modules are reloaded after each system reboot, rendering a simple reboot ineffective as a recovery method. The invisible rootkit also suppresses suspicious process lists, further complicating detection and removal.

See also: Docker malware targets exposed APIs

DDoS botnets

The L7 DDoS botnet demonstrates a worrying escalation in the cyberattack landscape, combining the brute force of millions of compromised devices with techniques that make defense difficult. The most worrying element is not only its size, but its ability to continuously evolve and evade traditional detection tools.

The exploitation of vulnerable IoT devices – from security cameras to home routers – shows how fragile the “smart” internet ecosystem is. Thousands of products are manufactured with little provision for security updates, leaving the door open for those who know how to exploit them. L7 proves that it doesn’t take advanced malware to pull off a devastating attack; all it takes is a critical mass of neglected devices.

L7 Botnet compromised 5.76 million devices for mass attacks

The most innovative element of the botnet is its use of a decentralized C2 infrastructure with rapid rotation. This means that by the time security teams detect one command server, the attackers have already moved on to another. Signature-based filtering, which relies on known patterns of malicious activity, seems powerless in the face of such dynamic tactics.

See also: Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts

From an operational perspective, the two-wave attack strategy—with millions of devices activated in succession—functions as a decoy, allowing attackers to gauge the strength of defenses before launching the most intense wave. It’s a tactic that’s more reminiscent of military operations than simple cybercrime.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The L7 botnet case is a warning: without investment in IoT security and rapid response mechanisms, critical infrastructure will continue to be at the mercy of ghost networks. The future of cyberspace will be determined not by the strength of attacks, but by the ability to build systems that can withstand and adapt.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS