In early March 2025, security teams first observed the L7 DDoS botnet , which targeted web applications across multiple domains.

The botnet, which expanded rapidly, starting with 1.33 million compromised devices, used HTTP GET floods to exhaust server resources and bypass traditional rate limits. By mid-May, the threat escalated as the botnet grew to 4.6 million nodes, leveraging compromised IoT devices and poorly secured endpoints. By September, this sprawling network had mobilized 5.76 million IP addresses for a coordinated attack on a government organization, generating tens of millions of requests per second.
Qrator Labs analysts noted significant changes in geographic distribution, with Brazil, Vietnam, and the United States emerging as the main sources of malicious traffic.
See also: ZynorRAT targets Windows and Linux systems
The latest attack evolved into two waves: an initial outbreak involving about 2.8 million devices, followed an hour later by an additional 3 million nodes. HTTP headers in the second wave revealed random User-Agent strings designed to evade simple traffic filtering.
Researchers at Qrator Labs identified key adaptations to the botnet’s control that facilitated its rapid scale. The malware communicates over encrypted channels with a decentralized command and control (C2) infrastructure, which attackers frequently change to avoid blacklisting. Signature-based mitigation struggled to keep up as each C2 endpoint was active for only a few hours before rotation.

DDoS L7 botnet: Infection mechanism and Persistence
The infection is primarily based on brute-force exploitation of default credentials and unpatched vulnerabilities in IoT device firmware. Once inside a device, the malware deploys a lightweight rootkit that attaches to network interfaces and interferes with firmware update routines.
This approach ensures that malicious modules are reloaded after each system reboot, rendering a simple reboot ineffective as a recovery method. The invisible rootkit also suppresses suspicious process lists, further complicating detection and removal.
See also: Docker malware targets exposed APIs
DDoS botnets
The L7 DDoS botnet demonstrates a worrying escalation in the cyberattack landscape, combining the brute force of millions of compromised devices with techniques that make defense difficult. The most worrying element is not only its size, but its ability to continuously evolve and evade traditional detection tools.
The exploitation of vulnerable IoT devices – from security cameras to home routers – shows how fragile the “smart” internet ecosystem is. Thousands of products are manufactured with little provision for security updates, leaving the door open for those who know how to exploit them. L7 proves that it doesn’t take advanced malware to pull off a devastating attack; all it takes is a critical mass of neglected devices.

The most innovative element of the botnet is its use of a decentralized C2 infrastructure with rapid rotation. This means that by the time security teams detect one command server, the attackers have already moved on to another. Signature-based filtering, which relies on known patterns of malicious activity, seems powerless in the face of such dynamic tactics.
See also: Fake Madgicx Plus and SocialMetrics extensions steal Meta accounts
From an operational perspective, the two-wave attack strategy—with millions of devices activated in succession—functions as a decoy, allowing attackers to gauge the strength of defenses before launching the most intense wave. It’s a tactic that’s more reminiscent of military operations than simple cybercrime.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The L7 botnet case is a warning: without investment in IoT security and rapid response mechanisms, critical infrastructure will continue to be at the mercy of ghost networks. The future of cyberspace will be determined not by the strength of attacks, but by the ability to build systems that can withstand and adapt.
