HomeSecurityShadowV2 Botnet Exploits Docker Containers on AWS

ShadowV2 Botnet Exploits Docker Containers on AWS

A sophisticated cybercrime campaign has emerged, turning legitimate AWS infrastructure into attack platforms through distributed denial of service (DDoS) capabilities. The ShadowV2 botnet represents a significant evolution in cyberthreats, leveraging exposed Docker daemons on Amazon Web Services EC2 instances to create permanent bases for large-scale DDoS operations.

See also: New Botnet Exploits DNS Misconfiguration

ShadowV2 botnet
ShadowV2 Botnet Exploits Docker Containers on AWS

This campaign demonstrates a worrying shift towards a professional, service-oriented cybercrime infrastructure that mirrors legitimate cloud-native applications in both design and functionality. The attack begins with malicious users operating from GitHub CodeSpaces, using a Python-based command and control framework to scan and exploit poorly configured Docker installations.

Unlike traditional botnet operations that rely on pre-built malicious Containers, the ShadowV2 botnet uses a unique multi-stage deployment process that creates custom environments directly on victims’ machines. The malware establishes communication with its operators via a RESTful API architecture, implementing sophisticated polling and heartbeat mechanisms that ensure constant connectivity while avoiding detection through the appearance of legitimate network traffic.

See also: SystemBC botnet targets VPS servers

goldoon botnet
ShadowV2 Botnet Exploits Docker Containers on AWS

Darktrace analysts detected the malware during routine honeypot monitoring, discovering that the campaign specifically targets AWS EC2 instances running exposed Docker daemons. Researchers observed the malicious users using advanced attack techniques, including HTTP/2 rapid reset attacks , Cloudflare under-attack mode bypasses , and large-scale HTTP flood campaigns . These capabilities, combined with a fully functional user interface and OpenAPI specification , indicate that ShadowV2 operates as a complete DDoS-as-a-service platform rather than a traditional botnet, giving customers the ability to launch sophisticated distributed attacks against targeted infrastructure.

The malware’s architecture reveals a disturbing level of professionalism, with the entire enterprise designed around a modular, service-oriented approach that includes user authentication, privilege management, and attack mitigation based on subscription levels. This development represents a fundamental shift in the cybercrime economy, where malicious infrastructure increasingly resembles legitimate software-as-a-service offerings in terms of user experience, reliability, and feature completeness.

See also: The AISURU Botnet behind the massive 11.5 Tbps DDoS attack

ShadowV2 Botnet Exploits Docker Containers on AWS

The ShadowV2 botnet uses a sophisticated three-stage deployment process that distinguishes it from conventional Docker-based malware campaigns. The initial breach occurs via Python scripts hosted on GitHub CodeSpaces, identifiable through distinctive HTTP headers, including User-Agent: docker-sdk-python/7.1.0 and X-Meta-Source-Client: github/codespaces.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS