
DDoS botnet research and indicators of compromise from Nokia Deepfield ERT
Threat research from the Nokia Deepfield Emergency Response Team (ERT), focused on DDoS botnets and related infrastructure. Each directory covers a botnet family with a brief summary and machine-readable indicators of compromise (IoCs).
This repo consolidates prior community research with original Deepfield ERT analysis. See individual READMEs for references and attribution.
Note:
- Indicators are provided in their raw (not defanged) form so they can be consumed directly by detection tooling. Exercise caution when handling URLs and domains.
- Some indicators contain offensive or vulgar language chosen by threat actors for branding or anti-analysis purposes. These are reproduced verbatim to facilitate detection and attribution.
| Directory | Description |
|---|---|
| aisuru | Mirai-derivative DDoS botnet, active since August 2024 |
| cecbot | CECbot: Android TV botnet with HDMI-CEC abuse, successor to Katana |
| cecilio | CatDDoS derivative with modified RC4 cipher, OpenNIC C2 |
| datasurge | Mirai-lineage bot with no self-propagation; competitor-killing scanner larger than its DDoS engine, plus operator RAT features |
| ddosia | DDoS client of the pro-Russian hacktivist group NoName057(16); crowdsourced, gamified crypto-reward leaderboard whose self-reported impact is trivially fabricated |
| drifter | Independent DDoS botnet on ADB attack surface, CCTV-themed C2 domains |
| ipmoyu | MoYu / BadBox 2.0 residential proxy delivered at runtime by clean grey-market Android-TV IPTV apps (the tigertv family) |
| jackskid | Mirai variant sharing code lineage with Aisuru, DoH C2 via mbedTLS |
| katana | Mirai variant with on-device compiled rootkit, targeting Android TV set-top boxes |
| kbotne | Mirai-lineage DDoS botnet with WebSocket C2 on port 80, hex-encoded config strings, and a broken Android APK |
| kimwolf | Dual-purpose residential proxy and DDoS botnet, 3M+ devices observed |
| maskify | Dual-purpose proxy/DDoS botnet with ENS, IPFS, and custom P2P mesh |
Standalone analyses that don't map to a single botnet family.
We welcome corrections, additional IoCs, and other feedback. Reach out to us on Mastodon at @[email protected].
| mossadproxy | Android TV/IoT DDoS botnet via ADB, operationally linked to ecosystem |
| potassium | Mirai variant with SHELL/SHOUT reverse-shell protocol on the C2 channel, three rotating campaigns from one codebase |
| vibenet | Custom DDoS-and-proxy family whose latest no-libc Linux build ships its own TLS/QUIC/HTTP3 stack to flood at Layer 7 behind a browser fingerprint, with on-chain ENS command-and-control |
| Date | Report | Description |
|---|
| 2026-03-19 | Pray4Bandwidth | Xiongmai DVR campaign deploying IPRoyal Pawns and IPIDEA PacketSDK via Mirai-derived downloader |
| 2026-03-20 | Aisuru ecosystem | Four DDoS botnets traced to one ecosystem via shared code, crypto, and infrastructure |
| 2026-06-18 | RoboVPN / Neunative | Commercial VPN bundling a residential-proxy SDK that shares the Vo1d/Popa C2 backend |