Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
public-research — DDoS botnet research and indicators of compromise from Nokia Deepfield ERT | Kitploit
Tools/GitHubGitHub/deepfield/public-research
Indicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Network SecurityMalware AnalysisThreat IntelligencePapers & Research
GitHubdeepfield/public-research

public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT

View Repository
64322 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Nokia Deepfield ERT — public research

Threat research from the Nokia Deepfield Emergency Response Team (ERT), focused on DDoS botnets and related infrastructure. Each directory covers a botnet family with a brief summary and machine-readable indicators of compromise (IoCs).

This repo consolidates prior community research with original Deepfield ERT analysis. See individual READMEs for references and attribution.

Note:

  • Indicators are provided in their raw (not defanged) form so they can be consumed directly by detection tooling. Exercise caution when handling URLs and domains.
  • Some indicators contain offensive or vulgar language chosen by threat actors for branding or anti-analysis purposes. These are reproduced verbatim to facilitate detection and attribution.

Contents

DirectoryDescription
aisuruMirai-derivative DDoS botnet, active since August 2024
cecbotCECbot: Android TV botnet with HDMI-CEC abuse, successor to Katana
cecilioCatDDoS derivative with modified RC4 cipher, OpenNIC C2
datasurgeMirai-lineage bot with no self-propagation; competitor-killing scanner larger than its DDoS engine, plus operator RAT features
ddosiaDDoS client of the pro-Russian hacktivist group NoName057(16); crowdsourced, gamified crypto-reward leaderboard whose self-reported impact is trivially fabricated
drifterIndependent DDoS botnet on ADB attack surface, CCTV-themed C2 domains
ipmoyuMoYu / BadBox 2.0 residential proxy delivered at runtime by clean grey-market Android-TV IPTV apps (the tigertv family)
jackskidMirai variant sharing code lineage with Aisuru, DoH C2 via mbedTLS
katanaMirai variant with on-device compiled rootkit, targeting Android TV set-top boxes
kbotneMirai-lineage DDoS botnet with WebSocket C2 on port 80, hex-encoded config strings, and a broken Android APK
kimwolfDual-purpose residential proxy and DDoS botnet, 3M+ devices observed
maskifyDual-purpose proxy/DDoS botnet with ENS, IPFS, and custom P2P mesh

Reports

Standalone analyses that don't map to a single botnet family.

Feedback

We welcome corrections, additional IoCs, and other feedback. Reach out to us on Mastodon at @[email protected].

Download Tool
mossadproxyAndroid TV/IoT DDoS botnet via ADB, operationally linked to ecosystem
potassiumMirai variant with SHELL/SHOUT reverse-shell protocol on the C2 channel, three rotating campaigns from one codebase
vibenetCustom DDoS-and-proxy family whose latest no-libc Linux build ships its own TLS/QUIC/HTTP3 stack to flood at Layer 7 behind a browser fingerprint, with on-chain ENS command-and-control
DateReportDescription
2026-03-19Pray4BandwidthXiongmai DVR campaign deploying IPRoyal Pawns and IPIDEA PacketSDK via Mirai-derived downloader
2026-03-20Aisuru ecosystemFour DDoS botnets traced to one ecosystem via shared code, crypto, and infrastructure
2026-06-18RoboVPN / NeunativeCommercial VPN bundling a residential-proxy SDK that shares the Vo1d/Popa C2 backend