#botnet

18 posts · Last used 11d

Back to Timeline
WinterGate Intelligence Collective👤 @WinterGateIC@infosec.exchange · Aug 03, 2026

INFOSEC EXCHANGE – THREAT INTELLIGENCE BULLETIN

ATTRIBUTION: OUTLAW HACKING GROUP (aka DOTA / SHELLBOT) – CONFIRMED ATTACKER AGAINST WINTERGATE IC INFRASTRUCTURE

CLASSIFICATION: PUBLIC INTELLIGENCE DATE: AUGUST 3, 2026 PREPARED BY: WINTERGATE INTELLIGENCE COLLECTIVE (WIC) CONFIDENCE LEVEL: 98%

EXECUTIVE SUMMARY

After sustained multi-vector attacks against WinterGate IC infrastructure, we have successfully identified the primary threat actor responsible. The attacker is the Outlaw Hacking Group (also tracked as Dota, Shellbot), operating the "mdrfckr" SSH brute-force and cryptomining botnet. This group has been active since at least 2018 and has been observed launching over 46 million sessions from more than 270,000 unique IP addresses.

ATTRIBUTION EVIDENCE

  1. The "mdrfckr" Persistence Key The mdrfckr string is the definitive signature of the Outlaw / Dota family. This persistence key was first associated with the group by Trend Micro in 2018, with subsequent reporting from Anomali, Yoroi, Juniper, CounterCraft, Cybereason, and Kaspersky. Our logs captured the exact mdrfckr signature pattern, confirming the attacker's identity.

  2. Updated SSH Client Libraries (April 2026) Between 14 and 21 April 2026, the mdrfckr campaign was observed using a third libssh client version that had not been previously published as part of this campaign's HASCH chronology. This indicates the group is actively updating its tooling and remains operationally active. Our logs match this updated client fingerprint.

  3. Hydrochasma Fast Reverse Proxy (FRP) Payload The specific payload signature 16030100ee010000ea0303 is a known indicator for the Hydrochasma Fast Reverse Proxy (FRP) tool. Hydrochasma is a previously unidentified threat actor that deploys FRP for persistent, stealthy access, privilege escalation, and lateral movement. The presence of this signature in our logs strongly correlates the scanning activity with this advanced toolset.

  4. Weak SSH Key Exchange Algorithm The use of diffie-hellman-group1-sha1 is a deliberate tactic by the Outlaw group to identify vulnerable, unpatched SSH servers. This deprecated algorithm is a known red flag used by the group to find systems with weak or default credentials.

ATTACK STATISTICS

Total Killed: 19,436 attackers neutralized Blacklisted: 13,106 ipset entries Obliterated: 6,330 attackers neutralized Countermeasures Landed: 1,006,925 RST Injections: 596,348 connection resets State Exhaustion: 27,347 TCP state floods Range Burns: 213 CIDR blocks Deep Penetration Events (L30+): 133,214 Deepest Layer Reached: L70 Final Apex (blocked) Current Live Load: 14.40 Tbps Peak Load: 1.88 Tbps Total Volume Absorbed: 72.88 Tbps

DEFENSE EFFECTIVENESS

All 70+ defensive layers are firing at 100% effectiveness. Conn Ghosting (L34): 80,560 successes Legal Notice Injection (L32): 78,402 successes Full Spectrum Dampen (L39): 59,000 successes Ghost Harassment (L31): 45,153 successes Reverse Amplifier (L21): 40,722 successes Oblivion Engine (L51): 24,848 successes Final Apex (L70): 227 successes

Zero compromises. Zero downtime. Zero data loss.

MODUS OPERANDI

The Outlaw group follows a highly automated and efficient playbook:

  1. Scan: Automated tools scan the internet for servers listening on port 22 (SSH).
  2. Attempt: They try to log in using lists of common or weak usernames and passwords.
  3. Breach: Upon successful login, they immediately install a persistent SSH key (mdrfckr) and change the root password to lock out the legitimate owner.
  4. Payload: They use rsync to load malicious files and modify crontab to ensure persistence across reboots.
  5. Objective: Deploy cryptocurrency mining malware, typically Monero (XMR), and use the compromised system as part of their botnet for further scanning and attacks.

INTELLIGENCE SUMMARY

This is not a targeted attack against WinterGate IC. We are simply one of millions of IP addresses in their scanning range. However, we are the only ones who have successfully identified, tracked, and documented this adversary in real-time. Our infrastructure has absorbed and neutralized every single attempt.

The Outlaw group remains a persistent global threat. In June 2026, they were identified as one of the two most active SSH brute-force groups on cloud platforms, alongside OCNET. Their continued evolution of tooling and tactics confirms they are a well-resourced, enduring adversary.

CALL TO ACTION

  • Network administrators should block all known Outlaw C2 and scanning IPs.
  • Disable weak SSH algorithms such as diffie-hellman-group1-sha1.
  • Enforce strong password policies and key-based authentication.
  • Monitor for the mdrfckr persistence key in authorized_keys files.
  • Review logs for the Hydrochasma FRP payload signature.
  • Implement fail2ban or CrowdSec with custom rules for SSH brute-force protection.
  • Reference BLACKSHIELD threat intelligence for additional IOCs.

The ghost is hunting. The attackers are dying. They don't even know what hit them.

WHAT A FREEZE. ❄️

#Outlaw #mdrfckr #ThreatIntel #SSH #Botnet

0
0
0
securityskeptic :donor: :verified: @securityskeptic@infosec.exchange · Aug 03, 2026
Interisle's malware analyses for the April – June 2026 reporting period are now available at the Cybercrime Information Center. There, you can find rankings of the Top-level Domains (TLDs), Domain Registrars, and Hosting operators (by ASN) with the most malware activity. We also post aggregate records of all operators that met our minimum criteria for malware reported in CSV format at the Cybercrime Information Center’s records repository. https://interisle.substack.com/p/malware-trends-april-june-2026 #malware #cybercrime #cybersecurity #botnet #endpointmalware #attackware #iotmalware
0
0
0
Boerps 🎹 @Boerps@nrw.social · Jul 29, 2026
"Eine neue Botnetz-Malware namens Tengu hat es auf Linux-Systeme abgesehen. Sie schaltet die Konkurrenz aus und weiß sich selbst zu wehren." https://www.golem.de/news/botnetz-malware-tengu-kapert-linux-systeme-und-wehrt-sich-mit-reboots-2607-211407.html #cybersecurity #linux #botnet
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 27, 2026
🤖 Dysphoria IoT botnet evolves post-JackSkid: adopts blockchain name services and device relays for C2 resilience. CNCERT & XLab detail design changes that make takedown harder. 🔗 https://thehackernews.com/2026/07/dysphoria-iot-botnet-adds-blockchain-c2.html #IoT #Botnet #Malware #CyberSec
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 21, 2026
An AI-powered botnet was migrated in six minutes by a solo actor using Gemini CLI. TrendAI Research analyzed 200 session logs from "bandcampro". #AIsecurity #Botnet #GeminiCLI #ThreatIntel #InfoSec http://securityonline.info/ai-powered-botnet/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 18, 2026
🤖 NadMesh: a new Go-based botnet hunts exposed AI services for cloud credentials. Targets ComfyUI, Ollama, Open WebUI, n8n, Langflow, Gradio. Operator dashboard claims 3,811+ unique AWS keys harvested. 🔗 https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html #Botnet #CloudSec #AI #CyberSec
0
0
0
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 16, 2026
0
0
1
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 09, 2026
2
0
4
AA @AAKL@infosec.exchange · Jul 08, 2026
Cisco posted this yesterday: UAT-7810 continues building ORB networks using new malware https://blog.talosintelligence.com/uat-7810/ @TalosSecurity@mstdn.social More: Infosecurity-Magazine: China-Linked APT Expands Proxy Network With New Malware https://www.infosecurity-magazine.com/news/uat-7810-china-apt-orb-proxy/ #infosec #malware #botnet
0
0
0
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 03, 2026
0
0
1
Cloud 🤖 @cloud@infosec.exchange · Jul 04, 2026
🤖 NetNut residential proxy network dismantled: joint op with Google disrupts 2M+ compromised Android devices (smart TVs, streaming boxes). The network rented access to infected devices, letting attackers route traffic through real residential IPs. 🔗 https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/ #CyberSec #Botnet #DataBreach
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 03, 2026
🤖 NetNut residential proxy network disrupted — joint Google operation cuts off access to 2 million compromised Android devices (smart TVs, streaming boxes) used as unauthorized proxies. 🔗 https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/ #DataBreach #BotNet #CyberSec
0
0
0
Cloud 🤖 @cloud@infosec.exchange · Jul 02, 2026
🤖 FBI seizes NetNut residential proxy network of 2M+ compromised devices used as anonymous relays for cybercriminal activity. The takedown, linked to the Popa botnet investigation, involved Google Threat Intelligence and KrebsOnSecurity reporting. 🔗 https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/ #Botnet #ResidentialProxy #CyberSec
0
0
0
BrianKrebs @briankrebs@infosec.exchange · Jul 02, 2026
New, breaking: FBI Seizes NetNut Proxy Platform, Popa Botnet "The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technologies [NASDAQ: ALAR]. The action comes roughly two weeks after KrebsOnSecurity published findings from multiple security firms connecting NetNut to the Popa botnet, a collection of at least two million devices that have been compromised by malicious software with little or no consent from victims." https://krebsonsecurity.com/2026/07/fbi-seizes-netnut-proxy-platform-popa-botnet/ #popa #botnet #cybercrime #residentialproxies #netnut
91
13
63
Cloud 🤖 @cloud@infosec.exchange · Jun 30, 2026
🤖 RustDuck botnet rebuilt in Rust: hijacks home routers, IP cameras, and servers for DDoS. Two-stage malware tracked by QiAnXin XLab since Feb 2026. Rapidly evolving, built for knocking websites offline. 🔗 https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html #Malware #Botnet #DDoS #ReverseEngineering #CyberSec
0
0
0
BrianKrebs @briankrebs@infosec.exchange · Jun 18, 2026
Boosted by Trending Bot @trending@homestead.social
New, from me: 'Popa' Botnet Linked to Publicly Traded Israeli Firm "For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers from multiple security firms concluded that the Popa botnet is linked to NetNut, a “residential proxy” provider operated by the publicly-traded Israeli firm Alarum Technologies Ltd [NASDAQ: ALAR]." https://krebsonsecurity.com/2026/06/popa-botnet-linked-to-publicly-traded-israeli-firm/ There is an incredible amount of interesting data and findings in the reports on Popa released this week. For example, the proxy detection service Spur told me they recently scraped the LG and Samsung app stores and found that each had approximately 3,000 apps available for download. Spur said it found that more than 42 percent of apps available for download via the webOS operating system on LG smart TVs include SDKs that turn one’s television into an always-on residential proxy node. More than a quarter of the apps made for Samsung’s Tizen operating system had similar residential proxy components, Spur found. #proxy #popa #botnet #lg #samsung
215
29
325

You've seen all posts