Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Posts
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
New, from our ERT: https://github.com/deepfield/public-research/blob/main/ipmoyu/report.md
The APK is clean. No sample would have tipped us off; the traffic did.
A DNS hunt on networks we protect flagged devices beaconing to an unlisted BADBOX C2. We pivoted on the shared infrastructure to a free IPTV app dropping a residential-proxy exit node. Skip the cable bill, get a tenant.
The ERT tracks DDoS, not IPTV (though Deepfield does track video for analytics). But an exit node isn’t video. It’s a TV dialing out, minding its business. Someone else’s business.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
We’d genuinely rather write the other report: the one where a bad actor goes legit. The door stays open and we’d take that story gladly.
Maskify/Earnify isn’t it. Since April it forked into a proxy-only SDK and a standalone Linux DDoS bot, now flooding Ukrainian ISPs (Triolan, Kyivstar), Russian scrubbing providers, game servers, and, inevitably, Krebs.
Our latest: https://github.com/deepfield/public-research/blob/main/maskify/report-2026-07-04-two-fleets.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
AsconBot
Novel multi-arch DDoS bot via ADB — ASCON-128 AEAD + key-ratchet C2
C2: 168.220.248[.]106:24032 (live)
SHA256: 96f926f634fe67a384d577612157472f7aae9db5c0651730dc9d98360b9e8766
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Somebody sat down and wrote a from-scratch QUIC client for a DDoS bot. No WolfSSL, no mbedTLS, nothing off the shelf: TLS 1.3, QUIC v1, HTTP/3, all hand-rolled.
A more complete QUIC stack than some things you installed on purpose.
Then it validates zero certificates.
New ERT report on Vibenet, aka Heilong: https://github.com/deepfield/public-research/blob/main/vibenet/report.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
New, from our ERT: what happens when you disconnect from that free VPN app, loaded with a residential proxy SDK that talks to the Vo1d/Popa infrastructure.
https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
New report: #kbotne, or: Mirai learns WebSocket, naturally calls it /connectlol
Standard RFC 6455 upgrade on port 80, which is novel for a Mirai fork.
Everything around it is less careful: hex-encoded config strings recoverable with xxd, a process killer that mostly recognizes its own binaries, and persistence that writes itself to `/.kbotne/kbotne`. Stealth was not the design goal.
https://github.com/deepfield/public-research/blob/main/kbotne/report.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
New report: #Datasurge, a rogue EDR agent with a DDoS module.
Mirai fork organized around retention, not acquisition. The operator exploits ADB, then lets a scanner/killer module ensure nothing else gets to run. (It's larger than the DDoS engine.)
Entropy heuristic, inotify watcher, directory lockdown, and a C2 toggle so the operator can briefly lower the drawbridge to deploy updates.
The config table cipher is ROT13 followed by single-byte XOR; the PRNG is seeded through a ChaCha-like init routine. Someone had priorities.
https://github.com/deepfield/public-research/blob/main/datasurge/report.md
(building on prior research from GHOST / Breakglass Intelligence)
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
#TerraBot: first #DDoS botnet we've seen carrying a working exploit for CVE-2026-0073 (Critical ADB auth bypass, patched May 2026).
Every other ADB botnet needs auth disabled; this one doesn't. Comes with 30+ methods + dual APK/ELF cross-platform worming.
C2: terrabot.qzz[.]io:69
Staging: 140.233.190[.]47 (AS214209)
hash: a532a072687f5bd6f8f4c2fb1ce899a5d3c4264453fe2e7bafc270e83661c893
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Potassium update: the Mirai fork @synthient@infosec.exchange reported in March (https://x.com/deobfuscately/status/2033923869782712514) is still active and the operator appears to have taken up Dutch poetry. The new C2 domain is ikhebkankerinmijnrechterteelbal[.]st (would not recommend pasting that into Google Translate during standup.)
Same key material and HTTP C2 protocol as the original potassium.vitacoco...[.]st variant. 11-port random C2 rotation, spreading via ADB to Android TV boxes.
IoCs:
a87aa7995ee9996952edb323d703875812f71d08237756ab44367f10e6197c7e
6833cb4681ac69281474be2c626df06cd90bb05bec72ae697cf219a6603826c9
3f13e18e190a7fc4c795d7caa83534d2879376ce43fd1a9120f23e48639cfe85
C2: ikhebkankerinmijnrechterteelbal[.]st → byte-swapped → 45.153.34[.]245
Dropper: 92.38.186[.]44 (HTTP + netcat :25565)
edit: added byte-swapped C2 value
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Latest report from our ERT on another proxy/ADB-based botnet: #Maskify
https://github.com/deepfield/public-research/blob/main/maskify/report.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Most Mirai forks are disposable. #Jackskid was built not to be.
Joint research with Comcast Threat Research Labs — we tracked this botnet across 80+ samples and 13 build generations as it evolved from a bare-bones prototype into a dual-vector Android TV/IoT platform with triple-layer encryption and DNS-over-HTTPS C2.
Report and IoCs: https://github.com/deepfield/public-research/blob/main/jackskid/report.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
ICYMI: a story about pulling one thread linking multiple botnets — four of which were targeted by coordinated law enforcement actions this week, and an adjacent one for which our team publishes the C2 decryption scheme.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Yesterday, the U.S. Department of Justice announced a coordinated international operation to disrupt four of the world's largest IoT DDoS botnets — Aisuru, Kimwolf, Jackskid, and Mossad — responsible for record-breaking attacks reaching approximately 30 Tbps.
Together, these botnets had hijacked over three million devices worldwide and launched hundreds of thousands of DDoS attacks against victims across the globe.
This was a massive collaborative effort involving law enforcement agencies in the U.S., Canada, and Europe, alongside many private-sector partners. We're proud that Nokia was among the companies that contributed — our Deepfield Emergency Response Team helped map botnet infrastructure and supported the takedown efforts.
Full DOJ press release: https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Excellent work by @nicter_jp@bird.makeup documenting a Xiongmai DVR campaign deploying residential proxy SDKs: https://blog.nicter.jp/2026/03/iot_proxyware/
We pulled the payloads and decompiled the chain.
The downloader is Mirai with all DDoS stripped out — repurposed as a vehicle for proxy monetization. It delivers two proxy SDKs: IPRoyal Pawns and PacketSDK, part of the IPIDEA network Google disrupted in January.
NICTER's IOC timeline tells the rest: PacketSDK v1.0.2 (original domains) → v1.0.6 (scrambled replacements) → v1.0.8.4 (single fallback) → not deployed. Every dispatch path is now NXDOMAIN.
A concrete view of Google's takedown continuing to have impact.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Why bother with n-day exploits when a residential proxy subscription gives you unauthenticated root shell on tens of millions of Android TV devices?
Our new ERT report on the #Katana botnet documents 30K+ bots, an on-device compiled kernel rootkit, and almost certainly more engineering effort in persistence than the devices received in firmware support.
https://github.com/deepfield/public-research/blob/main/katana/report.md
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
New deployment: @hetzner@mastodon.hetzner.social is strengthening #DDoS protection across its European data center infrastructure with Deepfield Defender; a great choice by one of Europe's leading hosting providers.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
We reached a point with #DDoS attacks are now affecting shared infrastructure — well beyond the intended targets.
Read on to learn about why networks need to address outbound DDoS traffic, and to build defenses as part of the network.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Nothing says "controlled chaos" like a live DDoS demo where the attacker literally has paperwork from the Ministry of Finance.
(And yes, this is in-line Layer 2 mitigation on a live network.)
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
Bots associated with this botnet can typically be recognized by distinctive hexadecimal banners featuring strings such as head[...]1111 or head[...]11111111, predominantly appearing on TCP port 17000.
Since its initial detection, our ERT has closely monitored the activities and growth of #Eleven11bot . Early assessments indicate a large and geographically distributed botnet presence, spanning multiple countries such as the United States, Canada, Israel, Spain, the United Kingdom, Brazil, Taiwan, Romania, and Japan, among others.
Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.
On 26 February 2025, the Nokia Deepfield Emergency Response Team (ERT) identified a significant new DDoS botnet, now tracked under #Eleven11bot
Primarily composed of compromised webcams and Network Video Recorders (NVRs), this botnet has rapidly grown to exceed 30,000 devices. Its size is exceptional among non-state actor botnets, making it one of the largest known DDoS botnet campaigns observed since the invasion of Ukraine in February 2022.
Eleven11bot has targeted diverse sectors, including communications service providers and gaming hosting infrastructure, leveraging a variety of attack vectors. Attack intensity has varied widely, ranging from a few hundred thousand to several hundred million packets per second (pps). Public forums report sustained attack campaigns causing service degradation lasting multiple days, some of which remain ongoing.