Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Nokia Deepfield

@deepfield@infosec.exchange
  • Open on infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

81 Followers
18 Following
26 Posts
Joined March 01, 2025
Website:
https://www.nokia.com/ip-networks/deepfield/
Gravatar:
https://gravatar.com/universallypandace44e4c96b

Posts

Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jul 24, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
New, from our ERT: Most residential proxy malware hides the exit behind an outbound tunnel. This one has the victim’s own router open 165 ports over UPnP and labels every mapping RELAY. Telemetry on the proxy domains led us back to #Jackskid, a DDoS botnet we have tracked since late 2025. Same operator behind all of it: a pure relay family, a Mirai bot that moonlights as one, and Jackskid, which now compiles the relay straight in. https://github.com/deepfield/public-research/blob/main/reports/2026-07-24-jackskid-residential-proxy-upnp.md #threatintel #tree4sale #peer4you
4
0
2
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jul 21, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
New ERT report: #IranBot is a botnet built to be thrown away. Three builds in six weeks, no infrastructure reused, each one cruder and each one reaching further. The build stripped of encryption is the one worming today, and its C2 outlives none of the others by much. https://github.com/deepfield/public-research/blob/main/iranbot/report.md #threatintel #DDoS
0
0
0
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jul 11, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

New, from our ERT: https://github.com/deepfield/public-research/blob/main/ipmoyu/report.md

The APK is clean. No sample would have tipped us off; the traffic did.

A DNS hunt on networks we protect flagged devices beaconing to an unlisted BADBOX C2. We pivoted on the shared infrastructure to a free IPTV app dropping a residential-proxy exit node. Skip the cable bill, get a tenant.

The ERT tracks DDoS, not IPTV (though Deepfield does track video for analytics). But an exit node isn’t video. It’s a TV dialing out, minding its business. Someone else’s business.

#threatintel #badbox #moyu

GitHub

public-research/ipmoyu/report.md at main · deepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT - deepfield/public-research

1
0
1
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jul 05, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
DDoSia is one of the least interesting botnets we track. We wrote it up anyway. Its product was never downtime. It’s the claim of downtime. We looked at the actual traffic. The honest version is boring. And boring is the one story the group can’t turn into a win. New from our ERT: https://github.com/deepfield/public-research/blob/main/ddosia/report.md #threatintel #NoName057
1
0
2
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jul 04, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

We’d genuinely rather write the other report: the one where a bad actor goes legit. The door stays open and we’d take that story gladly.

Maskify/Earnify isn’t it. Since April it forked into a proxy-only SDK and a standalone Linux DDoS bot, now flooding Ukrainian ISPs (Triolan, Kyivstar), Russian scrubbing providers, game servers, and, inevitably, Krebs.

Our latest: https://github.com/deepfield/public-research/blob/main/maskify/report-2026-07-04-two-fleets.md

#threatintel #DDoS

GitHub

public-research/maskify/report-2026-07-04-two-fleets.md at main · deepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT - deepfield/public-research

3
0
1
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 24, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

AsconBot

Novel multi-arch DDoS bot via ADB — ASCON-128 AEAD + key-ratchet C2

C2: 168.220.248[.]106:24032 (live)

SHA256: 96f926f634fe67a384d577612157472f7aae9db5c0651730dc9d98360b9e8766

#threatintel #malware #iocs

0
0
2
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 23, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Somebody sat down and wrote a from-scratch QUIC client for a DDoS bot. No WolfSSL, no mbedTLS, nothing off the shelf: TLS 1.3, QUIC v1, HTTP/3, all hand-rolled.

A more complete QUIC stack than some things you installed on purpose.

Then it validates zero certificates.

New ERT report on Vibenet, aka Heilong: https://github.com/deepfield/public-research/blob/main/vibenet/report.md

#DDoS #threatintel

GitHub

public-research/vibenet/report.md at main · deepfield/public-research

DDoS botnet research and indicators of compromise from Nokia Deepfield ERT - deepfield/public-research

1
0
1
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 18, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

New, from our ERT: what happens when you disconnect from that free VPN app, loaded with a residential proxy SDK that talks to the Vo1d/Popa infrastructure.

https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md

#threatintel #popa

1
3
1
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 04, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

New report: #kbotne, or: Mirai learns WebSocket, naturally calls it /connectlol

Standard RFC 6455 upgrade on port 80, which is novel for a Mirai fork.

Everything around it is less careful: hex-encoded config strings recoverable with xxd, a process killer that mostly recognizes its own binaries, and persistence that writes itself to `/.kbotne/kbotne`. Stealth was not the design goal.

https://github.com/deepfield/public-research/blob/main/kbotne/report.md

#threatintel #DDoS

infosec.exchange

Infosec Exchange

1
0
1
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 04, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

New report: #Datasurge, a rogue EDR agent with a DDoS module.

Mirai fork organized around retention, not acquisition. The operator exploits ADB, then lets a scanner/killer module ensure nothing else gets to run. (It's larger than the DDoS engine.)

Entropy heuristic, inotify watcher, directory lockdown, and a C2 toggle so the operator can briefly lower the drawbridge to deploy updates.

The config table cipher is ROT13 followed by single-byte XOR; the PRNG is seeded through a ChaCha-like init routine. Someone had priorities.

https://github.com/deepfield/public-research/blob/main/datasurge/report.md

(building on prior research from GHOST / Breakglass Intelligence)

#threatintel

0
0
2
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 01, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

#TerraBot: first #DDoS botnet we've seen carrying a working exploit for CVE-2026-0073 (Critical ADB auth bypass, patched May 2026).

Every other ADB botnet needs auth disabled; this one doesn't. Comes with 30+ methods + dual APK/ELF cross-platform worming.

C2: terrabot.qzz[.]io:69
Staging: 140.233.190[.]47 (AS214209)
hash: a532a072687f5bd6f8f4c2fb1ce899a5d3c4264453fe2e7bafc270e83661c893

#threatintel

infosec.exchange

Infosec Exchange

3
0
4
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · May 01, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Potassium update: the Mirai fork @synthient@infosec.exchange reported in March (https://x.com/deobfuscately/status/2033923869782712514) is still active and the operator appears to have taken up Dutch poetry. The new C2 domain is ikhebkankerinmijnrechterteelbal[.]st (would not recommend pasting that into Google Translate during standup.)

Same key material and HTTP C2 protocol as the original potassium.vitacoco...[.]st variant. 11-port random C2 rotation, spreading via ADB to Android TV boxes.

IoCs:

a87aa7995ee9996952edb323d703875812f71d08237756ab44367f10e6197c7e
6833cb4681ac69281474be2c626df06cd90bb05bec72ae697cf219a6603826c9
3f13e18e190a7fc4c795d7caa83534d2879376ce43fd1a9120f23e48639cfe85

C2: ikhebkankerinmijnrechterteelbal[.]st → byte-swapped → 45.153.34[.]245
Dropper: 92.38.186[.]44 (HTTP + netcat :25565)

#mirai #DDoS #threatintel

edit: added byte-swapped C2 value

infosec.exchange

Synthient (@synthient@infosec.exchange) - Infosec Exchange

0
1
1
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Apr 12, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

RE: @jmeyer@infosec.exchange

Latest report from our ERT on another proxy/ADB-based botnet: #Maskify

https://github.com/deepfield/public-research/blob/main/maskify/report.md

0
0
0
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 24, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Most Mirai forks are disposable. #Jackskid was built not to be.

Joint research with Comcast Threat Research Labs — we tracked this botnet across 80+ samples and 13 build generations as it evolved from a bare-bones prototype into a dual-vector Android TV/IoT platform with triple-layer encryption and DNS-over-HTTPS C2.

Report and IoCs: https://github.com/deepfield/public-research/blob/main/jackskid/report.md

#threatintel #ddos

infosec.exchange

Infosec Exchange

3
0
3
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 21, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

RE: @jmeyer@infosec.exchange

ICYMI: a story about pulling one thread linking multiple botnets — four of which were targeted by coordinated law enforcement actions this week, and an adjacent one for which our team publishes the C2 decryption scheme.

#aisuru #kimwolf #mossad #jackskid #cecilio

infosec.exchange

Jérôme Meyer: "One custom RC4 seed led us to four botnets, five …" - Infosec Exchange

2
0
0
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 20, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Yesterday, the U.S. Department of Justice announced a coordinated international operation to disrupt four of the world's largest IoT DDoS botnets — Aisuru, Kimwolf, Jackskid, and Mossad — responsible for record-breaking attacks reaching approximately 30 Tbps.

Together, these botnets had hijacked over three million devices worldwide and launched hundreds of thousands of DDoS attacks against victims across the globe.

This was a massive collaborative effort involving law enforcement agencies in the U.S., Canada, and Europe, alongside many private-sector partners. We're proud that Nokia was among the companies that contributed — our Deepfield Emergency Response Team helped map botnet infrastructure and supported the takedown efforts.

Full DOJ press release: https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks

#operationpoweroff

2
0
2
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 19, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Excellent work by @nicter_jp@bird.makeup documenting a Xiongmai DVR campaign deploying residential proxy SDKs: https://blog.nicter.jp/2026/03/iot_proxyware/

We pulled the payloads and decompiled the chain.

The downloader is Mirai with all DDoS stripped out — repurposed as a vehicle for proxy monetization. It delivers two proxy SDKs: IPRoyal Pawns and PacketSDK, part of the IPIDEA network Google disrupted in January.

NICTER's IOC timeline tells the rest: PacketSDK v1.0.2 (original domains) → v1.0.6 (scrambled replacements) → v1.0.8.4 (single fallback) → not deployed. Every dispatch path is now NXDOMAIN.

A concrete view of Google's takedown continuing to have impact.

https://github.com/deepfield/public-research/blob/main/reports/2026-03-19-xiongmai-packetsdk-ipidea.md

#Mirai #IPIDEA #threatintel

bird.makeup

bird.makeup - User

0
0
0
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 17, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Why bother with n-day exploits when a residential proxy subscription gives you unauthenticated root shell on tens of millions of Android TV devices?

Our new ERT report on the #Katana botnet documents 30K+ bots, an on-device compiled kernel rootkit, and almost certainly more engineering effort in persistence than the devices received in firmware support.

https://github.com/deepfield/public-research/blob/main/katana/report.md

#DDoS #threatintel

infosec.exchange

Infosec Exchange

0
0
2
1
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 16, 2026
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

New deployment: @hetzner@mastodon.hetzner.social is strengthening #DDoS protection across its European data center infrastructure with Deepfield Defender; a great choice by one of Europe's leading hosting providers.

https://hetzner.com/pressroom/nokia-network-security/

mastodon.hetzner.social

Hetzner (@hetzner@mastodon.hetzner.social) - Hetzner Mastodon

2
0
1
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Oct 23, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

We reached a point with #DDoS attacks are now affecting shared infrastructure — well beyond the intended targets.

Read on to learn about why networks need to address outbound DDoS traffic, and to build defenses as part of the network.

https://www.nokia.com/blog/the-internet-commons-under-siege-why-33-tbps-ddos-attacks-are-everyones-problem/

infosec.exchange

Infosec Exchange

6
2
4
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jul 25, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

Nothing says "controlled chaos" like a live DDoS demo where the attacker literally has paperwork from the Ministry of Finance.

(And yes, this is in-line Layer 2 mitigation on a live network.)

https://www.youtube.com/watch?v=BxsEaXUT94k

Live Anti-DDoS Demo by NL-ix: Nokia Deepfield Defender in Action
YouTube

Live Anti-DDoS Demo by NL-ix: Nokia Deepfield Defender in Action

Packet Pushers

0
0
0
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Jun 30, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
Replying to @deepfield@infosec.exchange
Quick nod to the brilliant folks at @nicter_jp@bird.makeup and @xlab_qax@bird.makeup: their latest research shows #Eleven11bot is really the next #Rapperbot evolution, leveraging a brand‑new device family. Teamwork in action 👉 https://blog.nicter.jp/2025/06/rapperbot_2025_2g/ | https://blog.xlab.qianxin.com/rapperbot-en/
1
0
0
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 01, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
Replying to @deepfield@infosec.exchange
We'd like to really thank the folks over at @greynoise@infosec.exchange and @censys@infosec.exchange for providing additional insights and context: https://www.greynoise.io/blog/new-ddos-botnet-discovered #threatintel #Eleven11bot
8
0
3
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 01, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
Replying to @deepfield@infosec.exchange
In scenarios involving maximum bot activation, #Eleven11bot is capable of launching volumetric DDoS attacks exceeding several hundred million packets per second across certain vectors. Most observed attacks, however, involve fewer devices—typically between 3,000 and 5,000 bots—but still represent a substantial threat to network reliability and service continuity.
1
2
1
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 01, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange
Replying to @deepfield@infosec.exchange

Bots associated with this botnet can typically be recognized by distinctive hexadecimal banners featuring strings such as head[...]1111 or head[...]11111111, predominantly appearing on TCP port 17000.

Since its initial detection, our ERT has closely monitored the activities and growth of #Eleven11bot . Early assessments indicate a large and geographically distributed botnet presence, spanning multiple countries such as the United States, Canada, Israel, Spain, the United Kingdom, Brazil, Taiwan, Romania, and Japan, among others.

2
1
2
0
Open post
deepfield
Nokia Deepfield @deepfield@infosec.exchange · Mar 01, 2025
Nokia Deepfield
@deepfield@infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

infosec.exchange

On 26 February 2025, the Nokia Deepfield Emergency Response Team (ERT) identified a significant new DDoS botnet, now tracked under #Eleven11bot

Primarily composed of compromised webcams and Network Video Recorders (NVRs), this botnet has rapidly grown to exceed 30,000 devices. Its size is exceptional among non-state actor botnets, making it one of the largest known DDoS botnet campaigns observed since the invasion of Ukraine in February 2022.

Eleven11bot has targeted diverse sectors, including communications service providers and gaming hosting infrastructure, leveraging a variety of attack vectors. Attack intensity has varied widely, ranging from a few hundred thousand to several hundred million packets per second (pps). Public forums report sustained attack campaigns causing service degradation lasting multiple days, some of which remain ongoing.

infosec.exchange

Infosec Exchange

4
4
1
0

Remote instance

infosec.exchange
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 04:18:15 UTC