Chalubo
Aliases: ChaChaDDoS
- First seen
- 2018-09-01 00:00:00
- Malware type
- botnet, ddos
- Family
- Malware family
- Last IoC activity
- 2026-06-26 08:37:17
- Profile updated
- 2026-07-07 14:23:37
Context
Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua. Variants exist for multiple architectures and it incorporates code from XorDDoS and Mirai.
Detection coverage
- 1 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Linux_Chachaddos (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Chalubo (report)
- blog.lumen.com — The Pumpkin Eclipse (report)
- news.sophos.com — Chalubo Botnet Wants To Ddos From Your Server Or Iot Device (report)
- blog.centurylink.com — The Pumpkin Eclipse (report)