Chalubo

Aliases: ChaChaDDoS

First seen
2018-09-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Last IoC activity
2026-06-26 08:37:17
Profile updated
2026-07-07 14:23:37

Context

Sophos describes this malware as a DDoS bot, with its name originating from ChaCha-Lua-bot due to its use of ChaCha cipher and Lua. Variants exist for multiple architectures and it incorporates code from XorDDoS and Mirai.

Detection coverage

  • 1 YARA rules

Detection rules

  • DITEKSHEN_MALWARE_Linux_Chachaddos (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Chalubo (report)
  • blog.lumen.com — The Pumpkin Eclipse (report)
  • news.sophos.com — Chalubo Botnet Wants To Ddos From Your Server Or Iot Device (report)
  • blog.centurylink.com — The Pumpkin Eclipse (report)

External references