Dofloo

Aliases: AESDDoS, Dofloo

First seen
2014-01-01 00:00:00
Malware type
botnet, ddos, cryptominer
Family
Malware family
Last IoC activity
2026-07-18 22:28:39
Profile updated
2026-07-07 14:22:07

Targeted industries: energy-and-utilities financial-services technology-and-telecommunications

Context

Dofloo (aka AESDDoS) is a popular malware used to create large scale botnets that can launch DDoS attacks and load cryptocurrency miners to the infected machines.

Reports & references

  • virusbulletin.com — Kalnaihorejsi Vb2015 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Dofloo (report)
  • Trend Micro — Aesddos Botnet Malware Infiltrates Containers Via Exposed Docker Apis (report)
  • digital.nhs.uk — Cc 3043 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Mrblack (report)
  • news.drweb.com (report)
  • bleepingcomputer.com — Exposed Docker Apis Abused By Ddos Cryptojacking Botnet Malware (report)
  • botconf.eu — Ok P13 Liu Ya Automatically Classify Unknown Bots By The Register Messages (report)
  • blog.syscall.party — Aes Ddos Analysis Part 1 (report)

External references