Dofloo
Aliases: AESDDoS, Dofloo
- First seen
- 2014-01-01 00:00:00
- Malware type
- botnet, ddos, cryptominer
- Family
- Malware family
- Last IoC activity
- 2026-07-18 22:28:39
- Profile updated
- 2026-07-07 14:22:07
Targeted industries: energy-and-utilities financial-services technology-and-telecommunications
Context
Dofloo (aka AESDDoS) is a popular malware used to create large scale botnets that can launch DDoS attacks and load cryptocurrency miners to the infected machines.
Reports & references
- virusbulletin.com — Kalnaihorejsi Vb2015 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Dofloo (report)
- Trend Micro — Aesddos Botnet Malware Infiltrates Containers Via Exposed Docker Apis (report)
- digital.nhs.uk — Cc 3043 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Mrblack (report)
- news.drweb.com (report)
- bleepingcomputer.com — Exposed Docker Apis Abused By Ddos Cryptojacking Botnet Malware (report)
- botconf.eu — Ok P13 Liu Ya Automatically Classify Unknown Bots By The Register Messages (report)
- blog.syscall.party — Aes Ddos Analysis Part 1 (report)