Kamasers
- Malware type
- botnet, backdoor, ddos
- Family
- Malware family
- Profile updated
- 2026-07-07 15:07:59
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
Kamasers is a DDOS botnet. The bot has backdoor capabilities as it connects to an attacker controller C2 server. This allows it to download files, receive commands, and execute files, allowing it to perform HTTP and DNS flooding attacks. The bot is also used to access sensitive files. The bot has been seen to be communicating with third-party platforms such as Telegram, Discord, and GitHub, using these platforms as backup C2 servers.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Kamasers_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Kamasers (report)
- x.com — 1971574897521336553 (report)
- any.run — Kamasers Technical Analysis (report)