XOR DDoS
Aliases: XORDDOS
- First seen
- 2014-09-01 00:00:00
- Malware type
- ddos, botnet
- Family
- Malware family
- Last IoC activity
- 2026-07-22 00:36:15
- Profile updated
- 2026-07-07 14:22:12
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications education-and-nonprofits
Context
XOR DDoS is a Linux-based malware family known for launching DDoS attacks. It primarily targets Linux systems and utilizes XOR-based encryption to evade detection. It is often used in botnet operations to perform coordinated DDoS attacks against targeted networks.
Detection coverage
- 3 YARA rules
Detection rules
- DITEKSHEN_MALWARE_Linux_Chachaddos (yara-rule)
- DITEKSHEN_MALWARE_Linux_Xorddos (yara-rule)
- SEKOIA_Bot_Lin_Xorddos_Strings (yara-rule)
Reports & references
- virusbulletin.com — Kalnaihorejsi Vb2015 (report)
- Trend Micro — Xorddos Kaiji Botnet Malware Variants Target Exposed Docker Servers (report)
- ibm.com — Wmdzowk6 (report)
- CrowdStrike — Linux Targeted Malware Increased By 35 Percent In 2021 (report)
- botconf.eu — Ok P13 Liu Ya Automatically Classify Unknown Bots By The Register Messages (report)
- blackberry.com — Pdfviewer (report)
- intezer.com — New Linux Backdoor Redxor Likely Operated By Chinese Nation State Actor (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Xorddos (report)
- Wikipedia — Xor Ddos (report)
- blog.checkpoint.com — Sb Report Threat Intelligence Groundhog (report)
- blog.nsfocusglobal.com — Analysis Report Of The Xorddos Malware Family (report)
- Mandiant — Anatomy Of A Brutef (report)
- lacework.com — Groundhog Botnet Rapidly Infecting Cloud (report)
- blog.avast.com — Linux Ddos Trojan Hiding Itself With An Embedded Rootkit (report)
- Cisco Talos — Unmasking The New Xorddos Controller And Infrastructure (report)
- maxkersten.nl — Ghidra Script To Decrypt A String Array In Xor Ddos (report)
- Microsoft — Rise In Xorddos A Deeper Look At The Stealthy Ddos Malware Targeting Linux Devices (report)
- bartblaze.blogspot.com — Notes On Linuxxorddos (report)
- blog.malwaremustdie.org — Mmd 0028 2014 Fuzzy Reversing New China (report)