Honeypot capture
Go DDoS botnet
VT 40/74C2 live
Fifteen attack methods, compiled from Go and shipped as a multi-architecture dropper suite. It spreads over SSH, carries IoT scanner exploits and layered persistence, and fronts a self-serve, account-gated API through which customers order attacks.
- Family
- Go DDoS botnet
- First seen
- June–July 2026
- Vector
- Jenkins Script Console RCE
- Format
- 6.25 MB PE32+ x86-64 + multi-arch ELF variants (Go)
- VirusTotal
- 40 engines: trojan.gorat/flooder; three distinct builds captured
- Tags
- ddos · botnet · golang · jenkins · iot
- Reports
- A cross-platform Go DDoS botnet-for-hire
Inside a gaming DDoS-for-hire operation - Sample
- By request. Email [email protected]
SHA-256
-
6da756970a411dade9db3c921ef4cdade550f317703d0fc12090a15d8c6778d4Windows PE build