Netskope Threat Labs

XorDDoS

ATP Sandbox Adv. HeuristicsAV

XorDDoS is a DDoS botnet that targets Linux devices and has been active since 2014, when researchers first documented the family in campaigns linked to China. Its namesake XOR encryption hides its strings and configuration from casual analysis, and some builds hid themselves further with an embedded rootkit. The botnet has targeted exposed Docker servers as well as general Linux hosts, and researchers have ranked it among the most prevalent Linux malware families.

First seen
May 2022
Last seen
October 2026
XORDDoSXorDDoSRootkitXorddos
Alert Name
Gen:Variant.Trojan.Linux.XorDDoS.2
Linux.Backdoor.XorDDoS
Linux.Backdoor.XorDDoSRootkit
Linux.Network.Xorddos
Linux.Network.XorDDoS
Linux.Ransomware.XorDDoS
Linux.Trojan.XorDDoS
Trojan.Linux.Xorddos.2
Trojan.Linux.Xorddos.4
Trojan.Linux.XORDDoS.AU