Description
XorDDoS is a DDoS botnet that targets Linux devices and has been active since 2014, when researchers first documented the family in campaigns linked to China. Its namesake XOR encryption hides its strings and configuration from casual analysis, and some builds hid themselves further with an embedded rootkit. The botnet has targeted exposed Docker servers as well as general Linux hosts, and researchers have ranked it among the most prevalent Linux malware families.
Stats
- First seen
- May 2022
- Last seen
- October 2026
Also known as
XORDDoSXorDDoSRootkitXorddos
Alert name variants
| Alert Name |
|---|
| Gen:Variant.Trojan.Linux.XorDDoS.2 |
| Linux.Backdoor.XorDDoS |
| Linux.Backdoor.XorDDoSRootkit |
| Linux.Network.Xorddos |
| Linux.Network.XorDDoS |
| Linux.Ransomware.XorDDoS |
| Linux.Trojan.XorDDoS |
| Trojan.Linux.Xorddos.2 |
| Trojan.Linux.Xorddos.4 |
| Trojan.Linux.XORDDoS.AU |