<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ddos on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ddos/</link><description>Recent content in Ddos on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 17 Aug 2026 11:37:07 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ddos/index.xml" rel="self" type="application/rss+xml"/><item><title>Large-scale DDoS attacks disrupt Threema messaging service</title><link>https://curasec.metacog.co.kr/insights/2026-08-17-large-scale-ddos-attacks-disrupted-threema-secure-messaging/</link><pubDate>Mon, 17 Aug 2026 11:37:07 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-17-large-scale-ddos-attacks-disrupted-threema-secure-messaging/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> DDoS campaign against a privacy-focused messaging platform; no IOCs or TTPs published, so no detection work is actionable, but useful context if your organization uses Threema or monitors availability-based attacks.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Kimwolf v7 Android/IoT Botnet Camouflages HTTP/2 DDoS as Legit Traffic</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-kimwolf-v7-android-botnet-makes-http-2-ddos-traffic-look-lik/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-kimwolf-v7-android-botnet-makes-http-2-ddos-traffic-look-lik/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> The HTTP/2 traffic-mimicry technique is worth understanding when reviewing WAF and CDN rate-limiting rules, but no enrichment signals (no KEV, no PoC, no active targeting) justify an immediate configuration change.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The botnet&amp;rsquo;s ability to blend DDoS volume into legitimate-looking HTTP/2 sessions is a detection gap worth scoping — review whether your traffic-analysis and DDoS-detection rules distinguish request-rate anomalies at the HTTP/2 stream level rather than relying on IP reputation alone.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Awareness item for the evolving DDoS evasion landscape; relevant background for the next DDoS-mitigation vendor review or business-continuity risk discussion, but no board-level action is warranted now.&lt;/li>
&lt;/ul></description></item><item><title>Dysphoria DDoS Botnet Compromises 200k Devices Globally</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No KEV, PoC, or EPSS signal provided; no specific vulnerability or affected software named in the summary. Monitor for follow-up reporting with exploitation details or affected device types that may be in your estate.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> A 200k-node botnet generating DDoS and relay traffic is worth building or tuning detections for — watch for follow-up IOC releases and prepare to hunt for anomalous outbound traffic patterns consistent with botnet C2 or relay behavior.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Awareness-level item for now; if your organization relies on internet-facing services, DDoS resilience posture is worth a periodic review but this report lacks specifics that would require immediate leadership action.&lt;/li>
&lt;/ul></description></item><item><title>Dysphoria IoT Botnet Adopts Blockchain C2 After JackSkid Takedown</title><link>https://curasec.metacog.co.kr/insights/2026-07-28-dysphoria-iot-botnet-adds-blockchain-c2-and-victim-relays-af/</link><pubDate>Tue, 28 Jul 2026 13:01:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-28-dysphoria-iot-botnet-adds-blockchain-c2-and-victim-relays-af/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Blockchain-based C2 and peer-relay architecture represent an evasion technique relevant to defenders running IoT-adjacent infrastructure, but there are no specific CVEs, affected products, or actionable mitigations named here.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The shift to blockchain name services and victim-device relays changes the detection model for this botnet family; build or tune detections for anomalous outbound connections to blockchain resolvers and unexpected device-to-device relay traffic in your estate.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Useful context on botnet resilience trends following law-enforcement disruptions, but no immediate vendor exposure or board-level risk event is indicated here.&lt;/li>
&lt;/ul></description></item><item><title>148 Malicious npm Packages Weaponized Browsers as DDoS Botnet</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-148-npm-packages-disguised-as-student-proxies-turned-browser/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-148-npm-packages-disguised-as-student-proxies-turned-browser/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Novel abuse of npm as free hosting infrastructure to serve malicious browser-side JavaScript to site visitors rather than targeting package consumers directly; review whether your org hosts any user-facing content via npm and revisit supply-chain threat models to include registry-as-CDN attack patterns.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or ATT&amp;amp;CK-mapped TTPs are published from this research, so there is nothing actionable to hunt or detect today; file as a reference technique — browser-based DDoS recruited via malicious proxy sites — for future detection engineering when lure sites targeting your sector emerge.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>