216.73.216.226

Attacks Targeting Linux SSH Servers to Install SVF DDoS Bot

· Published 20/08/2025 10:50 · Modified 20/08/2025 12:48

Export JSON

Essential information

Published
20/08/2025 10:50
Modified
20/08/2025 12:48
Tags
2025-08-20 brute-force ddos dictionary attack discord linux proxy servers ssh svf bot svf botnet
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 2 malware

Description

A recent attack on poorly managed servers has been identified, involving the installation of , a Bot malware developed in Python. The malware uses as its C&C server and employs multiple for attacks. The threat actor gains access through weak credentials and installs the bot using specific commands. supports various attack methods, primarily L7 HTTP Flood and L4 UDP Flood. It uniquely utilizes public proxy addresses for HTTP flood attacks, enhancing its effectiveness. The malware can receive commands from the threat actor, turning infected servers into Bots. To protect against such attacks, administrators are advised to use strong passwords, regularly update systems, and implement security measures like firewalls.

External references