Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Nokia Deepfield

@deepfield@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Deepfield, part of Nokia since 2017, delivers advanced network analytics and real-time DDoS protection to secure global networks.

81 Followers
18 Following
27 Posts
Joined March 01, 2025
Website:
https://www.nokia.com/ip-networks/deepfield/
Gravatar:
https://gravatar.com/universallypandace44e4c96b
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 2mo ago
New, from our ERT: Most residential proxy malware hides the exit behind an outbound tunnel. This one has the victim’s own router open 165 ports over UPnP and labels every mapping RELAY. Telemetry on the proxy domains led us back to #Jackskid, a DDoS botnet we have tracked since late 2025. Same operator behind all of it: a pure relay family, a Mirai bot that moonlights as one, and Jackskid, which now compiles the relay straight in. https://github.com/deepfield/public-research/blob/main/reports/2026-07-24-jackskid-residential-proxy-upnp.md #threatintel #tree4sale #peer4you
github.com
4
0
2
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 3mo ago

We’d genuinely rather write the other report: the one where a bad actor goes legit. The door stays open and we’d take that story gladly.

Maskify/Earnify isn’t it. Since April it forked into a proxy-only SDK and a standalone Linux DDoS bot, now flooding Ukrainian ISPs (Triolan, Kyivstar), Russian scrubbing providers, game servers, and, inevitably, Krebs.

Our latest: https://github.com/deepfield/public-research/blob/main/maskify/report-2026-07-04-two-fleets.md

#threatintel #DDoS

github.com
3
0
1
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 4mo ago

#TerraBot: first #DDoS botnet we've seen carrying a working exploit for CVE-2026-0073 (Critical ADB auth bypass, patched May 2026).

Every other ADB botnet needs auth disabled; this one doesn't. Comes with 30+ methods + dual APK/ELF cross-platform worming.

C2: terrabot.qzz[.]io:69
Staging: 140.233.190[.]47 (AS214209)
hash: a532a072687f5bd6f8f4c2fb1ce899a5d3c4264453fe2e7bafc270e83661c893

#threatintel

infosec.exchange
3
0
4
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 2mo ago

New, from our ERT: https://github.com/deepfield/public-research/blob/main/ipmoyu/report.md

The APK is clean. No sample would have tipped us off; the traffic did.

A DNS hunt on networks we protect flagged devices beaconing to an unlisted BADBOX C2. We pivoted on the shared infrastructure to a free IPTV app dropping a residential-proxy exit node. Skip the cable bill, get a tenant.

The ERT tracks DDoS, not IPTV (though Deepfield does track video for analytics). But an exit node isn’t video. It’s a TV dialing out, minding its business. Someone else’s business.

#threatintel #badbox #moyu

github.com
1
0
1
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 3mo ago
DDoSia is one of the least interesting botnets we track. We wrote it up anyway. Its product was never downtime. It’s the claim of downtime. We looked at the actual traffic. The honest version is boring. And boring is the one story the group can’t turn into a win. New from our ERT: https://github.com/deepfield/public-research/blob/main/ddosia/report.md #threatintel #NoName057
github.com
1
0
2
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 3mo ago

Somebody sat down and wrote a from-scratch QUIC client for a DDoS bot. No WolfSSL, no mbedTLS, nothing off the shelf: TLS 1.3, QUIC v1, HTTP/3, all hand-rolled.

A more complete QUIC stack than some things you installed on purpose.

Then it validates zero certificates.

New ERT report on Vibenet, aka Heilong: https://github.com/deepfield/public-research/blob/main/vibenet/report.md

#DDoS #threatintel

github.com
1
0
1
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 6mo ago

Most Mirai forks are disposable. #Jackskid was built not to be.

Joint research with Comcast Threat Research Labs — we tracked this botnet across 80+ samples and 13 build generations as it evolved from a bare-bones prototype into a dual-vector Android TV/IoT platform with triple-layer encryption and DNS-over-HTTPS C2.

Report and IoCs: https://github.com/deepfield/public-research/blob/main/jackskid/report.md

#threatintel #ddos

infosec.exchange
3
0
3
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 3mo ago

New, from our ERT: what happens when you disconnect from that free VPN app, loaded with a residential proxy SDK that talks to the Vo1d/Popa infrastructure.

https://github.com/deepfield/public-research/blob/main/reports/2026-06-18-robovpn-neunative.md

#threatintel #popa

github.com
1
3
1
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 4mo ago

New report: #kbotne, or: Mirai learns WebSocket, naturally calls it /connectlol

Standard RFC 6455 upgrade on port 80, which is novel for a Mirai fork.

Everything around it is less careful: hex-encoded config strings recoverable with xxd, a process killer that mostly recognizes its own binaries, and persistence that writes itself to `/.kbotne/kbotne`. Stealth was not the design goal.

https://github.com/deepfield/public-research/blob/main/kbotne/report.md

#threatintel #DDoS

infosec.exchange
1
0
1
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 11mo ago

We reached a point with #DDoS attacks are now affecting shared infrastructure — well beyond the intended targets.

Read on to learn about why networks need to address outbound DDoS traffic, and to build defenses as part of the network.

https://www.nokia.com/blog/the-internet-commons-under-siege-why-33-tbps-ddos-attacks-are-everyones-problem/

infosec.exchange
6
2
4
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 6mo ago

RE: @jmeyer@infosec.exchange

ICYMI: a story about pulling one thread linking multiple botnets — four of which were targeted by coordinated law enforcement actions this week, and an adjacent one for which our team publishes the C2 decryption scheme.

#aisuru #kimwolf #mossad #jackskid #cecilio

infosec.exchange
2
0
0
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 6mo ago

Yesterday, the U.S. Department of Justice announced a coordinated international operation to disrupt four of the world's largest IoT DDoS botnets — Aisuru, Kimwolf, Jackskid, and Mossad — responsible for record-breaking attacks reaching approximately 30 Tbps.

Together, these botnets had hijacked over three million devices worldwide and launched hundreds of thousands of DDoS attacks against victims across the globe.

This was a massive collaborative effort involving law enforcement agencies in the U.S., Canada, and Europe, alongside many private-sector partners. We're proud that Nokia was among the companies that contributed — our Deepfield Emergency Response Team helped map botnet infrastructure and supported the takedown efforts.

Full DOJ press release: https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks

#operationpoweroff

justice.gov
2
0
2
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 6mo ago

New deployment: @hetzner@mastodon.hetzner.social is strengthening #DDoS protection across its European data center infrastructure with Deepfield Defender; a great choice by one of Europe's leading hosting providers.

https://hetzner.com/pressroom/nokia-network-security/

infosec.exchange
2
0
1
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 19mo ago
Replying to

Bots associated with this botnet can typically be recognized by distinctive hexadecimal banners featuring strings such as head[...]1111 or head[...]11111111, predominantly appearing on TCP port 17000.

Since its initial detection, our ERT has closely monitored the activities and growth of #Eleven11bot . Early assessments indicate a large and geographically distributed botnet presence, spanning multiple countries such as the United States, Canada, Israel, Spain, the United Kingdom, Brazil, Taiwan, Romania, and Japan, among others.

2
1
2
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 15mo ago
Replying to
Quick nod to the brilliant folks at @nicter_jp@bird.makeup and @xlab_qax@bird.makeup: their latest research shows #Eleven11bot is really the next #Rapperbot evolution, leveraging a brand‑new device family. Teamwork in action 👉 https://blog.nicter.jp/2025/06/rapperbot_2025_2g/ | https://blog.xlab.qianxin.com/rapperbot-en/
blog.nicter.jp
1
0
0
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 19mo ago
Replying to
In scenarios involving maximum bot activation, #Eleven11bot is capable of launching volumetric DDoS attacks exceeding several hundred million packets per second across certain vectors. Most observed attacks, however, involve fewer devices—typically between 3,000 and 5,000 bots—but still represent a substantial threat to network reliability and service continuity.
1
2
1
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 5mo ago

RE: @jmeyer@infosec.exchange

Latest report from our ERT on another proxy/ADB-based botnet: #Maskify

https://github.com/deepfield/public-research/blob/main/maskify/report.md

infosec.exchange
0
0
0
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 6mo ago

Excellent work by @nicter_jp@bird.makeup documenting a Xiongmai DVR campaign deploying residential proxy SDKs: https://blog.nicter.jp/2026/03/iot_proxyware/

We pulled the payloads and decompiled the chain.

The downloader is Mirai with all DDoS stripped out — repurposed as a vehicle for proxy monetization. It delivers two proxy SDKs: IPRoyal Pawns and PacketSDK, part of the IPIDEA network Google disrupted in January.

NICTER's IOC timeline tells the rest: PacketSDK v1.0.2 (original domains) → v1.0.6 (scrambled replacements) → v1.0.8.4 (single fallback) → not deployed. Every dispatch path is now NXDOMAIN.

A concrete view of Google's takedown continuing to have impact.

https://github.com/deepfield/public-research/blob/main/reports/2026-03-19-xiongmai-packetsdk-ipidea.md

#Mirai #IPIDEA #threatintel

blog.nicter.jp
0
0
0
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 6mo ago

Why bother with n-day exploits when a residential proxy subscription gives you unauthenticated root shell on tens of millions of Android TV devices?

Our new ERT report on the #Katana botnet documents 30K+ bots, an on-device compiled kernel rootkit, and almost certainly more engineering effort in persistence than the devices received in firmware support.

https://github.com/deepfield/public-research/blob/main/katana/report.md

#DDoS #threatintel

infosec.exchange
0
0
2
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 14mo ago

Nothing says "controlled chaos" like a live DDoS demo where the attacker literally has paperwork from the Ministry of Finance.

(And yes, this is in-line Layer 2 mitigation on a live network.)

https://www.youtube.com/watch?v=BxsEaXUT94k

0
0
0
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 2mo ago
New ERT report: #IranBot is a botnet built to be thrown away. Three builds in six weeks, no infrastructure reused, each one cruder and each one reaching further. The build stripped of encryption is the one worming today, and its C2 outlives none of the others by much. https://github.com/deepfield/public-research/blob/main/iranbot/report.md #threatintel #DDoS
github.com
0
0
0
1
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 3mo ago

AsconBot

Novel multi-arch DDoS bot via ADB — ASCON-128 AEAD + key-ratchet C2

C2: 168.220.248[.]106:24032 (live)

SHA256: 96f926f634fe67a384d577612157472f7aae9db5c0651730dc9d98360b9e8766

#threatintel #malware #iocs

infosec.exchange

Infosec Exchange

0
0
2
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 4mo ago

New report: #Datasurge, a rogue EDR agent with a DDoS module.

Mirai fork organized around retention, not acquisition. The operator exploits ADB, then lets a scanner/killer module ensure nothing else gets to run. (It's larger than the DDoS engine.)

Entropy heuristic, inotify watcher, directory lockdown, and a C2 toggle so the operator can briefly lower the drawbridge to deploy updates.

The config table cipher is ROT13 followed by single-byte XOR; the PRNG is seeded through a ChaCha-like init routine. Someone had priorities.

https://github.com/deepfield/public-research/blob/main/datasurge/report.md

(building on prior research from GHOST / Breakglass Intelligence)

#threatintel

infosec.exchange
0
0
2
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 5mo ago

Potassium update: the Mirai fork @synthient@infosec.exchange reported in March (https://x.com/deobfuscately/status/2033923869782712514) is still active and the operator appears to have taken up Dutch poetry. The new C2 domain is ikhebkankerinmijnrechterteelbal[.]st (would not recommend pasting that into Google Translate during standup.)

Same key material and HTTP C2 protocol as the original potassium.vitacoco...[.]st variant. 11-port random C2 rotation, spreading via ADB to Android TV boxes.

IoCs:

a87aa7995ee9996952edb323d703875812f71d08237756ab44367f10e6197c7e
6833cb4681ac69281474be2c626df06cd90bb05bec72ae697cf219a6603826c9
3f13e18e190a7fc4c795d7caa83534d2879376ce43fd1a9120f23e48639cfe85

C2: ikhebkankerinmijnrechterteelbal[.]st → byte-swapped → 45.153.34[.]245
Dropper: 92.38.186[.]44 (HTTP + netcat :25565)

#mirai #DDoS #threatintel

edit: added byte-swapped C2 value

x.com
0
1
1
0
Open post
Nokia Deepfield @deepfield@infosec.exchange
· 1w ago
New Linux DDoS bot: Ourobot. 12 flood methods, SYN to GRE to TCP fragments. C2: 201.7.16[.]231:11121 Dropper: hxxp://power.belyxhost[.]in/payload.sh Backup C2: ENS bossmen.eth, text key "ouroboros" SHA256: 03436d1cf6b64faf682b8c7cd386e415d07a3eaa703f83419512d5c939adabf1 Blockchain C2 is very in right now. Ourobot has it: its hardcoded IP, on Ethereum, via curl. Very current. #DDoS #botnet
0
0
2
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:40:41 UTC