/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

XOR botnet infecting Linux computers launches 150 Gpbs DDoS attacks on up to 20 targets per day

Botnet preying on Linux computers delivers potent DDoS attacks  —  XOR DDoS bombards as many as 20 targets per day, sometimes with 150 GBpS of traffic.  —  Security researchers have uncovered …

Ars Technica Dan Goodin

Context & Ripple Effects

XOR arrives months after Mumblehard began infecting thousands of Linux and FreeBSD machines, marking 2015 as the year Linux servers became routine botnet recruiting grounds rather than an afterthought for malware authors.

What looks modest now — 150 Gbps floods against up to 20 daily targets — sits at the start of a scale curve the corpus traces forward: by 2022, attackers were supplementing botnets with misconfigured-server fleets via TCP Middlebox Reflection amplification, and by late 2025 botnets were driving a 31.4 Tbps attack before the US DOJ disrupted four botnets infecting 3M+ devices.

First-order effects

  • Up to 20 targets per day face multi-hundred-gigabit-class floods that standard hosting links cannot absorb, forcing victims onto DDoS mitigation services immediately; compromised Linux operators' first move is applying the released patch for the CopyFail root-privilege vulnerability.

Second-order effects

  • Anti-DDoS and CDN providers gain forced demand from Linux-hosting customers, while rival attackers watching XOR's throughput push toward amplification techniques — the path TCP Middlebox Reflection took in 2022 — because recruited-server capacity alone caps attack size.

Third-order effects

  • If the pattern holds, botnet defense migrates from per-victim mitigation to coordinated law-enforcement takedowns, the model the DOJ's four-botnet disruption later exercised; meanwhile unpatched always-on Linux machines remain the standing raw material for each generation of larger attacks.

The trend: DDoS capability is scaling from gigabit botnet floods toward terabit assaults, shifting the burden of disruption from individual network operators to national law-enforcement operations.