XOR botnet infecting Linux computers launches 150 Gpbs DDoS attacks on up to 20 targets per day
Botnet preying on Linux computers delivers potent DDoS attacks — XOR DDoS bombards as many as 20 targets per day, sometimes with 150 GBpS of traffic. — Security researchers have uncovered …
Context & Ripple Effects
XOR arrives months after Mumblehard began infecting thousands of Linux and FreeBSD machines, marking 2015 as the year Linux servers became routine botnet recruiting grounds rather than an afterthought for malware authors.
What looks modest now — 150 Gbps floods against up to 20 daily targets — sits at the start of a scale curve the corpus traces forward: by 2022, attackers were supplementing botnets with misconfigured-server fleets via TCP Middlebox Reflection amplification, and by late 2025 botnets were driving a 31.4 Tbps attack before the US DOJ disrupted four botnets infecting 3M+ devices.
First-order effects
- Up to 20 targets per day face multi-hundred-gigabit-class floods that standard hosting links cannot absorb, forcing victims onto DDoS mitigation services immediately; compromised Linux operators' first move is applying the released patch for the CopyFail root-privilege vulnerability.
Second-order effects
- Anti-DDoS and CDN providers gain forced demand from Linux-hosting customers, while rival attackers watching XOR's throughput push toward amplification techniques — the path TCP Middlebox Reflection took in 2022 — because recruited-server capacity alone caps attack size.
Third-order effects
- If the pattern holds, botnet defense migrates from per-victim mitigation to coordinated law-enforcement takedowns, the model the DOJ's four-botnet disruption later exercised; meanwhile unpatched always-on Linux machines remain the standing raw material for each generation of larger attacks.
The trend: DDoS capability is scaling from gigabit botnet floods toward terabit assaults, shifting the burden of disruption from individual network operators to national law-enforcement operations.