Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
ShadowV2 DDoS Service Lets Customers Self-Manage Attacks

ShadowV2 DDoS Service Lets Customers Self-Manage Attacks

Posted on September 23, 2025September 23, 2025 By CWS

A newly found distributed denial-of-service (DDoS) botnet targets misconfigured Docker containers for an infection and affords a brand new service mannequin the place prospects launch their very own assaults, Darktrace reviews.

The operation, named ShadowV2, breaks the standard DDoS service mannequin with using a Python-based command-and-control (C&C) platform hosted on GitHub CodeSpaces, and a classy assault toolkit that mixes conventional malware with fashionable DevOps know-how.

The an infection chain begins with a Python script hosted on GitHub CodeSpaces, which permits the attackers to work together with Docker to create containers. The attackers goal Docker daemons operating on AWS cloud cases which might be accessible from the web.

As an alternative of utilizing pictures from Docker Hub or importing a pre-prepared picture, the attackers spawn a generic ‘setup’ container. They then deploy varied instruments inside it, create a brand new picture of the custom-made container, and deploy it as a dwell container.

The container, Darktrace notes, acts as a wrapper round a Go-based binary that has no detections on VirusTotal, the place two of its variations had been submitted on June 25 and July 30, respectively.

Evaluation of the malware revealed that it spins up a number of threads operating configurable HTTP purchasers utilizing Valyala’s open supply Quick HTTP library, which helps making high-performance HTTP requests. The malware makes use of these purchasers to launch HTTP flood assaults.

The menace additionally contains a number of bypass mechanisms, together with HTTP2 fast reset, spoofed forwarding headers with random IP addresses, and Cloudflare under-attack-mode (UAM).

The malware’s C&C server is protected by Cloudflare, however the safety agency believes it’s possible operating on GitHub CodeSpaces. A misconfiguration allowed Darktrace to acquire a duplicate of the server’s API documentation and uncover all of the API endpoints.Commercial. Scroll to proceed studying.

A person API that has authentication, completely different account privilege ranges, and limitations to the kind of out there assaults led the cybersecurity agency to the conclusion that ShadowV2 is working as a DDoS-as-a-service platform as a substitute of a conventional DDoS botnet.

“As an alternative of the botnet operators launching assaults themselves, they’ve constructed a platform the place prospects can lease entry to the contaminated community to conduct their very own DDoS campaigns,” Darktrace explains.

This speculation is bolstered by the truth that the endpoint used to launch assaults asks customers to supply a listing of contaminated methods for use within the assault. Moreover, the C&C has an endpoint the place hosts that can’t be attacked will be outlined.

“The presence of an API and full UI turns the botnet right into a platform, which shifts detection from host indicators towards management airplane behaviors resembling uncommon Docker API calls, scripted container lifecycle occasions, and repetitive egress from ephemeral nodes. Defenders ought to deal with this as a product with a roadmap, looking forward to modular upgrades, abuse of reputable cloud companies, and new tenancy fashions fairly than remoted campaigns,” Sectigo senior fellow Jason Soroko stated.

Associated: Cloudflare Blocks Document-Breaking 11.5 Tbps DDoS Assault

Associated: Uncovered Docker APIs Doubtless Exploited to Construct Botnet

Associated: Google Sues Operators of 10-Million-Machine Badbox 2.0 Botnet

Associated: Cyber Warfare Rife in Ukraine, However Affect Stays in Shadows

Security Week News Tags:Attacks, Customers, DDoS, Lets, SelfManage, Service, ShadowV2

Post navigation

Previous Post: GitHub Enhances NPM’s Security with Strict Authentication, Granular Tokens, and  Trusted Publishing
Next Post: Top 25 MCP Vulnerabilities Reveal How AI Agents Can Be Exploited

Related Posts

Minnesota Activates National Guard in Response to Cyberattack Minnesota Activates National Guard in Response to Cyberattack Security Week News
Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats Chrome Extensions With 900,000 Downloads Caught Stealing AI Chats Security Week News
Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks Oracle Says Known Vulnerabilities Possibly Exploited in Recent Extortion Attacks Security Week News
Central Maine Healthcare Data Breach Impacts 145,000 Individuals Central Maine Healthcare Data Breach Impacts 145,000 Individuals Security Week News
US Organizations Warned of Chinese Malware Used for Long-Term Persistence US Organizations Warned of Chinese Malware Used for Long-Term Persistence Security Week News
WireTap Attack Breaks Intel SGX Security WireTap Attack Breaks Intel SGX Security Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News