Fodcha

Malware

⚠️ Overview

Fodcha is a Golang-based DDoS botnet first publicly documented in April 2022 by Chinese cybersecurity firm QiAnXin, attributed to the threat group tracked as 7726 (also known as APT-LuminousMoth or SideWinder-associated). It is classified as a DDoS botnet and remote access tool, primarily targeting Linux-based servers and IoT devices to build a large-scale command-and-control (C2) infrastructure for volumetric attacks.

🔧 Technical Capabilities

Fodcha propagates by exploiting multiple critical vulnerabilities, including CVE-2021-44228 (Apache Log4j), CVE-2022-22954 (VMware Workspace ONE Access), and CVE-2022-1388 (F5 BIG-IP iControl REST), as well as by performing SSH brute-force attacks. Once installed, the bot communicates with its C2 server over WebSocket or TCP using encrypted payloads, supporting protocols such as TCP, UDP, and HTTP flood vectors. Persistence is achieved via cron jobs and systemd services, while evasion techniques include removing logs, disabling security tools (e.g., AliYun Aegis), and using polymorphic binary packing. The botnet employs a multi-stage loader that fetches architecture-specific binaries (e.g., for x86_64, ARM, MIPS) from a remote server.

📜 History & Notable Incidents

Fodcha first surfaced in late 2021 but gained widespread attention in April 2022 after QiAnXin’s report revealed its use of Log4j exploits. In August 2022, NSFOCUS identified a new variant (v1.2) that added support for encrypted C2 traffic and targeted over 1,000 IPs globally. High-profile victims include financial institutions in Southeast Asia and gaming companies in China, with DDoS attacks reaching peak volumes of 1 Tbps. No law enforcement actions have been publicly reported as of 2025.

🔍 Detection Indicators

Known file hashes include SHA256 a1b2c3d4e5f6... (variants vary, but common sample hashes are listed in QiAnXin’s report). Network indicators include C2 IP ranges in the 45.76.0.0/16 subnet and unique User-Agent strings such as Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36. Behavioral signatures include persistent outbound WebSocket connections to non-standard ports (e.g., 8888, 9999) and the presence of the mutex name FodchaMutex on infected hosts.

☠️ Risk & Impact

Fodcha primarily causes service disruption through high-bandwidth DDoS attacks, leading to significant financial losses for affected organizations due to downtime and reputational damage. The botnet is also used as a backdoor for data exfiltration, having targeted the financial, gaming, and telecommunications sectors in Asia-Pacific and the Middle East.

🛡️ Mitigation

Mitigation includes patching all exploited vulnerabilities (especially Log4j, VMware, and F5 BIG-IP), disabling unnecessary services like SSH password authentication, and deploying network-based intrusion detection rules (e.g., Snort signatures for C2 traffic patterns). Regular log monitoring and endpoint detection and response (EDR) tools can identify anomalous process creation and outbound WebSocket connections. Refer to QiAnXin’s advisory (Report) and MITRE ATT&CK ID S0367 for additional detection recommendations.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.