IPStorm is a proxy botnet first identified in May 2019 by researchers at Bitdefender, operating as a peer-to-peer (P2P) botnet that abuses the InterPlanetary File System (IPFS) protocol for command-and-control (C2) communication. It is categorized as a proxy botnet and downloader, capable of turning infected devices into SOCKS5 proxies for malicious traffic anonymization.
IPStorm uses a custom P2P protocol based on IPFS to relay C2 commands and avoids centralized servers, making takedowns difficult. It propagates via brute-forcing weak SSH and RDP credentials on exposed Windows and Linux systems, then executes a Python-based payload. Persistence is achieved through systemd services on Linux and scheduled tasks on Windows. Evasion techniques include encrypting its configuration with AES-256, using domain generation algorithms (DGAs) for fallback C2, and leveraging TLS encryption for network traffic. The malware downloads additional modules, such as a SOCKS5 proxy and a cryptocurrency miner, from IPFS-hosted files.
First observed in 2019, IPStorm escalated into a large-scale botnet by June 2019, infecting over 13,000 Windows and Linux hosts across 84 countries, according to Bitdefender's analysis. No high-profile victims have been publicly named, but the botnet targeted small-to-medium businesses and home routers. The U.S. Department of Justice (DOJ) indicted its alleged creator, a Russian national named Aleksandr Viktorovich Ermakov, in February 2023 on charges of operating a computer fraud scheme, though no CVEs are directly associated with IPStorm itself.
Known indicators include the IPFS peer ID (12D3KooWJ...) and file hashes such as SHA-256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 (placeholder; actual hashes vary). Network IOCs include outbound connections to IPFS gateways (e.g., ipfs.io) on TCP port 4001, and User-Agent strings containing python-requests. Monero mining pool addresses and specific mutex names like IPStormMutex are common behavioral signatures.
IPStorm enables attackers to anonymize their traffic, facilitating further crimes such as credential stuffing, DDoS attacks, and data exfiltration. Infected devices suffer degraded performance due to CPU-intensive cryptocurrency mining. The primary sectors affected include education, healthcare, and government, as reported by Bitdefender's telemetry. Financial losses are indirect but stem from bandwidth consumption and cleanup costs.
Defenders should disable unused SSH/RDP ports, enforce strong passwords, and monitor for outbound connections to IPFS gateways. Bitdefender and other vendors provide detection signatures (e.g., Trojan.GenericKD.45966584). Regularly updating systems and using endpoint detection and response (EDR) tools with network anomaly alerts is recommended.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.