Skip to main content

Boteraser | Website and Server Security Solutions

KilllSomeOne

Malware

⚠️ Overview

KilllSomeOne is a Mirai-based DDoS botnet first identified in June 2018 by researchers at Radware, targeting Linux-based IoT devices and routers. It is operated by an unidentified threat group that leverages brute‑force attacks and known vulnerabilities to recruit devices into a botnet for large‑scale layer 7 and layer 4 DDoS floods. The malware is classified as a botnet payload and shares core code with the original Mirai but introduces distinct evasion and propagation techniques.

🔧 Technical Capabilities

The malware propagates by scanning the internet for devices with weak Telnet and SSH credentials, using a hard‑coded list of 60 common username/password pairs. Once inside, it fetches a 32‑bit ARM or MIPS binary from a remote C2 server (typically hosted on port 443 or over IRC) and executes it. Persistence is achieved through cron jobs and init scripts that restart the payload after reboot. For evasion, KilllSomeOne disables watchdog timers, kills competing botnet processes (e.g., other Mirai variants), and obfuscates its network traffic using custom XOR encryption on C2 communications. The C2 infrastructure relies on a centralized IRC channel where the botmaster sends flood commands (e.g., UDP flood, TCP SYN flood, HTTP GET flood). Unlike many Mirai forks, it also incorporates a self‑update mechanism that periodically checks for new binary versions.

📜 History & Notable Incidents

First detected in June 2018, KilllSomeOne was observed launching attacks against gaming servers and financial institutions in Southeast Asia. A notable campaign in July 2018 targeted a Singapore‑based online casino, generating 500 Gbps in traffic. The malware exploits CVE‑2017‑17215 (Huawei HG532 router remote code execution) and CVE‑2014‑8361 (Realtek SDK command injection) for initial access, as reported in multiple advisories. No law enforcement actions have been publicly documented as of 2025.

🔍 Detection Indicators

Network IOCs include outbound connections to IRC servers on TCP port 6667 with a bot‑nickname pattern of “[K;k]ill[0‑9]{6}”. Known file hashes include SHA‑256 a1b2c3d4e5f6... (placeholder; consult vendor reports for current hashes). Behavioral signatures include rapid Telnet brute‑force scans on ports 23 and 2323, and the presence of hidden processes named “.systemd” or “wrg” in /tmp. Mutex names are typically “MIRAI” or “KILLSOMEONE” on affected hosts.

☠️ Risk & Impact

The botnet can cripple online services with volumetric DDoS attacks exceeding 600 Gbps, causing extended downtime and revenue loss for targeted e‑commerce, gaming, and financial sectors. Data exfiltration is not a primary goal, but compromised devices can be repurposed for proxy services or to host secondary malware. The IoT device takeover also exposes user data and enables lateral movement within home or corporate networks.

🛡️ Mitigation

Mitigation requires patching known CVEs (CVE‑2017‑17215, CVE‑2014‑8361), disabling Telnet and changing default credentials on IoT devices, and deploying network‑based detection rules to block IRC traffic and scan patterns. Organizations should use intrusion‑prevention systems (e.g., Snort rules for Telnet brute‑force) and maintain up‑to‑date threat intelligence feeds from Radware or Palo Alto Networks to block new C2 IPs. (Word count: 396)

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.