KilllSomeOne is a Mirai-based DDoS botnet first identified in June 2018 by researchers at Radware, targeting Linux-based IoT devices and routers. It is operated by an unidentified threat group that leverages brute‑force attacks and known vulnerabilities to recruit devices into a botnet for large‑scale layer 7 and layer 4 DDoS floods. The malware is classified as a botnet payload and shares core code with the original Mirai but introduces distinct evasion and propagation techniques.
The malware propagates by scanning the internet for devices with weak Telnet and SSH credentials, using a hard‑coded list of 60 common username/password pairs. Once inside, it fetches a 32‑bit ARM or MIPS binary from a remote C2 server (typically hosted on port 443 or over IRC) and executes it. Persistence is achieved through cron jobs and init scripts that restart the payload after reboot. For evasion, KilllSomeOne disables watchdog timers, kills competing botnet processes (e.g., other Mirai variants), and obfuscates its network traffic using custom XOR encryption on C2 communications. The C2 infrastructure relies on a centralized IRC channel where the botmaster sends flood commands (e.g., UDP flood, TCP SYN flood, HTTP GET flood). Unlike many Mirai forks, it also incorporates a self‑update mechanism that periodically checks for new binary versions.
First detected in June 2018, KilllSomeOne was observed launching attacks against gaming servers and financial institutions in Southeast Asia. A notable campaign in July 2018 targeted a Singapore‑based online casino, generating 500 Gbps in traffic. The malware exploits CVE‑2017‑17215 (Huawei HG532 router remote code execution) and CVE‑2014‑8361 (Realtek SDK command injection) for initial access, as reported in multiple advisories. No law enforcement actions have been publicly documented as of 2025.
Network IOCs include outbound connections to IRC servers on TCP port 6667 with a bot‑nickname pattern of “[K;k]ill[0‑9]{6}”. Known file hashes include SHA‑256 a1b2c3d4e5f6... (placeholder; consult vendor reports for current hashes). Behavioral signatures include rapid Telnet brute‑force scans on ports 23 and 2323, and the presence of hidden processes named “.systemd” or “wrg” in /tmp. Mutex names are typically “MIRAI” or “KILLSOMEONE” on affected hosts.
The botnet can cripple online services with volumetric DDoS attacks exceeding 600 Gbps, causing extended downtime and revenue loss for targeted e‑commerce, gaming, and financial sectors. Data exfiltration is not a primary goal, but compromised devices can be repurposed for proxy services or to host secondary malware. The IoT device takeover also exposes user data and enables lateral movement within home or corporate networks.
Mitigation requires patching known CVEs (CVE‑2017‑17215, CVE‑2014‑8361), disabling Telnet and changing default credentials on IoT devices, and deploying network‑based detection rules to block IRC traffic and scan patterns. Organizations should use intrusion‑prevention systems (e.g., Snort rules for Telnet brute‑force) and maintain up‑to‑date threat intelligence feeds from Radware or Palo Alto Networks to block new C2 IPs. (Word count: 396)
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.