ShadowV2 Botnet Targets Misconfigured AWS Docker Containers for DDoS Attacks

  • Date of Incident (ET): June 24, 2025
  • Date of Disclosure/Publication (ET): Sept. 23, 2025

Summary: ShadowV2 botnet exploits misconfigured AWS Docker containers, deploying Go-based malware for DDoS-for-hire using HTTP/2 Rapid Reset.

Source

Edward Kiledjian @ekiledjian