ShadowV2: An emerging DDoS for hire botnet www.darktrace.com/blog/shad…
Darktrace’s latest investigation uncovered a novel campaign that blends traditional malware with modern devops technology.
At the center of this campaign is a Python-based command-and-control (C2) framework hosted on GitHub CodeSpaces. This campaign also utilizes a Python based spreader with a multi-stage Docker deployment as the initial access vector.
The threat actors employ advanced methods such as HTTP/2 rapid reset, a Cloudflare under attack mode (UAM) bypass, and large-scale HTTP floods, demonstrating a capability to combine distributed denial-of-service (DDoS) techniques with targeted exploitation.