USENIX Security2026Top-tier venue
From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet
Maarten Weyns, Dario Ferrero, Stefan Op de Beek, Daniel Wagner, Georgios Smaragdakis, Harm Griffioen
Abstract
In 2016, the Mirai botnet swept the Internet, ushering in a new era of DDoS attacks. Over the following decade, spinoffs of the Mirai botnet transitioned from simple attack tools into commercial platforms, offering Distributed Denial of Service (DDoS) attacks for Hire. Such platforms enable users to launch large-scale DDoS attacks with minimal technical expertise. One notable example is the Gorilla Botnet, which was operational between Fall 2024 and Summer 2025, an unusually long lifetime compared to similar Mirai-based Botnets. In this paper, we reverse-engineer the Mirai-based Gorilla Botnet and aim to understand its design, engineering decisions, and marketing strategies to enhance its resilience and success. We investigate its operational characteristics, including the types of attacks it supports, its underlying infrastructure, and the behavior of its bots. We find that Gorilla's longevity stems from targeted improvements, including two software development phases and learning from previous releases, setting it apart from typical Mirai-based botnets. In the process, we analyze the firepower and attack vectors of the Gorilla botnet and characterize the business types of its targets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a6b8f405-75cb-4ecd-a5c6-4970c323555eBuilds on5
- Understanding the Mirai BotnetManos Antonakakis, Tim April, Michael D. Bailey, Matt Bernhard et al.USENIX Security 2017 · 2,003 citations
- A Lustrum of Malware Network Communication: Evolution and InsightsChaz Lever, Platon Kotzias, Davide Balzarotti, Juan Caballero et al.S&P 2017 · 86 citations
- Examining Mirai's Battle over the Internet of ThingsHarm Griffioen, Christian DoerrCCS 2020 · 81 citations
- Scan, Test, Execute: Adversarial Tactics in Amplification DDoS AttacksHarm Griffioen, Kris Oosthoek, Paul van der Knaap, Christian DoerrCCS 2021 · 35 citations
- Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire ServicesAnh V. Vu, Ben Collier, Daniel R. Thomas, John Kristoff et al.USENIX Security 2025
Related papers
- The Circle Of Life: A Large-Scale Study of The IoT Malware LifecycleOmar Alrawi, Charles Lever, Kevin Valakuzhy, Ryan Court et al.USENIX Security 2021 · 109 citations
- Measurement and Analysis of Hajime, a Peer-to-peer IoT BotnetStephen Herwig, Katura Harvey, George Hughey, Richard Roberts et al.NDSS 2019 · 168 citations
- Understanding Linux MalwareEmanuele Cozzi, Mariano Graziano, Yanick Fratantonio, Davide BalzarottiS&P 2018 · 203 citations
- Could you clean up the Internet with a Pit of Tar? Investigating tarpit feasibility on Internet wormsHarm Griffioen, Christian DoerrS&P 2023
- NXNSAttack: Recursive DNS Inefficiencies and VulnerabilitiesYehuda Afek, Anat Bremler-Barr, Lior ShafirUSENIX Security 2020
