Lune

USENIX Security2026顶会

From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet

Maarten Weyns, Dario Ferrero, Stefan Op de Beek, Daniel Wagner, Georgios Smaragdakis, Harm Griffioen

出版方
2026年份

摘要

In 2016, the Mirai botnet swept the Internet, ushering in a new era of DDoS attacks. Over the following decade, spinoffs of the Mirai botnet transitioned from simple attack tools into commercial platforms, offering Distributed Denial of Service (DDoS) attacks for Hire. Such platforms enable users to launch large-scale DDoS attacks with minimal technical expertise. One notable example is the Gorilla Botnet, which was operational between Fall 2024 and Summer 2025, an unusually long lifetime compared to similar Mirai-based Botnets. In this paper, we reverse-engineer the Mirai-based Gorilla Botnet and aim to understand its design, engineering decisions, and marketing strategies to enhance its resilience and success. We investigate its operational characteristics, including the types of attacks it supports, its underlying infrastructure, and the behavior of its bots. We find that Gorilla's longevity stems from targeted improvements, including two software development phases and learning from previous releases, setting it apart from typical Mirai-based botnets. In the process, we analyze the firepower and attack vectors of the Gorilla botnet and characterize the business types of its targets.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper5

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖