A cross-platform java-bot
Anton Ivanov
Kaspersky Lab Expert

Early this year, we received a malicious Java application for analysis, which turned out to be a multi-platform bot capable of running on Windows, Mac OS and Linux. The bot was written entirely in Java. The attackers used vulnerability CVE-2013-2465 to infect users with the malware.


The bot is designed to conduct DDoS attacks from infected user machines.

The bot supports two flood types:

  • HTTP
  • UDP

Which attack type is to be used is specified by an attacker in the IRC channel for zombie machines. In addition, the following parameters are specified:

  • Address of the computer to be attacked
  • Port number
  • Attack duration
  • Number of threads to be used in the attack