CECbot
Malware family · 2 sample(s) · 2 indicator record(s) · 2 signing certificate(s)
About CECbot
Android TV box DDoS botnet - the operational successor to Katana by the same operator, but a clean-sheet Android app instead of a Mirai ELF: Java C2 layer, native JNI attack engine (11 DDoS methods incl. HTTP/2 + dynamic TLS), Curve25519 + Ed25519 + ChaCha20-Poly1305 C2 encryption, 9 persistence layers, and the first documented malware to weaponize HDMI-CEC. It maps the victim's home network (ICMP sweep + ARP correlation) and doubles as a residential proxy exit node. Bootstrap C2 strings are XOR-encrypted in the DEX; clearnet C2 domains are pushed at runtime, with a Tor .onion fallback.
Indicators
| Indicator | Type | Sample | First seen |
|---|---|---|---|
| c2kxpjr7cux7fqrfmimsz7rtq527xauw627xrjojimt66nwxqvrqbuyd.onion | domain | 2152b98a832c… | 2026-09-24 |
| c2kxpjr7cux7fqrfmimsz7rtq527xauw627xrjojimt66nwxqvrqbuyd.onion | domain | b3c1d5fc273d… | 2026-03-23 |