SHARE
Facebook X Pinterest WhatsApp

New Version of Fodcha DDoS Botnet Adds Extortion

Back in April of this year, 360 Netlab researchers reported on a new DDoS botnet with more than 10,000 daily active bots and over 100 DDoS victims per day, dubbed Fodcha due to its command and control (C2) domain name folded.in and its use of the ChaCha encryption algorithm. In response to 360 Netlab’s report, […]

Written By
thumbnail Jeff Goldman
Jeff Goldman
Oct 28, 2022
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Back in April of this year, 360 Netlab researchers reported on a new DDoS botnet with more than 10,000 daily active bots and over 100 DDoS victims per day, dubbed Fodcha due to its command and control (C2) domain name folded.in and its use of the ChaCha encryption algorithm.

In response to 360 Netlab’s report, the author appeared to concede defeat by leaving the phrase “Netlab pls leave me alone I surrender” in a sample.

It’s now clear that the surrender was fake – according to a new 360 Netlab report, an updated, more powerful version has been released.

Fodcha version 2 has more than 60,000 daily active bots and over 40 C2 domains and can generate more than 1 Tbps of traffic. The number of daily attacks has also surged – its peak thus far was on October 11, with 1,396 targets in a single day.

See also: How to Stop DDoS Attacks: Prevention & Response

Fodcha Attacks Spread

The new version adds redundancy, using both XXTEA and ChaCha20 encryption to protect sensitive information and avoid detection, and leveraging a combination of primary and backup C2 domains.

“This redundancy mechanism can not only prevent C2 from being taken over, but also has good robustness and can maintain the stability of its master network,” the researchers wrote (via Google Translate).

While the attacks primarily target victims within China, they’re spreading worldwide. According to the report, 78.2 percent of targets are in China, followed by 10 percent in the U.S., 2.1 percent in Singapore, 1.6 percent in Japan, 1.4 percent in Russia, 1 percent in France, and 1 percent in Germany.

On September 21, the researchers said, a leading cloud service provider reached out to them about an attack with traffic exceeding 1Tbps. They concluded that the attacker was Fodcha.

See the Top DDoS Protection Service Providers

Demanding Ransom in Monero

Notably, the code now includes a demand to “send 10 xmr to [address] or we will shut down your business.” As the 360 Netlab researchers put it, the operators behind Fodcha seem to be pursuing “the business model of extortion.”

If so, their choice of XMR (Monero) follows a trend. In a recent report on cyber extortion, Trend Micro researchers wrote that while address-linking techniques can be used to trace Bitcoin addresses back to their owners, cybercriminals “have started to shift to anonymity-based coins such as Monero, which are much harder to trace.”

“Several dark web marketplaces now use Monero exclusively,” Trend Micro noted.

thumbnail Jeff Goldman

eSecurity Planet contributor Jeff Goldman has been a technology journalist for more than 20 years and an eSecurity Planet writer since 2009. He's also written extensively about wireless and broadband infrastructure and semiconductor engineering. He started his career at MTV, but soon decided that technology writing was a more promising path.

Recommended for you...

SQL Injection Prevention: 6 Ways to Protect Your Stack
Matt Gonzales
Jul 9, 2025
Microsoft Defender vs Bitdefender: Compare Antivirus Software
Jenna Phipps
May 27, 2025
Bitwarden vs Dashlane: Comparing Password Managers
Jenna Phipps
May 14, 2025
What Is Malware? Definition, Examples, and More
Davin Jackson
Feb 10, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.