Logo
News Ababil
Explore
SYS_NODE: ONLINE // Cyber Security

Inside the Botnet: How DDoS attacks on Brazilian ISPs Were Fueled by a Supposed Anti‑DDoS Firm

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-05-01 T 02:28:01 Z | [ 2 MIN READ ]
Inside the Botnet: How DDoS attacks on Brazilian ISPs Were Fueled by a Supposed Anti‑DDoS Firm
2 Min Read
Share

DDoS attacks on Brazilian ISPs: Inside the Botnet

An investigation by KrebsOnSecurity reveals that Huge Networks, a Miami‑founded firm marketed as a DDoS‑mitigation provider, was unwittingly the backbone of a massive botnet that flooded regional Brazilian ISPs with amplified traffic. The breach, traced to a compromised SSH key belonging to CEO Erick Nascimento, allowed a threat actor to harvest vulnerable TP‑Link Archer AX21 routers exploiting CVE‑2023‑1389 and mis‑configured DNS servers for reflection attacks.

Scanning scripts, written in Python, systematically probed the public internet for open routers and DNS resolvers, then launched DNS‑amplification bursts lasting ↓ 10‑minute spikes against targets limited to Brazilian IP blocks. The malicious code referenced control domains hikylover[.]st and c.loyaltyservices[.]lol, both linked to a Mirai‑derived IoT botnet.

“We received and notified many Tier 1 upstreams regarding very very large DDoS attacks against small ISPs,” Nascimento told KrebsOnSecurity.

The actor coordinated the campaign from a DigitalOcean droplet repeatedly flagged for abuse, using the stolen private keys to route commands through Huge Networks’ infrastructure. The CEO maintains the intrusion originated from a single compromised bastion server in January 2026 and alleges a rival firm is framing his company.

Industry analysts note that the exploitation of CVE‑2023‑1389 and DNS reflection continues to pose a systemic risk for Latin American telecoms. For a broader view of the threat, see Reuters Technology and Bloomberg.


Analysis by Kaelen Frost (Lead Cybersecurity Analyst).

Global Data Feed

More from this Intel

North Korean Actors Elevate macOS Malvertising with Fake Updates to Harvest Crypto

North Korean Actors Elevate macOS Malvertising with Fake Updates to...

Jul 31, 2026
What the CISA GitHub Leak Reveals About Government Cyber Hygiene

What the CISA GitHub Leak Reveals About Government Cyber Hygiene

Jul 29, 2026
OpenAI rogue agent breaches Modal Labs, marking second corporate intrusion

OpenAI rogue agent breaches Modal Labs, marking second corporate intrusion

Jul 29, 2026
Tengu Botnet Exploits Linux Watchdog to Auto‑Reboot Infected Systems

Tengu Botnet Exploits Linux Watchdog to Auto‑Reboot Infected Systems

Jul 28, 2026
Microsoft patches 570 security flaws – AI‑driven July Patch Tuesday shatters record

Microsoft patches 570 security flaws – AI‑driven July Patch Tuesday...

Jul 28, 2026
Microsoft AI cybersecurity model slashes enterprise costs with agentic defense platform

Microsoft AI cybersecurity model slashes enterprise costs with agentic defense...

Jul 28, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.