News Ababil.
Explore
SYS_NODE: ONLINE // Cyber Security

Inside the Botnet: How DDoS attacks on Brazilian ISPs Were Fueled by a Supposed Anti‑DDoS Firm

DECRYPTED BY: Kaelen Frost | TIMESTAMP: 2026-05-01 T 02:28:01 Z | [ 2 MIN READ ]
Inside the Botnet: How DDoS attacks on Brazilian ISPs Were Fueled by a Supposed Anti‑DDoS Firm
2 Min Read
Share

DDoS attacks on Brazilian ISPs: Inside the Botnet

An investigation by KrebsOnSecurity reveals that Huge Networks, a Miami‑founded firm marketed as a DDoS‑mitigation provider, was unwittingly the backbone of a massive botnet that flooded regional Brazilian ISPs with amplified traffic. The breach, traced to a compromised SSH key belonging to CEO Erick Nascimento, allowed a threat actor to harvest vulnerable TP‑Link Archer AX21 routers exploiting CVE‑2023‑1389 and mis‑configured DNS servers for reflection attacks.

Scanning scripts, written in Python, systematically probed the public internet for open routers and DNS resolvers, then launched DNS‑amplification bursts lasting ↓ 10‑minute spikes against targets limited to Brazilian IP blocks. The malicious code referenced control domains hikylover[.]st and c.loyaltyservices[.]lol, both linked to a Mirai‑derived IoT botnet.

“We received and notified many Tier 1 upstreams regarding very very large DDoS attacks against small ISPs,” Nascimento told KrebsOnSecurity.

The actor coordinated the campaign from a DigitalOcean droplet repeatedly flagged for abuse, using the stolen private keys to route commands through Huge Networks’ infrastructure. The CEO maintains the intrusion originated from a single compromised bastion server in January 2026 and alleges a rival firm is framing his company.

Industry analysts note that the exploitation of CVE‑2023‑1389 and DNS reflection continues to pose a systemic risk for Latin American telecoms. For a broader view of the threat, see Reuters Technology and Bloomberg.


Analysis by Kaelen Frost (Lead Cybersecurity Analyst).

Global Data Feed

More from this Intel

Splunk Enterprise vulnerability CVE‑2026‑20253 enables unauthenticated code execution

Splunk Enterprise vulnerability CVE‑2026‑20253 enables unauthenticated code execution

Jun 14, 2026
Phishing Attack Volume Drops 20% Yet Threat Sophistication Soars

Phishing Attack Volume Drops 20% Yet Threat Sophistication Soars

Jun 12, 2026
ShinyHunters Weaponizes Oracle PeopleSoft zero‑day (CVE‑2026‑35273) to Assault Universities

ShinyHunters Weaponizes Oracle PeopleSoft zero‑day (CVE‑2026‑35273) to Assault Universities

Jun 12, 2026
Cybersecurity Stars Awards 2026 Winners Revealed Across 95 Categories

Cybersecurity Stars Awards 2026 Winners Revealed Across 95 Categories

Jun 11, 2026
North Korea cybercrime Drives GDP Growth and Threatens Asia‑Pacific Firms

North Korea cybercrime Drives GDP Growth and Threatens Asia‑Pacific Firms

Jun 11, 2026
Meta AI Support Bot Exploit Lets Hackers Hijack High‑Profile Instagram Accounts

Meta AI Support Bot Exploit Lets Hackers Hijack High‑Profile Instagram...

Jun 09, 2026

Join The Elite

Get the top 0.1% global intelligence and market insights delivered directly to your inbox before the masses.

We respect your privacy. No spam.