Diicot expands its tactics with the Cayosin Botnet, moving from cryptojacking to DDoS assaults.
Recently discovered payloads have been linked to the Romanian threat actor Diicot, according to cybersecurity specialists. The results revealed the group's growing capacity, particularly its potential to launch distributed denial-of-service (DDoS) attacks. The researchers point out the relevance of the name Diicot, which also corresponds to the Romanian organised crime and anti-terrorism enforcement unit. It was revealed in a technical report by Cado Security. The investigation also finds that materials from Diicot's efforts use language and imagery that allude to this group, suggesting a possible connection. Diicot, formerly known as Mexals, was first discovered by Bitdefender in July 2021 using a Go-based SSH brute-forcer tool named Diicot Brute to infiltrate Linux systems as part of a cryptojacking effort. Akamai revealed a resurgence of the group's activity in April of this year, which they suspect began around October 2022 and resulted in about $10,000 in illegal reve...