2026-07-09NOTABLETwo Golang DDoS botnets, Apex2 and c2c/meow, flood exposed Telnet/SSH Linux and IoT with fake-systemd persistence and passwordless-sudo escalation
Apex2
tool · tool:apex2-botnet single-source
Golang-based IoT/Linux/Windows DDoS botnet, a structural evolution of the earlier Apex botnet, delivered via Telnet credential brute-force; supports a Cloudflare-bypass HTTP(S) flood ('cf'), UDP/game/Discord floods, and TLS floods; Linux builds cover arm/arm64/mipsle/ppc64 (Nozomi Networks Labs, 2026-07-06).
Aliases: Apex
Coverage
1
first 2026-07-09 → last 2026-07-09
Latest activity
2026-07-09
Two Golang DDoS botnets, Apex2 and c2c/meow, flood exposed Telnet/SSH Linux and IoT with fake-systemd…
Peak priority
notable
1 notable
Targets
energy
sectors: energy, water, transport
Sources cited
2
2 hosts
Action items (3)
Do-now tasks recorded on the entries about Apex2, newest first. Check the date before acting on an older one.
- Remove Telnet and SSH management-interface exposure from internet-facing IoT and embedded-Linux devices (the initial-access vector for both families) and eliminate default/weak credentials, both botnets rely entirely on credential brute-force, not exploitation.2026-07-09Two Golang DDoS botnets, Apex2 and c2c/meow, flood…
- Hunt for the c2c/meow persistence and escalation markers: systemd unit files created outside package-manager/config-management workflows (auditd on unit-file writes), a binary at /usr/local/bin/cpufreqd or a 'CPU Frequency Daemon' unit, and processes probing passwordless sudo via 'sudo -n true'.2026-07-09Two Golang DDoS botnets, Apex2 and c2c/meow, flood…
- Alert on outbound plaintext-TCP-carrying-JSON to non-standard ports (the C2 channel) and segment OT-adjacent Linux systems from business-critical networks with restricted outbound connectivity to limit both C2 reach and DDoS participation.2026-07-09Two Golang DDoS botnets, Apex2 and c2c/meow, flood…
Defender insights
What each entry about Apex2 tells a defender to do, newest first.
Story timeline
ATT&CK techniques (6 across 6 tactics)
6 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- PersistenceCreate or Modify System Process: Systemd Service
- Privilege EscalationCreate or Modify System Process: Systemd Service · Abuse Elevation Control Mechanism: Sudo and Sudo Caching
- StealthMasquerading: Match Legitimate Resource Name or Location
- Credential AccessBrute Force
- Command and ControlIngress Tool Transfer
- ImpactNetwork Denial of Service
Persistence TA0003
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
Privilege Escalation TA0004
T1543.002Create or Modify System Process: Systemd Service×1
Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a system and service manager commonly used for managing background daemon processes (also known as services) and other system resources. Systemd is the default initialization (init) system on many Linux distributions replacing legacy init systems, including SysVinit and Upstart, while remaining backwards compatible.
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
T1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching×1
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges.
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
Stealth TA0005
T1036.005Masquerading: Match Legitimate Resource Name or Location×1
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading defenses and observation.
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
Credential Access TA0006
T1110Brute Force×1
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
Command and Control TA0011
T1105Ingress Tool Transfer×1
Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim network through the command and control channel or through alternate protocols such as ftp. Once present, adversaries may also transfer/spread tools between victim devices within a compromised environment (i.e. Lateral Tool Transfer).
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
Impact TA0040
T1498Network Denial of Service×1
Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.
Evidence: 2026-07-09/nozomi-apex2-c2c-meow-golang-iot-linux-ddos-botnets · ATT&CK page ↗
Entries about Apex2 (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- industrialcyber.co1 (50%)
- nozominetworks.com1 (50%)
All cited sources (2)
- industrialcyber.coIndustrial Cyberhttps://industrialcyber.co/ransomware/nozomi-identifies-apex2-and-c2c-golang-malware-driving-faster-iot-botnet-attacks-raising-risks-for-ot-environments/
- nozominetworks.comNozomi Networks Labshttps://www.nozominetworks.com/blog/spring-botnet-floods-golang-malware-targets-exposed-iot-systems