Botnets operating in NZ/AU

Appendix: List of Known/names Botnets & DDoS attackers operating in NZ/AU

Source: the Deep Research Tool on Gemini AI.

Based on current intelligence reports and technical analysis, here is what is known about the named botnet families and DDoS operators actively targeting web infrastructure across the Australia and New Zealand region:

Advanced IoT and Multi-Purpose Botnet Families

  • Aisuru: A “Turbo Mirai-class” botnet responsible for a record-breaking 31.4 Tbps DDoS attack and a 15.72 Tbps attack specifically targeting an IP endpoint in Australia.
  • Kimwolf: A successor to Aisuru that hijacks Android TV set-top boxes to use as residential proxies; it has infected over 2 million devices globally.
  • RondoDox: An Internet of Things botnet that scales by exploiting critical remote code execution flaws, such as those in HPE OneView.
  • ShadowV2: Designed to exploit known vulnerabilities across multiple embedded Internet of Things platforms.
  • Tsundere: A Node.js-based botnet that utilizes Ethereum blockchain smart contracts for its infection infrastructure.
  • Raptor Train: A massive botnet of over 200,000 compromised Internet of Things devices (cameras, routers, NAS) managed by Integrity Technology Group for state-sponsored operations in AU and NZ.
  • Quad7 (xlogin/CovertNetwork-1658): Primarily targets TP-Link routers for credential theft and password spraying against Microsoft 365 accounts.
  • KV-botnet: A sophisticated resource used by state actors (Volt Typhoon) consisting of compromised Cisco, Netgear, and DrayTek routers.
  • Mozi: Historically the largest tracked IoT botnet, primarily used for volumetric DDoS and credential theft.
  • Mirai (and variants): Including Murdoc (targeting AVTECH/Huawei) and other unnamed variants frequently used to target regional telecommunications.
  • PolarEdge: Compromised over 2,000 Internet of Things devices by exploiting Cisco Small Business Router vulnerabilities.
  • JackSkid & Mossad: Smaller botnets disrupted in early 2026 alongside the Aisuru and Kimwolf infrastructure.
  • AsyncRAT & DcRAT: Identified as the most prevalent malware families recorded in Australia and New Zealand for 2024–2025.
  • SolarMarker RAT & Rhadamanthys Stealer: Leading malware strains identified in the region for initial access and credential exfiltration.
  • Androxgh0st: Known for targeting PHP servers and Moodle LMS platforms.
  • AkiraBot: An AI-powered botnet capable of bypassing CAPTCHAs and spamming websites at scale.
  • Prometei: A resilient botnet targeting Linux servers.
  • HTTPBot: A rapidly expanding botnet family identified in 2025.
  • Vo1d: Specifically targets Android TV devices worldwide, including those in the Oceania region.
  • CryptBot: Distributed via fake software “cracks” to compromise end-user devices.

DDoS Operators and Hacktivist Collectives

  • Anonymous Sudan: A pro-Russia hacktivist group that conducted “opAustralia” in early 2023, targeting government, aviation, and media sectors.
  • NoName057(16): A sophisticated pro-Russia group that uses volunteer-based bots to launch randomized “Web DDoS Tsunami” attacks.
  • Killnet: A Russian cybercrime syndicate and hacktivist cluster targeting energy, utility, and financial services in countries supporting Ukraine.
  • Usersec: A pro-Russia group mobilized to conduct DDoS attacks against critical infrastructure in countries allied with Ukraine.
  • Dark Storm Team: A pro-Palestine hacktivist group that has claimed high-profile DDoS attacks against global targets including Snapchat and Indian financial entities.
  • DragonForce Malaysia: Originally a hacktivist group known for “OpsBedil” and “OpsPatuk,” it has since evolved into a professionalized ransomware-as-a-service operator.
  • Indian Cyber Force: A hacktivist group that has targeted portals in response to regional and international religious or political conflicts.
  • Vulture (Iran-based), RipperSec (Malaysia-based), & Mysterious Team (Bangladesh-based): Hacktivist collectives that coordinate DDoS campaigns against Western-aligned nations.
  • AnonSec: A pro-Pakistan hacktivist group active in regional DDoS campaigns.

Ransomware and Extortion Operators (Utilizing DDoS)

  • INC Ransom (Lynx): A prolific group targeting critical networks and government agencies in Australia, New Zealand, and Tonga using “triple extortion” (encryption, data leak, and DDoS).
  • LockBit & ALPHV (BlackCat): RaaS operators that pioneered the use of DDoS attacks to pressure AUNZ victims during ransomware negotiations.
  • Black Basta: Leverages Qakbot for initial access and uses DDoS as an additional extortion lever.
  • REvil & Phantom Squad: Groups that have launched Ransom Denial of Service campaigns, including embedding ransom notes within attack payloads.
  • ShinyHunters: A high-profile extortion group linked to data breaches and service outages for several AU and NZ entities.
  • Scattered Spider: Known for aggressive credential stuffing and social engineering campaigns targeting retail and technology sectors in Australasia.

State-Sponsored and Specialty Operators

  • Volt Typhoon, Salt Typhoon, & Flax Typhoon: PRC-linked actors that compromise routers and Internet of Things devices to create stealthy botnet infrastructure for espionage and disruption.
  • Calisto (FSB Center 18): A Russian intelligence-linked intrusion set targeting government and military sectors in Australia and New Zealand.
  • DarkSpectre: A Chinese-affiliated threat actor that has compromised millions of browser users to exfiltrate corporate meeting data.
  • Iridium: A nation-state actor conducting long-term cyberespionage against the Five Eyes alliance, including Australian and New Zealand government resources.

Mobile Banking and Financial Botnets

  • FluBot, Medusa, & TeaBot: Resurgent Android banking trojans that use “smishing” (SMS phishing) to build botnets for financial fraud and credential theft.
  • Datzbro: An Android banking trojan that uses AI-generated social media scams to compromise devices and perform financial theft.
  • Klopatra: Sophisticated mobile malware targeting financial institutions in Europe and Oceania using Hidden VNC and overlay attacks.
  • Olymp Loader: A Malware-as-a-Service (MaaS) platform written in Assembly to bypass modern antivirus engines, used to deliver credential stealers to victims.

Page last updated on Sunday, May 17, 2026 by the author Ben Kemp

Written by Ben Kemp - WP Security Consultant

  • Ben Kemp is a veteran web consultant with over 28 years of industry experience. Specialising in technical WordPress support and maintenance since version 1.5 (2005), Ben delivers security services to a global portfolio of clients. Connect with Ben on LinkedIn, Facebook or WordPress.