Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

The Same Skype ID Malware Author Used to Run IoT Botnet and Apply for Jobs

True to the biggest failure of all time, a malware developer uses the same Skype address to advertise his IoT botnet and also the Skype ID itself to apply for freelance jobs.

Table of Contents

True to the biggest failure of all time, a malware developer uses the same Skype address to advertise his IoT botnet and also the Skype ID itself to apply for freelance jobs.

The Same Skype ID Malware Author Used to Run IoT Botnet and Apply for Jobs Overview

Nicknamed DadyL33T, this developer is the man behind DaddyHackingTeam, the home of an upcoming future botnet. It is still in the development phase, but the website has also contained some of the source code of the leaked malware variants over the past few years.

DaddyL33T will not be a real hacker if he does not have an account on HackForums. This account is registered under DaddyPvP and most of his posts are asking for help or introducing their botnet.

Most people who want to be hackers on HackForums are harmless, but DaddyL33T seems to be skilled, at least enough for his botnet to work.

The Person Behind the Hybrid Botnet Qbot-Gr1n IoT

Researcher at NewSky Security Ankit Anubhav has tracked DaddyL33T's botnet, apparently the modified version of the QBot botnet. On HackForums, DaddyL33T also asked some questions about QBot.

Researcher at NewSky Security Ankit Anubhav has tracked DaddyL33T's botnet, apparently the modified version of the DaddyL33T asks about QBot on HackForum

The researcher said DaddyL33T's botnet uses a binary file that was used during infection from DaddyHackingTeam. Private chat with DaddyL33T via Skype, Anubhav said DaddyL33T admitted his botnet is trying to infect about 300 devices, a very small number compared to other IoT botnets.

The researcher said DaddyL33T's botnet uses a binary file that was used during infection from DaddyHackingTeam Source code on DaddyHackingTeam

When analyzing the QBot model, Anubhav also found many similarities with the malware Gr1n IoT, also used to create IoT botnet. So it seems that DaddyL33t's botnet is just a copy.

DaddyL33T Is a 13-Year-Old Boy

This, he admitted in a private conversation with Anubhav. The lack of malware development experience and OpSec is obvious when Anubhav says he found a job application on the freelance job site, where DaddyL33T uses the same Skype address he used to advertise his botnet. In it, he also said that he is 13 years old, just as he confessed to Anubhv.

This, he admitted in a private conversation with Anubhav DaddyL33T's freelance job application

Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.

FAQ

Why does the Same Skype ID Malware Author Used to Run IoT Botnet and Apply for Jobs matter?

True to the biggest failure of all time, a malware developer uses the same Skype address to advertise his IoT botnet and also the Skype ID itself to apply for freelance jobs.

Who may be affected by this issue?

The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.

How can users reduce the risk?

Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.