Fodcha — Cross-Architecture DDoS Botnet Spreading via N-Day Exploits (CVE-2021-22205, CVE-2021-35394) and Telnet/SSH Brute-Force, Later Adding Ransom DDoS — Threadlinqs Intelligence
As of 2026-06-10, Fodcha — Cross-Architecture DDoS Botnet Spreading via N-Day Exploits (CVE-2021-22205, CVE-2021-35394) and Telnet/SSH Brute-Force, Later Adding Ransom DDoS is a high-severity malware threat attributed to Fodcha operator, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 30 indicators of compromise.
Threat ID: TL-2026-0754 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Fodcha operator · FINANCIAL
Fodcha is a rapidly spreading IoT/Linux DDoS botnet discovered by CNCERT and 360 Netlab in early 2022, named for its initial C2 domain (folded.in) and its use of the ChaCha algorithm to encrypt
Fodcha is a Mirai-derived, multi-architecture DDoS botnet first sampled on January 12, 2022 and publicly disclosed by 360 Netlab on April 13, 2022. CNCERT and 360 Netlab named it 'Fodcha' from its original command-and-control domain folded.in combined with its use of the ChaCha20 stream cipher to encrypt network traffic. The botnet ships discrete payloads for mips, mpsl (mipsel), arm, and x86 CPU architectures, allowing it to colonize a broad range of routers, DVRs, and Linux servers.
Propagation is two-pronged. First, Fodcha weaponizes a basket of N-day vulnerabilities, including CVE-2021-22205 (GitLab CE/EE unauthenticated RCE via a flawed ExifTool image parse), CVE-2021-35394 (Realtek Jungle SDK 'UDPServer' command-injection / buffer-overflow affecting dozens of OEM SoCs), an Android Debug Bridge (ADB) Debug Server RCE on exposed TCP/5555, and a series of device backdoors / command-injection flaws in MVPower DVR, LILIN DVR, TOTOLINK routers, and ZHONE routers. Second, a standalone brute-force cracking tool named Crazyfia — found co-located on the same downloader servers — scans for and cracks weak Telnet/SSH credentials; the Crazyfia scan results are consumed by the Fodcha operator to push samples onto vulnerable hosts. Successful exploitation pulls architecture-specific binaries from staging servers via wget/curl (ingress tool transfer).
The original (v1) build used folded.in for C2 until March 19, 2022, when the hosting/cloud vendor took down the domain; the operators migrated to fridgexperts.cc (v2), which resolved to more than a dozen IPs spread across the US, Korea, Japan, and India on Amazon, DediPath, DigitalOcean, and Linode infrastructure. Fodcha's C2 protocol uses a multi-step handshake; later builds redesigned communications to use xxtea (with hardcoded key 'PJbiNbbeasddDfsc') to encrypt sensitive configuration/resources and ChaCha20 (32-byte key + 12-byte nonce, single round) for the network channel, deliberately frustrating both file- and traffic-level detection. Bot commands include 0x69 (heartbeat), 0xEB (launch attack), and 0xFB (exit), with roughly 17 attack vectors largely reused from leaked Mirai source.
During March 29–April 10, 2022 Fodcha accumulated over 62,000 unique bot IPs with daily active counts around 10,000, overwhelmingly inside China (China Unicom ~59.9%, China Telecom ~39.4%, China Mobile ~0.5%; top provinces Shandong, Liaoning, Zhejiang) and hitting 100+ DDoS victims per day. Over subsequent releases (v2 OpenNIC TLDs on April 19; v3 xxtea on April 24; v4 structured config on June 5; v4.x dual-ICANN C2 on July 7) the botnet grew to 60,000+ daily bots and 40+ C2 IPs, peaking at over 1Tbps of attack traffic against a cloud provider on September 21, 2022 and 1,396 unique targets in a single day on October 11, 2022. The returning version added a ransom-DDoS (RDDoS) capability: extortion text demanding '10 xmr' to a Monero wallet is embedded directly in the Data portion of DDoS packets — turning a pure availability threat into a financially motivated extortion operation.
Weaknesses (CWE)
CWE-94, CWE-78, CWE-120, CWE-521, CWE-798
Target sectors: healthcare, telecommunications, cloud, technology, gaming, government
Target regions: China, North America, Europe, Japan, Australia, Russia, Brazil
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 30 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, CVE-2021-22205, CVE-2021-35394, T1595, T1583, T1583, T1587, T1190, T1078, T1133, T1059, T1133, T1110