.putty P7DocsCybersecurity
Related
How to Protect Your Linux Servers from the Dirty Frag Root ExploitBreathing New Life into a 1947 Arvin 664A AM Radio: A Restoration JourneyApple Business Manager Admin Authentication: 5 Urgent Security Fixes Apple Must Implement6 Key Insights on Anthropic's Mythos and the Future of CybersecurityUNC6692 Hackers Exploit IT Help Desk Trust to Deploy Custom Malware via Microsoft Teams10 Ways Automation and AI Are Reshaping Cybersecurity Execution at Machine SpeedUnderstanding the Fragnesia Linux Kernel Flaw: Root Privilege Escalation ExplainedDirtyDecrypt Exploit Code Released: Critical Linux Kernel LPE Vulnerability Now Weaponized

Brazilian Anti-DDoS Firm Hacked, Used as Botnet Base for Attacks on ISPs

Last updated: 2026-05-04 01:07:17 · Cybersecurity

Breaking News: Anti-DDoS Firm Turned Attack Platform

A Brazilian tech company that markets DDoS protection services has been exposed as the command center for a years-long botnet campaign targeting Brazilian ISPs. The CEO admits a security breach, but experts say the scale suggests a deliberate operation.

Brazilian Anti-DDoS Firm Hacked, Used as Botnet Base for Attacks on ISPs
Source: krebsonsecurity.com

"This was absolutely a breach," said Huge Networks CEO in a statement. "We believe a competitor is trying to ruin our reputation." However, security researchers who have tracked the attacks since 2019 disagree: "The evidence points to a sophisticated, persistent actor, not a quick hack-and-tarnish job."

Background

For years, massive DDoS attacks have battered Brazilian ISPs, but the source remained a mystery. That changed when a trusted source shared an archive found in an open directory. It contained Portuguese-language Python malware and the private SSH keys of Huge Networks' CEO.

Huge Networks, founded in 2014 and headquartered in Miami with operations in Brazil, started as a game server DDoS protector. It grew into an ISP-focused mitigation provider with no public abuse complaints. The CEO insists the company is clean.

How the Attack Worked

The archive shows the threat actor had root access to Huge Networks' infrastructure. They scanned the internet for insecure routers and misconfigured DNS servers. These devices were then used to build a botnet for amplified attacks.

DNS reflection attacks exploit servers that answer queries from anywhere. Attackers spoof requests to appear from the target, and the DNS responses can be 70 times larger than the query. Combined with thousands of compromised routers, the result is devastating bandwidth floods.

Brazilian Anti-DDoS Firm Hacked, Used as Botnet Base for Attacks on ISPs
Source: krebsonsecurity.com

The malware discovered was in Portuguese, suggesting a Brazilian origin. The SSH keys allowed the attacker to maintain persistent access without detection.

What This Means

This revelation shakes trust in DDoS mitigation providers. If a company specializing in defense can be weaponized, ISPs must reconsider their partners. The breach also exposes the widespread insecurity of consumer routers in Brazil, many of which have default passwords left unchanged.

Security experts urge immediate action: change router credentials, disable remote management, and audit any third-party access. Huge Networks faces a reputation crisis, but the real damage is to the Brazilian ISPs that suffered years of attacks — and to their customers who experienced outages.

"This is a textbook case of how an insider threat or a breach can turn a defender into an attacker," said one researcher. "It should be a wake-up call for the entire industry."