Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-014
DDoS-for-hire operator running an AI co-authored C2 framework over a Pandora-Mirai botnet
Status
Active
Distinct actor
LOW 60%
Named actor
INSUFFICIENT
First observed
25 May 2026
Last updated
26 May 2026
Operator language
English-speaking
Motivation
Financial, DDoS-as-a-Service
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-014 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

An eleven-architecture Mirai-lineage botnet with a Discord-fronted customer dispatch, whose Python attack framework was co-authored by an AI coding agent, captured with the agent's own session logs as primary evidence. The operator is a downstream adopter of a publicly documented variant lineage, not its author.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Sectors
IoT devicesDDoS-for-hire customers

Eleven-architecture IoT botnet sold as a DDoS-for-hire service.

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

account-id 1441591352927326259 operator Discord ID
string PandoraNet botnet identifier baked into binaries
string Pandoras_Box operator directory-naming convention
string 1gba4cdom53nhp12ei0kfj operator-bespoke 22-character charset

Infrastructure and tooling

Primary host
87.106.143.220 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
Pandora-Mirai variantMatrix C2Atlassian Rovodev

MITRE ATT&CK

19 techniques across 8 tactics, read from the mapping tables of the reports about this actor, which keep their mapping on the companion detection page. Each technique links to where it is mapped.

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.