A Brazilian technology company focused on defending networks against distributed denial-of-service attacks has reportedly been compromised and used to orchestrate a sustained barrage of DDoS assaults targeting competing network operators throughout Brazil, according to security research. The company's leadership contends that malicious actors exploited a security vulnerability to gain unauthorized access and that the campaign may represent a deliberate attempt by a rival firm to damage the company's reputation.
Over several years, cybersecurity researchers have documented a pattern of severe DDoS incidents originating from Brazil and directed exclusively at Brazilian ISPs. The source of these attacks remained unclear until recently, when an anonymous security professional shared an unusual collection of files discovered in an unprotected online directory.
The leaked archive contained multiple malware tools written in Python with Portuguese-language documentation, along with private SSH authentication credentials belonging to the chief executive of Huge Networks, a Brazilian internet service provider specializing in DDoS mitigation for other network operators.
Established in Miami, Florida in 2014, Huge Networks operates primarily from Brazil. The organization began by safeguarding gaming servers from DDoS attacks and subsequently expanded into providing mitigation services to ISPs. The company maintains no public record of abuse complaints and shows no connection to known DDoS-for-hire operations.
The recovered archive demonstrates that an unauthorized actor based in Brazil obtained administrative access to Huge Networks systems and constructed a substantial DDoS botnet through systematic scanning of the internet for vulnerable routers and misconfigured DNS infrastructure suitable for weaponization.
DNS Amplification Mechanics
DNS enables internet users to navigate to websites by entering domain names rather than numerical IP addresses. Under normal circumstances, DNS servers respond only to queries from authorized machines within their domain. However, attackers exploit misconfigured DNS servers that respond to requests from any location on the internet. By sending forged DNS queries that appear to originate from a target network, attackers cause DNS servers to direct their responses to the intended victim.
When attackers leverage DNS protocol extensions that support larger message sizes, they can substantially amplify attack traffic. A DNS query smaller than 100 bytes can generate responses 60 to 70 times larger, magnifying the assault's destructive capacity. This amplification becomes particularly potent when perpetrators simultaneously query numerous DNS servers using spoofed requests from tens of thousands of compromised devices.

Botnet Construction and Operation
The exposed archive includes command-line records revealing how the attacker systematically built and operated the botnet by hunting for TP-Link Archer AX21 routers. The botnet specifically targeted devices vulnerable to CVE-2023-1389, an unauthenticated command injection flaw that received a patch in April 2023.
Malicious domains embedded in the Python scripts included DNS requests to hikylover[.]st and c.loyaltyservices[.]lol, both previously identified as command-and-control infrastructure for an IoT botnet utilizing a Mirai malware variant.
Evidence indicates the botmaster coordinated operations from a Digital Ocean server flagged for abusive conduct hundreds of times within the preceding year. The Python code references multiple internet addresses registered to Huge Networks, which were deployed to identify targets and launch DDoS campaigns. Attacks remained geographically confined to Brazilian IP ranges, with each targeted address block subjected to 10-60 seconds of assault using four concurrent processes before moving to the next victim.
The archive further reveals that the malicious Python scripts utilized private SSH credentials belonging to Huge Networks CEO Erick Nascimento. When questioned about the files, Nascimento stated he did not create the attack code and was unaware of the full scope of the DDoS operations until contacted by security researchers.
We received and notified many Tier 1 upstreams regarding very very large DDoS attacks against small ISPs. We didn't dig deep enough at the time, and what you sent makes that clear.
Erick Nascimento
Security Breach and Response
Nascimento attributed the unauthorized activity to a digital intrusion discovered in January 2026 that compromised two company development servers and his personal SSH keys. He asserted that no evidence supports the use of these credentials after January.
We notified the team in writing the same day, wiped the boxes, and rotated keys. All documented internally.
Erick Nascimento
Nascimento indicated that Huge Networks has contracted a third-party network forensics company to conduct a comprehensive investigation.
Our working assessment so far is that this all started with a single internal compromise — one pivot point that gave the attacker downstream access to some resources, including a legacy personal droplet of mine. The compromise happened through a bastion/jump server that several people had access to. Digital Ocean flagged the droplet on January 11 — compromised due to a leaked SSH key, in their wording — I was traveling at the time and addressed it on return. That droplet was deprecated and destroyed, and it was never part of Huge Networks infrastructure.
Erick Nascimento
Historical Context and Denial
The malware powering the TP-Link botnet derives from Mirai, a malware family that first emerged in September 2016 with a record-breaking DDoS attack. In January 2017, researchers identified the Mirai creators as co-owners of a DDoS mitigation company that weaponized the botnet against gaming servers to acquire new clients.
In May 2025, another Mirai-based assault struck, which Google characterized as the largest attack it had ever absorbed. The incident implicated a Brazilian man in his twenties operating both a DDoS mitigation company and multiple DDoS-for-hire platforms subsequently dismantled by federal law enforcement.
Nascimento categorically rejected suggestions that Huge Networks orchestrated DDoS campaigns against Brazilian operators to generate demand for protective services.
We don't run DDoS attacks against Brazilian operators to sell protection. Our sales model is mostly inbound and through channel integrator, distributors, partners — not active prospecting based on market incidents. The targets in the scripts you received are small regional providers, the vast majority of which are neither in our customer base nor in our commercial pipeline — a fact verifiable through public sources like QRator.
Erick Nascimento
Nascimento asserted possession of "strong evidence stored on the blockchain" demonstrating that a competitor orchestrated the entire operation. When pressed to identify the rival, he declined, citing concerns about compromising a planned strategic response.
I would love to share this with you, but it could not be published as it would lose the surprise factor against my dishonest competitor. Coincidentally or not, your contact happened a week before an important event – one that this competitor has NEVER participated in (and it's a traditional event in the sector). And this year, they will be participating. Strange, isn't it?
Erick Nascimento
Source: Krebs on Security