Matryosh is a new botnet that targets Android-like devices with the main purpose of DDoS attacks. The encryption algorithm implemented in this botnet and the process of obtaining C2 are nested in layers, like Russian nesting dolls. Based on the similarity of C2 instructions, we speculate that it is another attempt by the Moobot group, which is very active at the moment. The main function is to download and execute scripts from the remote host 199.19.226.25/bwget.”]
Source: https://blog.netlab.360.com/matryosh-botnet-is-spreading-en/

