The Firewall Guard Was Holding a Crowbar: Brazilian DDoS-Protection Firm Caught Powering the Attacks
Exposed archive ties Huge Networks infrastructure and its CEO's SSH keys to a long-running Mirai botnet hammering Brazilian ISPs. The CEO blames a competitor.

Imagine the security guard out front shows up every morning with a smile, then moonlights as the guy smashing the back window. That's roughly the shape of what just spilled out of an open directory tied to Huge Networks, a Miami-incorporated, Brazil-operating DDoS mitigation provider that sells protection to other Brazilian ISPs.
The exposed archive — Portuguese-language Python attack scripts, a command-line history, and the private SSH keys of Huge Networks CEO Erick Nascimento — describes a botnet that has been pounding small Brazilian network operators for years. The scripts hunt the public internet for TP-Link Archer AX21 routers still vulnerable to CVE-2023-1389, an unauthenticated command injection bug TP-Link patched in April 2023. Compromised routers get drafted into a Mirai variant that fires DNS reflection attacks (spoofed queries to open resolvers that reply to the victim with responses 60-70x the request size).
The targeting is the tell. Every IP prefix in the scripts sits inside Brazilian address space. Each victim gets hit for 10-60 seconds with four parallel processes per host, then the botnet rolls to the next one. Scanning was coordinated from a DigitalOcean droplet that has racked up hundreds of abuse complaints in the past year, and the malicious infrastructure phones home to hikylover[.]st and c.loyaltyservices[.]lol, both previously flagged as Mirai C2s.
And the SSH keys used to drive the attack scripts? They belong to the CEO of the company that's supposed to stop this kind of thing.
Nascimento denies writing the scripts or running the campaign. He pointed to a January 11, 2026 DigitalOcean notification flagging one of his personal droplets as compromised via a leaked SSH key, said the box was destroyed, and insists it was never Huge Networks production infrastructure. "We don't run DDoS attacks against Brazilian operators to sell protection," Nascimento said, arguing the targets in the scripts aren't customers or sales prospects. He says a third-party forensics firm is now reconstructing how a bastion server compromise pivoted into the rest of the environment.
His other claim is bolder: this was a competitor framing him, with evidence "stored on the blockchain" that he won't yet name because it would spoil the surprise.
There is precedent for skepticism here. The original Mirai authors, unmasked in 2017, were themselves running a DDoS mitigation business and using the botnet to drum up customers. A May 2025 record-breaking Mirai attack — the largest Google said it had ever mitigated — was tied to another twenty-something Brazilian operating both a mitigation company and DDoS-for-hire services later seized by the FBI. The arsonist-firefighter pattern is now a genre.
The forensics report, if it ever becomes public, is the thing to watch.



