Keksec is a cybercrime botnet operator active since at least 2016 and known for running multiple parallel malware and IoT botnet lines. The group is associated with DDoS-focused extortion and broader profit-driven operations including cryptomining, information theft, and malware deployment. Malware and botnet families linked to Keksec or its ecosystem include Gafgyt and Tsunami variants, the Python-based Necro botnet, EnemyBot, LOLFME variants, Simps, and infrastructure-linked tooling such as Kaitori and AISURU. More recent reporting also places TuxBot v3 Evolution within the broader Keksec ecosystem through shared infrastructure and tooling overlap, although that linkage is ecosystem-level rather than proof of identical codebases. Keksec has shown a pattern of rapidly operationalizing publicly disclosed vulnerabilities, especially one-day exploits, across Linux, Windows, server, and IoT environments. Reported targeting has included internet-facing enterprise applications, routers, cameras, CMS platforms, Android Debug Bridge exposures, and other embedded devices. Observed propagation methods include exploit scanning, Telnet and SSH weak-credential attacks, brute forcing, and shell-script download chains. The group has repeatedly reused and modified open-source or leaked botnet code, particularly from Mirai-, Gafgyt-, and Tsunami-related lineages, while also developing custom components such as Necro. Necro is one of the most feature-rich malware families associated with Keksec. Reported capabilities include exploit scanning, SSH brute forcing, packet sniffing, Tor-backed command and control, domain generation, web-file infection, process injection, and Windows rootkit deployment. Associated payloads and web-injection activity have also enabled credential theft, keylogging, session theft, and browser-based DDoS behavior. Across its malware portfolio, Keksec has demonstrated defense evasion through process masquerading, obfuscation, anti-analysis checks, hidden or resilient command-and-control mechanisms, and malware-killing behavior against competitors. EnemyBot and related IoT-focused tooling illustrate Keksec’s emphasis on scalable DDoS operations. EnemyBot has been linked to exploitation of numerous known vulnerabilities in routers, web servers, CMS platforms, and other exposed devices, while supporting multiple architectures and active feature development. Simps and other linked botnets further reinforce the group’s use of hybrid Mirai/Gafgyt-style code for DDoS campaigns. LOLFME-related development has also shown destructive or wiper-like logic in some variants, though confirmed operational deployment of those destructive functions has not been established. Overall, Keksec is best characterized as an organized, adaptable, financially motivated cybercrime actor centered on botnet operations, DDoS-for-hire and extortion activity, opportunistic exploitation of newly disclosed vulnerabilities, and monetization through cryptomining, malware operations, and theft-enabling payloads.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
56 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
27 CVEs this actor has used in observed campaigns. 27 of them exploited in the wild.
CVE-2014-9118: Targets Zhone routers
CVE-2015-2051: Targets D-Link routers
CVE-2017-18368: Targets Zyxel P660HN routers
CVE-2018-10823 flaw an older D-Link routers (DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, DWR-111 through 1.01).
The malware exploits tens of known vulnerabilities including: CVE-2020-17456 vulnerability affecting SEOWON INTECH SLC-130 and SLR-120S routers
22 more CVEs tied to this actor tracked in Mallory.
109 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected ecosystem linked via shared infrastructure to the operator behind TuxBot v3 Evolution; no confirmed attribution is made.
Operates multiple parallel IoT botnets; TuxBot is assessed as part of its ecosystem.
An IoT botnet operator ecosystem linked to TuxBot through shared infrastructure with Kaitori v3.9 and AISURU; known for running multiple IoT botnet variants in parallel.
Infrastructure overlap with TuxBot through shared hosting and certificate artifacts; not stated to be the same malware/codebase.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.