BotenaGo is Go-based malware targeting Linux-based routers, modems, network-attached storage systems, and other IoT equipment. It incorporates more than 30 exploit functions for known vulnerabilities across multiple vendors, enabling remote compromise of exposed, unpatched devices. Its exploit repertoire includes vulnerabilities affecting D-Link, Netgear, Dasan GPON, Zyxel, and other products. Following successful exploitation, it executes shell commands to download device-dependent payloads. It also provides backdoor functionality that receives attacker commands through network listeners or terminal input.
BotenaGo follows exploitation methods similar to those used by Mirai operators but is not derived from Mirai's source code. It has been operationally linked to Mirai infrastructure, and its publicly available source code has enabled derivative tools. One derivative, named Lillin scanner, targets Lilin surveillance DVRs: it accepts attacker-supplied targets, attempts authentication using embedded credential pairs, exploits command injection in the NTP configuration interface, and deploys Mirai payloads for multiple processor architectures. This derivative relies on supplied target lists rather than autonomous worm-like propagation. BotenaGo activity includes exploitation of known vulnerabilities in unpatched Dasan GPON home routers; no specific named threat actor is firmly attributed to the family.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Lucifer Malware, BotenaGo Botnet and Zerobot Malware exploiting vulnerabilities on unpatched Dasan GPON home routers (CVE-2018-10562, CVE-2018-10561).
Lucifer Malware, BotenaGo Botnet and Zerobot Malware exploiting vulnerabilities on unpatched Dasan GPON home routers (CVE-2018-10562, CVE-2018-10561).
CVE-2017-18368: Zyxel routers and NAS devices; IPS coverage: TrueOnline.ZyXEL.P660HN.V1.Unauthenticated.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2014-2321: ZTE modems; IPS coverage: ZTE.Router.Web_shell_cmd.Remote.Command.Execution. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2018-10088: XiongMai uc-httpd 1.0.0; IPS coverage: XiongMai.uc-httpd.Buffer.Overflow. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2020-8515: Vigor routers; IPS coverage: DrayTek.Vigor.Router.Web.Management.Page.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2017-18362: ConnectWise plugin | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2016-6277: Netgear devices; IPS coverage: NETGEAR.WebServer.Module.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2015-2051: D-Link routers; IPS coverage: D-Link.Devices.HNAP.SOAPAction-Header.Command.Execution. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2016-1555: Netgear devices; IPS coverage: Netgear.macAddress.Remote.Command.Execution. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2020-9377: D-Link routers | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2020-8958: Guangzhou 1 GE ONU | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2013-3307: Linksys X3000 1.0.03 build 001 | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2017-6334: Netgear devices; IPS coverage: NETGEAR.DGN.DnsLookUp.Remote.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2013-5223: D-Link DSL-2760U Gateway (Rev. E1) | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2020-9054: Zyxel routers and NAS devices; IPS coverage: ZyXEL.NAS.Pre-authentication.OS.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2017-6077: Netgear devices; IPS coverage: NETGEAR.ping_IPAddr.HTTP.Post.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2019-19824: Realtek SDK based routers | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2020-10173: VR-3033 router; IPS coverage: Comtrend.VR-3033.Remote.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2016-11021: D-Link routers | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2020-10987: Tenda products; IPS coverage: Tenda.AC15.AC1900.Authenticated.Remote.Command.Injection. | BotenaGo is a malware written in Golang and is reportedly capable of exploiting more than 30 vulnerabilities in various IoT devices such as routers, modems, and NAS devices, and varies the delivered payload depending on the device it successfully exploited.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The modified configuration contains a command that, because of the vulnerability, will attempt to download a file named wget.sh from the IP address 136.144.41[.]169 and then immediately execute its content.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a separate malware family that follows Mirai's approach to exploiting exposed, insecure IoT devices and has operational links to Mirai infrastructure, despite not sharing its source-code lineage.
BotenaGo is described as malware targeting devices with known CVE vulnerabilities from multiple vendors.
Malware targeting multiple routers with numerous exploit functions.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.