ShellBot, also known as PerlBot, is a Perl-based Linux bot malware family that commonly operates as an IRC-controlled DDoS bot and remote administration implant. It has been observed in attacks against internet-exposed Linux systems, especially poorly secured SSH servers and vulnerable web applications, where it is deployed after brute-force credential attacks or exploitation of server-side remote code execution flaws. ShellBot has also appeared in broader multi-payload intrusion chains alongside coin miners, log-cleaning tools, and other Linux malware.
ShellBot communicates with command-and-control infrastructure over IRC, using persistent channel-based messaging and keepalive exchanges to receive operator commands. Reported capabilities include launching distributed denial-of-service attacks, executing arbitrary system commands, downloading additional payloads, performing port scanning, and providing shell or reverse-shell style remote control. Some variants also support private-message based operator interaction that can facilitate exfiltration or tasking. In observed compromises, ShellBot has been used both as an active botnet component and as a post-compromise control mechanism on infected hosts.
On Linux targets, ShellBot has been associated with persistence and defense-evasion behavior such as modifying startup mechanisms, adding cron-based execution, disguising process names, deleting artifacts, and interfering with forensic visibility. Variants have been seen masquerading as legitimate processes and being wrapped in installer scripts that adjust resource limits, remove traces, and repeatedly restore or relaunch components. Campaign reporting also links ShellBot to threat activity targeting Linux SSH infrastructure through dictionary and brute-force attacks, as well as opportunistic exploitation of exposed applications such as vBulletin, Cacti, and misconfigured Tomcat services.
ShellBot is an older but still active malware family, frequently reused or modified by multiple threat actors rather than tied to a single exclusive operator. It is regularly associated with Linux-focused botnet activity, DDoS operations, and opportunistic server compromise in both traditional hosts and containerized environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Recently, Unit 42 researchers found exploits in the wild leveraging the vBulletin pre-auth RCE vulnerability CVE-2020-17496. The exploits are a bypass of the fix for the previous vulnerability, CVE-2019-16759... We caught the first incident of CVE-2020-17496 exploitation on Aug. 10, 2020, and later found that exploitation attempts from different IP addresses are ongoing. | Some attackers are utilizing the vulnerability to download a Perl-based script malware (Shellbot) with the PHP function shell_exec() for the execution of the system command wget from the address http://178[.]170[.]117[.]50/bot1 and run it.
The exploitation of the BASH bug, now widely referred to as “Shellshock”, is in full swing... The initial patch for this vulnerability (CVE-2014-6271), which was released in sync with the vulnerability’s public disclosure, was quickly found to be inadequate. | The Perl script (md5: cd23ef54e264bd84ab1a12dddceb3f48) was first submitted to VirusTotal over a year ago and is known as ShellBot. It is an IRC bot with remote shell, scanning, and DDoS functionality.
This time, the group explored unpatched systems vulnerable to CVE-2016-8655 and Dirty COW exploit (CVE-2016-5195) as attack vectors.
This time, the group explored unpatched systems vulnerable to CVE-2016-8655 ... as attack vectors.
The Perl script (md5: cd23ef54e264bd84ab1a12dddceb3f48) was first submitted to VirusTotal over a year ago and is known as ShellBot. It is an IRC bot with remote shell, scanning, and DDoS functionality.
"...allowing threat actors to breach internet-exposed Cacti servers to deliver botnet malware such as MooBot and ShellBot."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The a binary is a script wrapper to start run, a Perl-obfuscated script for installation of a Shellbot to gain control of the infected system. The Shellbot disguises itself as a process named rsync... Shellbot is also used to control the botnet...
30 distinct techniques documented for this family, organized by ATT&CK tactic.
It then resets cron and removes possible cache files from other programs, starts scripts and binaries a, init0, and start, and sets the persistence by modifying the crontab.
The attacker gained access to the Tomcat container, brute forcing its default credentials and spawning a reverse shell. | These are the real Shellbot malware that forces the victim to communicate with the IRC server, executing and running whatever it wants.
These payloads try to execute system commands echo and id... The payload contains the PHP function shell_exec() for the execution of arbitrary system commands and a system command cat ../../../../../../../../../../etc/passwd...
The a binary is a script wrapper to start run, a Perl-obfuscated script for installation of a Shellbot to gain control of the infected system.
By exploiting this vulnerability, an attacker could have gained privileged access and control over any vBulletin server running versions 5.0.0 up to 5.5.4... allows attackers to send a crafted HTTP request with a specified template name and malicious PHP code, and leads to remote code execution.
It modified the shell configuration file so that it will download the files again when the user opens a new terminal.
It then resets cron and removes possible cache files from other programs, starts scripts and binaries a, init0, and start, and sets the persistence by modifying the crontab.
It modified the shell configuration file so that it will download the files again when the user opens a new terminal.
The Shellbot disguises itself as a process named rsync, commonly the binary seen on many Unix- and Linux-based systems to automatically run for backup and synchronization.
In the end, the malware removed all files, the history, and whatever it had fetched from the IRC server.
They also tracked down an IP address that had attempted to connect to the OSI server 38 times in what Air Force investigators called an SSH brute-force attack.
This ulimit.sh script initially checked the $EUID variable as a way to see if the attacker had root permissions.
It can also ask to perform a port scanning, which has the purpose to contact some specific ports of the target IP or a full-port scanning.
Bot.pl and craton.pl are two identical scripts used to communicate with different IRC servers, via different ports. | Shellbot malware enables the attackers to communicate with the C&C server... The C&C server, also called the IRC server in this scenario
Tsunami connects to the IRC server, joins a channel, and waits for the threat actor’s commands... ShellBot ... is also an IRC Bot that utilizes the IRC protocol like Tsunami.
Here is the PING-PONG exchange that is used to keep the communication channel alive between the bot and the IRC server.
On November 16, 2020, OSI said one of its engineers found a cryptominer on one of its servers during a routine maintenance operation. The crypto-mining malware, which was running at full capacity, had blocked the server altogether, which was failing to process valid requests.
102 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
The Sysdig research team analyzes other malware, like serv-hello or Shellbot, with similar behavior.
IRC-controlled malware that establishes command-and-control communications, downloads and launches multiple binaries/scripts for different architectures, performs file download, port scanning, data exfiltration, persistence and cleanup, and can be used to conduct DDoS/flooding attacks from compromised systems.
Propagation-capable Linux malware used in the attacks to help distribute or install the XMRig CoinMiner on targeted servers.
Perl-based IRC bot used for DDoS and remote system control on infected Linux servers. In this campaign it was distributed alongside the coin miner tooling.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.