EnemyBot is a multi-architecture DDoS botnet first identified in 2022 and attributed to the Keksec cybercrime group, also known as Kek Security. It primarily targets Linux servers, routers, and other IoT devices, with additional infection functionality for Android devices. Its codebase draws extensively from Gafgyt and Mirai, incorporates components from other botnets, and includes custom functionality. Its publicly released source code enables reuse by other operators.
EnemyBot self-propagates by scanning pseudorandom IP addresses, attempting hardcoded default credentials, and exploiting vulnerabilities in internet-facing services. Targets include routers, web servers, content management systems, and enterprise applications. Its exploit repertoire includes Log4Shell, Spring Cloud Gateway CVE-2022-22947, VMware Workspace ONE CVE-2022-22954, and D-Link CVE-2015-2051. EnemyBot has been deployed through exploitation of CVE-2022-22954 and embeds that exploit for subsequent propagation. It also attempts infection through exposed Android Debug Bridge services and USB-connected Android devices. Successful compromise typically triggers a shell-based downloader that retrieves and executes an architecture-specific payload.
EnemyBot supports multiple DDoS methods, including TCP, UDP, HTTP, TLS, DNS, SSDP, and ICMP flooding. Operators can execute shell commands, establish reverse shells, control scanning and packet-sniffing functions, and download additional payloads. Infected systems continue scanning while awaiting commands. Observed variants establish persistence through cron scheduling, randomize process names, remove downloaded installation artifacts, and use string encoding or XOR obfuscation to hinder analysis. Tor-based command-and-control conceals operator infrastructure. Development during 2022 included frequent revisions and rapid incorporation of newly disclosed exploits, expanding its reach beyond embedded devices to vulnerable server applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In particular, MooBot and Enemybot Malware targeting D-Link routers (CVE-2015-2051).
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Here is a list of those four exploit sets and malware that uses them ... Enemybot.
Enemy Botx64 Observed Exploits: CVE-2021-45046, CVE-2021-44228: Log4j – Remote Code Execution. | EnemyBot is mainly built on Gafgyt’s source code, with several modules from the original Mirai source code, and other botnets.
CVE-2022-27226 affecting iRZ mobile routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-41773/CVE-2021-42013: Targets Apache HTTP servers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2018-20062: Targets ThinkPHP CMS | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-41773/CVE-2021-42013: Targets Apache HTTP servers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2020-5902 F5 BigIP RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-36356, CVE-2021-35064 Kramer VIAware RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
Some examples are Razer Sila (April 2022) which was published without a CVE and a remote code execution (RCE) vulnerability impacting VMWare Workspace ONE with CVE-2022-22954 the same month. | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2020-7961 Liferay Portal - Java Unmarshalling via JSONWS RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2022-1388 F5 BIG IP RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-36356, CVE-2021-35064 Kramer VIAware RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
EnemyBot is mainly built on Gafgyt’s source code, with several modules from the original Mirai source code, and other botnets.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses a list of hardcoded username/password combinations to login into devices in the attempt to access systems using weak or default credentials.
The message was stored as cleartext in earlier samples, new samples were released with the message encoded with an XOR operation using a multiple-byte key.
Each line of the script attempts to download (again using various methods), set permissions to execute (777), execute from /tmp/ and then delete the original ELF binary.
It uses a list of hardcoded username/password combinations to login into devices in the attempt to access systems using weak or default credentials.
“Stateless” TCP SYN probes to pseudorandom IPs on Telnet ports 23 and 2323 Once targets were identified, Mirai attempted a brute-force attack...
Scrubbing the file in a decompile, it appears to feature a host of networking options such as port scanners, TCP/UDP flood options and general system enumeration.
Mapped to MITRE ATT&CK The findings of this report are mapped to the following MITRE ATT&CK Matrix techniques: TA0011: Command and Control T1132: Data Encoding T1001: Data Obfuscation
Once the bot has been installed on a device, it connects to its C2 server and waits for further commands
it connects to a command-and-control (C2) server that is hidden in the Tor network, making its takedown more complicated.
Then the script downloads the actual Enemybot binary which is compiled for the target device’s architecture.
Mirai managed to keep 200,000 – 300,000 enslaved devices and peaked at an unbelievable 600,000... FBI special agents compared Mirai’s 1+ Tbps (1,000 Gbps)... The first Mirai incident was reported after the 18th Sep 2016 attack against popular Minecraft servers hosted on French service OVH.
36 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KekSec-developed botnet mentioned as background context.
Botnet built on Gafgyt and Mirai code, actively developed and using Mirai-derived scanner, killer, and weak-credential modules to compromise devices and remove competitors.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and participate in DDoS attacks.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and conduct DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.