EnemyBot is a Linux-focused IoT botnet associated with the Keksec cybercrime group and used primarily for distributed denial-of-service activity, with reporting also linking the operator ecosystem to extortion. The malware targets internet-exposed routers, web servers, CMS platforms, Linux hosts, and some Android devices, and is notable for rapidly incorporating newly disclosed vulnerabilities into its propagation logic. Public reporting describes EnemyBot as derived in part from Mirai and Gafgyt code, with additional custom development and continued active evolution.
EnemyBot spreads by exploiting a broad set of known vulnerabilities in internet-facing devices and applications, and by attempting authentication with weak or default credentials. Observed targeting has included multiple router vendors, Apache HTTP Server, ThinkPHP, Log4j-exposed applications, Spring Cloud Gateway, VMware Workspace ONE Access and Identity Manager, WordPress components, and other embedded or server-side software. It has also attempted to compromise exposed Android Debug Bridge services. In multiple campaigns, successful exploitation led to shell-based download chains that retrieved architecture-specific binaries for the victim host.
The malware supports multiple processor architectures and is designed to run across diverse Linux and embedded environments. After execution, it connects to command-and-control infrastructure and awaits instructions while continuing to scan for additional vulnerable systems. Reported functionality includes random internet scanning, vulnerability probing, shell command execution, reverse shell support, modular payload retrieval, and multiple DDoS flooding modes spanning network and application layers. Some analyses also describe system enumeration, duplicate-instance checks, anti-analysis behavior, string obfuscation, and concealment of command-and-control infrastructure through Tor. EnemyBot has additionally been reported to include data theft via HTTP POST in at least some samples.
EnemyBot stands out among contemporary botnets for embedding propagation exploits directly into the bot, including support for further exploitation of VMware Workspace ONE vulnerabilities after initial compromise. Its rapid adoption of one-day vulnerabilities and broad exploit coverage make it a significant threat to unpatched Linux servers, IoT devices, and exposed enterprise applications.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2016-6277: Targets NETGEAR routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2017-18368: Targets Zyxel P660HN routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2022-27226 affecting iRZ mobile routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-41773/CVE-2021-42013: Targets Apache HTTP servers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-44228/2021-45046: Better known as Log4j | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2018-20062: Targets ThinkPHP CMS | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2015-2051: Targets D-Link routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2018-10823 flaw an older D-Link routers (DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, DWR-111 through 1.01). | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-44228/2021-45046: Better known as Log4j | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
The malware exploits tens of known vulnerabilities including: CVE-2020-17456 vulnerability affecting SEOWON INTECH SLC-130 and SLR-120S routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2022-25075 to 25084: Targets TOTOLINK routers, previously exploited by the Beastmode botnet | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-41773/CVE-2021-42013: Targets Apache HTTP servers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2014-9118: Targets Zhone routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2020-5902 F5 BigIP RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-36356, CVE-2021-35064 Kramer VIAware RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2022-22947 Spring Cloud Gateway - Code injection vulnerability | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
Some examples are Razer Sila (April 2022) which was published without a CVE and a remote code execution (RCE) vulnerability impacting VMWare Workspace ONE with CVE-2022-22954 the same month. | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-4039 Zyxel NWA-1100-NH Command injection | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2020-7961 Liferay Portal - Java Unmarshalling via JSONWS RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2022-1388 F5 BIG IP RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-36356, CVE-2021-35064 Kramer VIAware RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2018-16763 Fuel CMS 1.4.1 RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
21 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses a list of hardcoded username/password combinations to login into devices in the attempt to access systems using weak or default credentials.
The message was stored as cleartext in earlier samples, new samples were released with the message encoded with an XOR operation using a multiple-byte key.
Each line of the script attempts to download (again using various methods), set permissions to execute (777), execute from /tmp/ and then delete the original ELF binary.
It uses a list of hardcoded username/password combinations to login into devices in the attempt to access systems using weak or default credentials.
Scrubbing the file in a decompile, it appears to feature a host of networking options such as port scanners, TCP/UDP flood options and general system enumeration.
Scrubbing the file in a decompile, it appears to feature a host of networking options such as port scanners, TCP/UDP flood options and general system enumeration.
Mapped to MITRE ATT&CK The findings of this report are mapped to the following MITRE ATT&CK Matrix techniques: TA0011: Command and Control T1132: Data Encoding T1001: Data Obfuscation
Once the bot has been installed on a device, it connects to its C2 server and waits for further commands
it connects to a command-and-control (C2) server that is hidden in the Tor network, making its takedown more complicated.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KekSec-developed botnet mentioned as background context.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and participate in DDoS attacks.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and conduct DDoS attacks.
Linux-based multi-architecture botnet targeting a wide range of Linux hosts including servers and IoT devices. It downloads architecture-specific ELF binaries, performs system enumeration, supports port scanning and TCP/UDP flood capabilities, can steal data via HTTP POST, and includes counter-forensics/anti-analysis behavior.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.