FBot is a malware name used for at least two distinct threat contexts. The better-established usage in IoT threat reporting refers to a Mirai-derived botnet targeting embedded Linux and IoT devices. In that form, FBot conducts Telnet-based scanning and credential attacks, exploits remote code execution vulnerabilities in internet-exposed devices, and deploys architecture-specific payloads to expand the botnet. Reported propagation has included exploitation of vulnerabilities in LILIN DVR/NVR products and Iteris Vantage Velocity roadside monitoring infrastructure. Core functionality includes command-and-control registration and heartbeat traffic, distributed denial-of-service attack execution, and automated propagation through scanning, brute-force login attempts, and payload delivery using available transfer utilities or fallback upload methods. FBot code and protocol elements have also been cited as part of the lineage for later botnets, including Dysphoria, and as one of the source families referenced in RapperBot development.
A separate usage of the name FBot refers to a Python-based cloud and web attack tool focused on account takeover and abuse of SaaS and cloud services rather than IoT botnet operations. That tool targets services such as AWS, Office365, PayPal, Sendgrid, and Twilio, scans exposed web application configuration files for secrets, validates accounts, and can create privileged cloud identities to facilitate spam operations and broader post-compromise abuse. Because the same name is applied to materially different malware/tooling families in public reporting, attribution and classification under the label FBot should be handled carefully and disambiguated by platform, language, and operational context.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
On February 20, 2021, the 360Netlab Threat Detection System captured attackers were using a remote command execution vulnerability (CVE-2020-9020) in the Vantage Velocity product from Iteris to spread Fbot botnet samples. | Background Fbot, a botnet based on Mirai, has been very active... attackers were using a remote command execution vulnerability (CVE-2020-9020) in the Vantage Velocity product from Iteris to spread Fbot botnet samples.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
FBot has three functions dedicated to AWS account attacks. The first is an AWS API Key Generator, handled by function aws_generator, which generates a random AWS access key ID by appending 16 randomly selected alphabetic characters to the standard AKIA prefix. Then, it generates a secret key from 40 randomly selected alphabetic characters.
The second AWS feature is a Mass AWS Checker, handled by function aws_checker. This function checks for AWS Simple Email Service (SES) email configuration details, including the maximum send quota and rate, as well as how many messages have been sent in the past 24 hours, likely to maximize spamming efforts against the targeted account.
The Hidden Config Scanner feature takes a URL as input and crafts an HTTP GET request to several PHP, Laravel, and AWS-related URIs where configuration values may be stored, including: _profiler/phpinfo config.js .env config/aws.yml .env.bak info.php aws.yml phpinfo aws/credentials phpinfo.php
The second AWS feature is a Mass AWS Checker, handled by function aws_checker. This function checks for AWS Simple Email Service (SES) email configuration details, including the maximum send quota and rate, as well as how many messages have been sent in the past 24 hours, likely to maximize spamming efforts against the targeted account.
The second AWS feature is a Mass AWS Checker, handled by function aws_checker. This function checks for AWS Simple Email Service (SES) email configuration details, including the maximum send quota and rate, as well as how many messages have been sent in the past 24 hours, likely to maximize spamming efforts against the targeted account.
The latest fbot variant of Dysphoria invests considerable effort in string protection. Its decryption algorithm draws inspiration to some extent from the jackskid codebase.
The second AWS feature is a Mass AWS Checker, handled by function aws_checker. This function checks for AWS Simple Email Service (SES) email configuration details, including the maximum send quota and rate, as well as how many messages have been sent in the past 24 hours, likely to maximize spamming efforts against the targeted account.
When a port is detected as open, login is attempted using a hard-coded credential list.
The response is parsed for keys and secrets related to the following services and the result is written to a text file: AWS ... Office365 ... Sendgrid ... Twilio ... Mailgun | FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties.
Fbot uses the technique of SYN port detection in the propagation process to improve the efficiency of propagation.
The function cms_scanner contains a map of CMS and web frameworks to regular expressions (regex) associated with the service. The program creates a request to the targeted URL and parses the response for the following technologies: Codeigniter Laravel phpBB ... WordPress ... Joomla ... Zimbra
First Fbot establishes a connection with the hardcoded C2 (198.23.238.203:5684)... After sending the registration packet the Bot starts to wait for C2 to issue commands
This article provides an in-depth analysis of Dysphoria's historical evolution timeline, its core string decryption algorithm, its C2 infrastructure retrieval mechanism, its distinctive network proxy mechanism, sample propagation methods, infection scope, and DDoS attacks.
62 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Earlier botnet/malware lineage referenced as part of Dysphoria's evolution.
IoT malware/botnet referenced as part of the code or functional basis for Dysphoria.
An earlier malware family/variant lineage associated with Dysphoria's evolution; the latest fbot variant is described as adding stronger string protection and contributing to Dysphoria's development.
A precursor malware/botnet family from which Dysphoria evolved.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.