Echobot is a Mirai-derived botnet malware family first identified in 2019 that compromises Linux-based IoT devices, network appliances, and enterprise systems to recruit hosts for distributed denial-of-service attacks. It combines automated scanning and brute-force attempts using default credentials with exploitation of known remote code execution and command injection vulnerabilities. Its exploit arsenal expanded from 18 exploits in early samples to 71 in later variants, incorporating both legacy vulnerabilities and newly disclosed flaws.
Targets include routers, IP cameras, set-top boxes, smart home controllers, network-attached storage, SD-WAN appliances, web application firewalls, application delivery controllers, enterprise administration tools, and industrial control products. Industrial targets include Mitsubishi Electric remote terminal units and Schneider Electric U.Motion systems. Echobot activity against operational technology environments has been observed across geographically dispersed manufacturing organizations; those observations did not establish operational disruption.
Successful exploitation invokes payloads that download and execute architecture-specific malware. A Bash-based dropper supports deployment across at least 13 processor architectures, and compromised servers have been used to host payloads and propagate further infections. Echobot's broad exploitation coverage supports opportunistic recruitment beyond conventional consumer IoT devices into enterprise and industrial environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The ICS-specific exploits used by Echobot target CVE-2019-14931, an unauthenticated remote OS command injection vulnerability affecting Mitsubishi Electric ME-RTU devices.
The ICS-specific exploits used by Echobot target [...] CVE-2018-7841, a remote command execution flaw affecting Schneider Electric’s U.Motion Builder product.
Echobot added four exploits to its arsenal from 2019, while the latest one is from August 2019, targeting Webmin Linux/Unix administration panel (CVE-2019-15107). | F5 Networks researchers have detected a new variant of the "Echobot" malware, now consisting of 71 exploits.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
this version of Echobot adds an outstanding exploit for CVE-2019-14927, which targets Mitsubishi Electric‘s Remote Terminal Unit (RTU). | F5 Networks researchers have detected a new variant of the "Echobot" malware, now consisting of 71 exploits.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The list of exploits used by this Echobot variant includes multiple 'Remote Command Execution' and 'Command Injection' vulnerabilities across targeted products.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named in connection with a Mirai-associated sample exhibiting extremely rapid host scanning during a March 2026 sandbox analysis. The article does not provide further functionality or first-discovery information.
Mirai variant identified as the most commonly observed malware in IBM's 2019 OT attack data. It incorporates over two dozen exploits targeting enterprise and ICS products, including remote command execution vulnerabilities in Mitsubishi Electric ME-RTU devices and Schneider Electric U.Motion Builder. Observed ICS attacks primarily targeted manufacturing across a wide geographical area. IBM reported no observed Echobot attacks causing disruptions or other serious operational problems.
A Mirai-family botnet malware variant that propagates via a large and growing exploit set, spreads through a bash dropper named "Richard," downloads and compiles itself for multiple processor architectures, compromises exposed devices and servers, and recruits them into a botnet.
An IoT botnet and Mirai spin-off that propagates by leveraging dozens of public remote code execution exploits across a wide range of devices and software. It is described as built for distributed denial-of-service attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.