Security researchers reported that EnemyBot, a Linux-based botnet linked to the Keksec threat actor, expanded from targeting IoT devices into a broader malware platform aimed at exposed Linux servers, web servers, CMS platforms, and even Android devices. The malware is largely derived from Mirai and Qbot, with public source code and added modules for obfuscation, propagation, command-and-control, reverse shells, packet sniffing, shell command execution, and distributed denial-of-service attacks. Researchers said the botnet aggressively incorporated recently disclosed one-day vulnerabilities, including flaws affecting Log4j, VMware Workspace ONE, Spring Cloud Gateway, F5 BIG-IP, Adobe ColdFusion, WordPress plugins, and multiple routers and IoT products.
Analysis of observed infections showed EnemyBot using remote code execution and shell-based download chains to fetch an update.sh script, which then retrieved 13 architecture-specific ELF payloads for different Linux environments. The malware attempted access to web server /shell endpoints and used common utilities such as wget, busybox, curl, and ftpget to stage payloads, while its x86 variant performed port scanning, TCP/UDP flooding, host enumeration, duplicate-instance checks, and HTTP POST-based data theft. Researchers also noted encrypted code, anti-analysis checks that terminated execution in sandbox-like environments, and similarities to the short-lived LolFMe botnet, underscoring the risk to internet-facing Linux and IoT systems that remain unpatched or allow execution from temporary directories.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Securonix Threat Labs published initial coverage detailing EnemyBot as a Linux-based botnet targeting Linux systems and IoT devices via remote code execution and shell-based download-and-execute chains. The report documented an observed infection attempt using a /shell endpoint and retrieval of an update.sh script that downloaded 13 architecture-specific ELF payloads.
LevelBlue described EnemyBot as a rapidly evolving botnet attributed to Keksec that had expanded beyond IoT into Linux servers, web servers, CMS platforms, and Android devices. The report also highlighted its aggressive use of recently disclosed one-day vulnerabilities through a built-in webscan module with 24 exploits.
LevelBlue says Fortinet later published an in-depth analysis of EnemyBot after its initial discovery. The provided Fortinet reference confirms such reporting was published in April 2022.
LevelBlue states that Securonix first discovered the EnemyBot botnet in March 2022. This marks the earliest explicit identification of the malware family in the provided references.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securonix.com
Open sourcelevelblue.com
Open sourcesecurityaffairs.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.