Microsoft and CUJO AI reported that Zerobot, a Go-based malware-as-a-service botnet, expanded its compromise of IoT and internet-facing systems by combining brute-force attacks on weak SSH and Telnet credentials with exploitation of more than 20 known vulnerabilities. The malware targeted routers, firewalls, IP cameras, web servers, and enterprise software, with observed exploitation including CVE-2021-42013 in Apache, CVE-2022-33891 in Apache Spark, Spring4Shell, and F5 BIG-IP flaws. Researchers said the botnet delivered architecture-specific binaries or a zero.sh script from attacker-controlled infrastructure and added infected devices to a distributed denial-of-service network.
The newer Zerobot 1.1 variant added multiple DDoS attack methods, Linux and Windows-capable samples, and persistence mechanisms for both platforms, while also attempting to remove rival malware such as Mozi, Kaiten, Sora, Phantom, Nbrute, and minerd. Investigators linked activity to infrastructure including the domain zero.sudolite.ml and IP addresses 176.65.137.5 and 176.65.137.6, and noted that one associated domain was reportedly among domains tied to DDoS-for-hire services seized by the FBI. Researchers also found some exploit routines were malformed or mislabeled, suggesting the botnet was still under active development even as it broadened propagation and evasion behavior.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
CUJO AI published a deeper technical analysis of Zerobot, stating that samples observed earlier used 22 exploit routines targeting 21 listed vulnerabilities. The report also described payload delivery via architecture-specific binaries or zero.sh, attempts to kill competing malware, and efforts to erase shell history.
Microsoft published research detailing Zerobot's evolution as a malware-as-a-service botnet and described the latest tracked version, Zerobot 1.1. The company said the newer version expanded propagation with exploits including CVE-2021-42013 and CVE-2022-33891, added new DDoS methods, and included Linux and Windows-capable samples plus indicators such as zero.sudolite.ml and IPs 176.65.137.5 and 176.65.137.6.
In December 2022, the FBI seized domains associated with DDoS-for-hire services; Microsoft noted that one domain linked to Zerobot activity was reportedly among them. This connected part of Zerobot's infrastructure to broader law-enforcement action against booter services.
At the end of November, CUJO AI Labs publicly reported a new Golang-based botnet named Zerobot. The report described the malware as evolving and abusing numerous recently disclosed vulnerabilities.
CUJO AI Labs observed Zerobot samples in customer networks between November 24 and November 26, marking the malware's initial observed activity in the provided sources. The samples showed a Golang-based botnet targeting routers, firewalls, cameras, web servers, and enterprise software via multiple exploits.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cujo.com
Open sourcemicrosoft.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.