Keksec, also styled #keksec, is a financially motivated cybercrime group active since 2016 that develops and operates IoT, Linux, and Windows botnets. The group has been associated with the Necro, Gafgyt, Gafgyt_tor, Tsunami, EnemyBot, Simps, and LOLFME malware families. It is known for operating multiple botnet variants in parallel and for rapidly incorporating publicly disclosed vulnerabilities and weak or default credentials into large-scale propagation campaigns targeting internet-exposed routers, IoT devices, web applications, and servers. Keksec operations support distributed denial-of-service activity, including DDoS-based extortion, cryptocurrency mining, information theft, and malware distribution. Its malware commonly performs internet-wide service scanning, Telnet and SSH credential attacks, exploitation of known remote-code-execution vulnerabilities, multi-architecture payload delivery, and command-and-control obfuscation through Tor services and domain-generation techniques. EnemyBot and related tooling reuse components from Mirai and Gafgyt-derived codebases while adding broad exploit coverage and multiple DDoS methods. Necro is Keksec's most feature-rich known platform. It has targeted Linux and Windows hosts, deployed cryptominers, performed web-file injection to deliver browser-resident theft and DDoS functionality, and used rootkit-assisted process and artifact concealment on Windows through in-memory process injection. Browser-oriented payloads associated with Necro support keylogging, form-data collection, cookie and clipboard theft, and browser-based DDoS activity. Across its malware families, Keksec has also used packet sniffing, process masquerading, anti-analysis measures, and mechanisms to remove competing malware. LOLFME variants associated with Keksec have incorporated destructive device-wiping logic, including behavior intended to erase storage, disrupt networking, and reboot infected devices. Available evidence did not establish widespread deployment of these destructive functions. TuxBot v3 Evolution has infrastructure and tooling overlaps with the broader Keksec ecosystem, including Kaitori and AISURU-related activity, but this connection is an ecosystem-level assessment rather than conclusive attribution of TuxBot operations directly to Keksec.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
28 CVEs this actor has used in observed campaigns. 28 of them exploited in the wild.
CVE-2014-9118: Targets Zhone routers
CVE-2015-2051: Targets D-Link routers
CVE-2017-18368: Targets Zyxel P660HN routers
CVE-2018-10823 flaw an older D-Link routers (DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, DWR-111 through 1.01).
Necro exploits WebLogic RCE (CVE-2020-14882) with separate Linux and Windows exploit chains that download and execute Necro and mining payloads.
23 more CVEs tied to this actor tracked in Mallory.
242 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
18 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Suspected ecosystem linked via shared infrastructure to the operator behind TuxBot v3 Evolution; no confirmed attribution is made.
Operates multiple parallel IoT botnets; TuxBot is assessed as part of its ecosystem.
An IoT botnet operator ecosystem linked to TuxBot through shared infrastructure with Kaitori v3.9 and AISURU; known for running multiple IoT botnet variants in parallel.
Infrastructure overlap with TuxBot through shared hosting and certificate artifacts; not stated to be the same malware/codebase.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.