BotenaGo is a Go-based malware family targeting internet-exposed IoT devices, particularly routers, network video recorders, digital video recorders, cameras, and similar embedded Linux systems. It is best known for incorporating a large set of exploit functions for known vulnerabilities across multiple vendors, enabling operators to compromise vulnerable devices and conscript them into botnet activity. Public reporting has associated BotenaGo with exploitation of flaws affecting products such as Zyxel and Xiongmai, and later BotenaGo-derived tooling was observed targeting Lilin DVR devices.
BotenaGo operates as an exploitation-focused botnet malware family rather than a conventional user-endpoint threat. Reported samples include more than 30 exploit routines aimed at IoT and edge devices. Variants and derivatives have been used to attempt remote code execution against exposed services and, in some cases, to try embedded default or weak credentials before exploitation. A documented BotenaGo-derived Lilin-focused scanner accepted attacker-supplied target IP addresses, attempted multiple credential pairs for HTTP basic authentication, exploited a command-injection flaw in DVR management functionality, and then retrieved and executed a follow-on payload from the Mirai family. That derivative appeared intended for manual or semi-manual operation rather than autonomous worm-like propagation.
The family has been linked to post-compromise payload delivery and botnet enablement on Linux-based embedded devices. Its role is primarily to gain execution on vulnerable hosts and deploy additional malware, including Mirai, which can then support distributed denial-of-service operations and broader botnet use. BotenaGo source code became publicly available in late 2021 and early 2022, which likely lowered the barrier for reuse, modification, and derivative development by multiple actors.
BotenaGo is associated with exploitation of known vulnerabilities in internet-facing IoT infrastructure and with opportunistic targeting of poorly secured devices. The malware is relevant to defenders monitoring botnet activity against embedded Linux and network-device ecosystems, especially in environments with exposed surveillance, routing, or NAS equipment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Update on Jan. 27, 2022 Recent research suggested that a new BotenaGo malware is targeting a list of devices with known CVE vulnerabilities from several vendors. | Zyxel NAS (Network Attached Storage) and firewall products are affected by a remote code execution vulnerability... A remote code execution vulnerability was identified in the weblogin.cgi program used in Zyxel NAS and firewall products. Missing authentication for the program could allow attackers to perform remote code execution via OS command injection.
the botnet is co-located with a Xiongmai NVR/IP camera’s HTTP server... correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460... CVE-2018-10088, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The modified configuration contains a command that, because of the vulnerability, will attempt to download a file named wget.sh from the IP address 136.144.41[.]169 and then immediately execute its content.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BotenaGo is described as malware targeting devices with known CVE vulnerabilities from multiple vendors.
Malware targeting multiple routers with numerous exploit functions.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
Botnet referenced as already associated with exploitation of a Xiongmai vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.