BotenaGo is a Go-based IoT botnet malware family that targets internet-exposed embedded devices by exploiting known vulnerabilities across multiple vendors. It has been reported with more than 30 built-in exploit functions and is associated with opportunistic compromise of routers, network-attached storage appliances, security cameras, DVRs, and similar Linux-based IoT systems. The malware is widely regarded as part of the post-Mirai ecosystem and reuses techniques associated with Mirai-style botnet operations.
BotenaGo’s core behavior centers on scanning for vulnerable devices and attempting remote exploitation through publicly known flaws, including vulnerabilities affecting Xiongmai devices and Zyxel products. Reported variants and derivatives have also targeted Lilin DVR equipment. In at least one analyzed BotenaGo-derived sample, the malware accepted attacker-supplied target lists rather than autonomously discovering victims, attempted multiple embedded credential pairs for HTTP authentication, exploited a command-injection flaw in DVR management functionality, and then downloaded and executed a follow-on Mirai payload. This demonstrates that BotenaGo code has also been repurposed as a scanner or loader component in broader botnet deployment chains.
The malware is written in Golang, which contributes to large statically linked binaries and portability across architectures. BotenaGo source code was leaked and later uploaded publicly, which likely accelerated reuse, modification, and derivative development by other actors. Security reporting has linked BotenaGo activity to exploitation of known CVEs in exposed IoT infrastructure, and the family has been observed in the broader ecosystem of commodity botnets competing for vulnerable embedded devices.
BotenaGo primarily targets Linux-based IoT platforms and network-connected appliances. Its operational objective is botnet propagation and post-compromise payload delivery rather than stealthy long-term intrusion. High-confidence reporting supports exploitation, scanning, brute-force authentication attempts in some variants, and delivery of additional malware such as Mirai.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Update on Jan. 27, 2022 Recent research suggested that a new BotenaGo malware is targeting a list of devices with known CVE vulnerabilities from several vendors. | Zyxel NAS (Network Attached Storage) and firewall products are affected by a remote code execution vulnerability... A remote code execution vulnerability was identified in the weblogin.cgi program used in Zyxel NAS and firewall products. Missing authentication for the program could allow attackers to perform remote code execution via OS command injection.
the botnet is co-located with a Xiongmai NVR/IP camera’s HTTP server... correlate three known vulnerabilities this server is affected by: CVE-2017-7577, CVE-2018-10088, and CVE-2022-45460... CVE-2018-10088, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
7 distinct techniques documented for this family, organized by ATT&CK tactic.
The modified configuration contains a command that, because of the vulnerability, will attempt to download a file named wget.sh from the IP address 136.144.41[.]169 and then immediately execute its content.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
BotenaGo is described as malware targeting devices with known CVE vulnerabilities from multiple vendors.
Malware targeting multiple routers with numerous exploit functions.
CVE-2018-10888, in particular, is already associated with the Satori, Hajime, and BotenaGo botnets.
Botnet referenced as already associated with exploitation of a Xiongmai vulnerability.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.