ShellBot, also known as PerlBot, is a Perl-based Linux bot malware family primarily associated with IRC-controlled distributed denial-of-service activity. It has been observed targeting poorly managed Linux SSH servers and other internet-exposed Linux systems, including through brute-force or dictionary attacks against weak SSH credentials and through exploitation of vulnerable public-facing applications such as Cacti. Once installed, ShellBot connects to command-and-control infrastructure over IRC and supports remote command execution on compromised hosts. Reported variants provide DDoS functionality, remote shell access, scanning, and broader system-control features, enabling operators to use infected systems as part of a botnet.
ShellBot has appeared in multiple Linux intrusion and botnet campaigns. It has been distributed under alternate names such as .B0t and has been used alongside other Linux malware and tooling including XMRig, MIG LogCleaner, XHide, Mirai-family bots, Tsunami/Kaiten, and propagation components used to spread across SSH-accessible systems. In some campaigns it was installed by wrapper scripts or obfuscated Perl installers and disguised itself as legitimate processes such as rsync to reduce operator scrutiny. Persistence has been achieved through mechanisms such as startup-script modification and cron-based execution.
Operationally, ShellBot is associated with post-compromise botnet control rather than initial exploitation alone. Observed capabilities include receiving IRC commands, launching denial-of-service attacks, scanning for additional targets, and maintaining attacker control over infected Linux hosts. The malware has also been linked to campaigns involving weak-credential attacks on Linux servers and to opportunistic exploitation waves such as Shellshock-era activity. ShellBot remains relevant as a long-running Linux bot family used in server-focused attacks where exposed services, weak authentication, or unpatched vulnerabilities provide access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exploitation of the BASH bug, now widely referred to as “Shellshock”, is in full swing... The initial patch for this vulnerability (CVE-2014-6271), which was released in sync with the vulnerability’s public disclosure, was quickly found to be inadequate. | The Perl script (md5: cd23ef54e264bd84ab1a12dddceb3f48) was first submitted to VirusTotal over a year ago and is known as ShellBot. It is an IRC bot with remote shell, scanning, and DDoS functionality.
This time, the group explored unpatched systems vulnerable to CVE-2016-8655 and Dirty COW exploit (CVE-2016-5195) as attack vectors.
This time, the group explored unpatched systems vulnerable to CVE-2016-8655 ... as attack vectors.
The Perl script (md5: cd23ef54e264bd84ab1a12dddceb3f48) was first submitted to VirusTotal over a year ago and is known as ShellBot. It is an IRC bot with remote shell, scanning, and DDoS functionality.
"...allowing threat actors to breach internet-exposed Cacti servers to deliver botnet malware such as MooBot and ShellBot."
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The a binary is a script wrapper to start run, a Perl-obfuscated script for installation of a Shellbot to gain control of the infected system. The Shellbot disguises itself as a process named rsync... Shellbot is also used to control the botnet...
21 distinct techniques documented for this family, organized by ATT&CK tactic.
It then resets cron and removes possible cache files from other programs, starts scripts and binaries a, init0, and start, and sets the persistence by modifying the crontab.
After gaining access, ShellBot is deployed, often achieving persistence by modifying startup scripts or cron jobs.
After gaining access, ShellBot is deployed, often achieving persistence by modifying startup scripts or cron jobs.
The commands above Base64 decode the initial string into the following python code below and execute it with Python.
The Shellbot disguises itself as a process named rsync, commonly the binary seen on many Unix- and Linux-based systems to automatically run for backup and synchronization.
Article Link: Case Study: Distribution of a CoinMiner Targeting Linux SSH Servers via Malware Distribution via Network Transmission - ASEC
Tsunami/Kaiten... mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC... ShellBot... It is an IRC bot with remote shell, scanning, and DDoS functionality.
67 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Propagation-capable Linux malware used in the attacks to help distribute or install the XMRig CoinMiner on targeted servers.
Perl-based IRC bot used for DDoS and remote system control on infected Linux servers. In this campaign it was distributed alongside the coin miner tooling.
A Linux bot malware distributed in these SSH compromise attempts, observed under the filename '.B0t'.
A named malware family included in the report tags related to Linux SSH server threats.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.