Muhstik is a Linux-focused botnet active since at least 2017, commonly characterized as a Tsunami-derived botnet with reused Mirai code. It compromises internet-exposed servers, web applications, SOHO and IoT devices, and containerized workloads through opportunistic exploitation of public vulnerabilities and weak credentials. Observed propagation targets include Drupal, GPON routers, JBoss, DD-WRT, Apache Log4j, Atlassian Confluence, Apache RocketMQ, WordPress, WebLogic, WebDAV, and other exposed services. Muhstik uses IRC-based command-and-control and can receive commands to scan for vulnerable systems, conduct SSH password attacks and expansion, deploy cryptocurrency miners, and perform flooding-based DDoS attacks. Variants have established persistence through system-startup configuration changes and self-copying, installed SSH access mechanisms, checked for monitoring and analysis tools, and terminated competing malware or mining processes. Muhstik has been observed compromising Linux servers and IoT devices, including Kubernetes-hosted workloads, for botnet recruitment, cryptomining, and DDoS operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
VPN Mentor disclosed CVE-2018-10562 as a GPON command-execution vulnerability. The content provides POST payloads abusing the router diagnostic endpoint to execute wget commands and download Muhstik components. | Muhstik added exploits for GPON (CVE-2018-10561, CVE-2018-10562), JBoss (CVE-2007-1036), and DD-WRT. Its C2 directs bots to conduct scanning, SSH scale-out, XMRig/CGMiner mining, or DDoS attacks.
VPN Mentor disclosed two vulnerabilities of GPON home routers on 2018-05-01: CVE-2018-10561 authentication bypass and CVE-2018-10562 command execution vulnerabilities. From 2018-05-02 through 2018-05-10, five botnet families were observed using the GPON exploit. | Muhstik added exploits for GPON (CVE-2018-10561, CVE-2018-10562), JBoss (CVE-2007-1036), and DD-WRT. Its C2 directs bots to conduct scanning, SSH scale-out, XMRig/CGMiner mining, or DDoS attacks.
Muhstik added exploits for three vulnerabilities: GPON (CVE-2018-10561 and CVE-2018-10562), JBoss (CVE-2007-1036), and DD-WRT web-authentication brute forcing. The GPON and JBoss exploits were embedded in the aiomips sample. | Muhstik added exploits for GPON (CVE-2018-10561, CVE-2018-10562), JBoss (CVE-2007-1036), and DD-WRT. Its C2 directs bots to conduct scanning, SSH scale-out, XMRig/CGMiner mining, or DDoS attacks.
Netlab 360 researchers say they have identified a botnet, dubbed Muhstik, that is taking advantage of the Drupal bug.
Netlab 360 researchers say they have identified a botnet, dubbed Muhstik, that is taking advantage of the Drupal bug.
The shell script attempts to download Executable and Linkable Format (ELF) files and execute them, which leads to the installation of the Muhstik botnet.
In August 2021, Atlassian published a security advisory about CVE-2021-26084 that could enable a threat actor to run arbitrary code on unpatched Confluence Server and Data Center instances. After releasing the advisory, there occur massive scanning and proof-of-concept exploit code in public. We also collect a lot attacking traffic. | Muhstik By exploiting CVE-2021-26084, it downloads conf2 from 149.28.85[.]17. The file will deploy and execute dk86 from 188.166.137[.]241 and ldm script.
The P2PInfect worm infects vulnerable Redis instances by exploiting the Lua sandbox escape vulnerability, CVE-2022-0543. P2PInfect exploits CVE-2022-0543 for initial access and then drops an initial payload that establishes P2P communication to a larger P2P network. | The first exploit for this particular vulnerability was published in March 2022, which resulted in the connection of the infected Redis instance to the Muhstik botnet. However, the P2PInfect worm appears to be associated with a different malicious network, not known to be related to the Muhstik botnet.
CVE-2023-33246: The Apache RocketMQ remote code execution vulnerability In 2023, a remote code execution vulnerability was discovered for RocketMQ versions 5.1.0 and below. RocketMQ elements, such as NameServer, Broker, and Controller, are accessible from the extranet without needing permission checks. This creates an opportunity for attackers to exploit the flaw. | Aqua Nautilus discovered a new campaign of Muhstik malware targeting message queuing services applications, specifically the Apache RocketMQ platform.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
The malicious PHP code loads files and executes remote commands... echo " " . shell_exec($comd) . "";
The attackers then edited the inittab file... used the respawn command to instruct the init process to automatically restart the pty3 process
#muhstik-SSH # stealing local ssh credentials, further horizontal expansion, delivering itself. worm propagation
The attackers then edited the inittab file... used the respawn command to instruct the init process to automatically restart the pty3 process
it was revealed that the Muhstik malware, downloaded as pty3, is detected as packed software. This means the file signature was changed in an attempt to avoid signature-based detection.
the file is saved with the name pty3. pty is a known mechanism in Linux that facilitates communication between processes. The attackers provided the file with a seemingly legitimate name
360Netlab observed a large number of scans on the internet against this vulnerability... the aiox86 scanning module is quite complicated... Target Ports : Scans TCP port 80, 8080, 7001, 2004, and tries varieties of different payloads on each port.
the attackers also uses the IRC communication protocol to invoke commands for the botnet: “We observed multiple IRC Channels, all starting with ‘muhstik,'”
Muhstik is a variant of the Tsunami botnet... Communication protocol: Based on the IRC protocol, sending different instructions via different channels
Muhstik scanners forced vulnerable GPON devices to report status to PHP URLs hosted on attacker-controlled report servers, including gpon.php and gponb6abe42c3a9aa04216077697eb1bcd44.php.
155 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware mentioned as another example of malware using SOHO devices as botnet nodes.
Muhstik is a botnet/worm active since 2017, reportedly based on a Mirai fork, that compromises exposed web applications and devices, establishes persistence, joins infected hosts to a botnet, performs DDoS activity, and monetizes infections through cryptocurrency mining.
Muhstik is a Linux and IoT-targeting malware used for cryptocurrency mining and distributed denial-of-service attacks. In this campaign it was delivered via exploitation of Apache RocketMQ CVE-2023-33246, established persistence by copying itself to multiple directories and modifying inittab, communicated with C2 over IRC, performed host discovery, and attempted SSH-based lateral movement.
Muhstik is a botnet malware that targets Linux servers and IoT devices, often exploiting web application vulnerabilities to install cryptocurrency miners and participate in DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.