PumaBot is a custom Go-based Linux botnet that targets embedded Linux IoT devices through SSH brute-force attacks. Rather than scanning autonomously, it retrieves target address lists and credential pairs from command-and-control infrastructure, attempts SSH authentication, and upon successful access deploys itself to the victim and continues propagation. The malware collects host details including operating system, kernel, and architecture, and reports compromised-host metadata together with working credentials back to its operators.
On infected systems, PumaBot establishes persistence by installing itself under names intended to resemble legitimate software components, creating systemd services for automatic startup, and adding attacker-controlled SSH keys to authorized_keys files to preserve access even if the primary service is removed. It also includes environment-checking logic to avoid unsuitable or monitored systems, including fingerprinting behavior consistent with honeypot and restricted-shell evasion.
PumaBot has been linked to a broader Linux intrusion set involving additional components that support long-term access, credential theft, self-updating behavior, and operational resilience. Associated tooling includes a Go-based backdoor, an SSH brute-force utility, shell scripts used to deploy follow-on payloads, a trojanized PAM module that intercepts successful logins to steal credentials, and a watcher component that monitors harvested credentials and exfiltrates them. Collectively, this activity indicates an ecosystem focused on compromising Linux and IoT environments, maintaining durable access, harvesting credentials, and expanding botnet reach.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom Go-based Linux botnet targeting embedded Linux IoT devices. It retrieves target IPs and credential lists from C2 infrastructure, brute-forces SSH logins, fingerprints environments to avoid honeypots or unsuitable hosts, reports host details to C2, persists via systemd services masquerading as Redis/MySQL, and adds SSH keys for continued access.
Go-based botnet targeting Linux IoT devices; performs SSH brute forcing to expand and can deliver additional malware/payloads.
Go-based Linux botnet that targets embedded IoT devices via SSH brute-force attacks.
PumaBot is a botnet malware that targets Linux-based IoT devices, likely for purposes such as DDoS attacks or further propagation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.