EnemyBot is a Linux-based botnet malware family targeting a broad range of Linux hosts, including servers and IoT devices. Reported infection activity used remote code execution and shell-based download-and-execute chains, including exploitation of VMware Workspace ONE Access and Identity Manager via CVE-2022-22954. In one observed chain, attackers attempted to access a web server /shell endpoint and used wget, busybox wget, curl, and ftpget to retrieve an update.sh script from 198.12.116.254, which then downloaded 13 architecture-specific ELF payloads, saved them locally, changed permissions to 777, executed them, and deleted them. Reported payload names included enemybotmips, enemybotmpsl, enemybotsh4, enemybotx86, enemybotarm7, enemyboti686, enemybotppc, enemyboti586, enemybotm68k, enemybotspc, enemybotarm, enemybotarm5, and enemybotppc-440fp.
Analysis of an x86 sample identified capabilities including port scanning, TCP and UDP flood attacks, general system enumeration, duplicate-instance checks, and HTTP POST-based data theft. The malware accepted arguments such as destination IP, source IP, destination port, source port, data payload, and packet count. Researchers also observed encrypted code and counter-forensic or anti-analysis behavior; dynamic analysis was limited because the malware terminated shortly after execution, and it reportedly killed itself when certain process names associated with analysis environments were detected.
EnemyBot has been described as built with code from both Gafgyt and Mirai, and reporting noted similarities to the LolFMe botnet, including the string "watudoinglookingatdis." It also follows the Mirai-like pattern of multi-architecture support and RCE-based initial footholds. Among botnet payloads observed exploiting CVE-2022-22954, EnemyBot was specifically noted as embedding CVE-2022-22954 exploit logic for further exploitation and propagation. Mentioned indicators include the IP address 198.12.116.254, the update.sh downloader, architecture-specific EnemyBot ELF binaries, and sample strings such as "watudoinglookingatdis," "Determined we already have a instance running on this system!" and "Binded and listening on address %d.%d.%d.%d."
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The exception to this is Enemybot, a currently prevalent botnet built with bits of code from both Gafgyt and Mirai source code. The exploits involving Enemybot eventually download Enemybot samples that themselves embed CVE-2022-22954 exploits for further exploitation and propagation. | CVE-2022-22954, a remote code execution (RCE) vulnerability due to server-side template injection in VMware Workspace ONE Access and Identity Manager, is trivial to exploit with a single HTTP request to a vulnerable device.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
Much of the code appears to be encrypted and we encountered some counter forensics which can make static analysis problematic.
Each line of the script attempts to download (again using various methods), set permissions to execute (777), execute from /tmp/ and then delete the original ELF binary.
Scrubbing the file in a decompile, it appears to feature a host of networking options such as port scanners, TCP/UDP flood options and general system enumeration.
Scrubbing the file in a decompile, it appears to feature a host of networking options such as port scanners, TCP/UDP flood options and general system enumeration.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and participate in DDoS attacks.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and conduct DDoS attacks.
Linux-based multi-architecture botnet targeting a wide range of Linux hosts including servers and IoT devices. It downloads architecture-specific ELF binaries, performs system enumeration, supports port scanning and TCP/UDP flood capabilities, can steal data via HTTP POST, and includes counter-forensics/anti-analysis behavior.
A botnet derived from Gafgyt and Mirai code that was observed being dropped via CVE-2022-22954 exploitation; its samples embed CVE-2022-22954 exploit logic for further propagation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.