EnemyBot is a Linux-focused IoT botnet and DDoS malware family associated with the Keksec cybercrime group. It is derived in part from Mirai and Gafgyt codebases and has been observed targeting routers, web servers, CMS platforms, Linux hosts, and exposed Android devices. The malware supports multiple CPU architectures and is designed to compromise heterogeneous internet-facing systems, particularly embedded and server-class Linux environments.
EnemyBot propagates primarily by exploiting known vulnerabilities in internet-exposed devices and applications, and by attempting authentication with weak or default credentials. Reported exploitation coverage includes router and IoT flaws, web application and CMS vulnerabilities, Apache and Log4j-related remote code execution paths, and VMware Workspace ONE Access exploitation. It has also been observed attempting to infect Android devices with exposed Android Debug Bridge services. In some campaigns, successful exploitation triggers a shell-based download chain that retrieves an architecture-appropriate binary and executes it on the victim.
Once installed, EnemyBot connects to command-and-control infrastructure and awaits operator instructions while continuing to scan for additional vulnerable systems. Reported functionality includes distributed denial-of-service attacks across multiple protocols, shell command execution, reverse shell support, scanner control, sniffer control, modular payload retrieval, and further propagation. Analysis has also identified reconnaissance and system-enumeration behavior, duplicate-instance checks, anti-analysis logic, and string obfuscation. Some reporting indicates data theft via HTTP POST, though EnemyBot is primarily characterized as a botnet used for DDoS operations and opportunistic exploitation.
EnemyBot has been described as under active development, with newer variants expanding exploit coverage rapidly after public disclosure of one-day vulnerabilities. It has used obfuscation to conceal strings and has hidden command-and-control services behind Tor in some variants. The malware has been linked to Keksec’s broader botnet ecosystem, which includes Mirai and Gafgyt deployments as well as internally developed families such as Necro and LOLFME. EnemyBot is notable for combining commodity botnet lineage with aggressive vulnerability adoption, making it a persistent threat to unpatched Linux servers, routers, and other IoT devices.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
22 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
CVE-2016-6277: Targets NETGEAR routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2017-18368: Targets Zyxel P660HN routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2022-27226 affecting iRZ mobile routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-41773/CVE-2021-42013: Targets Apache HTTP servers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-44228/2021-45046: Better known as Log4j | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2018-20062: Targets ThinkPHP CMS | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2015-2051: Targets D-Link routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2018-10823 flaw an older D-Link routers (DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, DWR-111 through 1.01). | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-44228/2021-45046: Better known as Log4j | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
The malware exploits tens of known vulnerabilities including: CVE-2020-17456 vulnerability affecting SEOWON INTECH SLC-130 and SLR-120S routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2022-25075 to 25084: Targets TOTOLINK routers, previously exploited by the Beastmode botnet | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2021-41773/CVE-2021-42013: Targets Apache HTTP servers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
CVE-2014-9118: Targets Zhone routers | Enemybot is a DDoS botnet that targeted several routers and web servers by exploiting known vulnerabilities.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2020-5902 F5 BigIP RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-36356, CVE-2021-35064 Kramer VIAware RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2022-22947 Spring Cloud Gateway - Code injection vulnerability | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
Some examples are Razer Sila (April 2022) which was published without a CVE and a remote code execution (RCE) vulnerability impacting VMWare Workspace ONE with CVE-2022-22954 the same month. | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-4039 Zyxel NWA-1100-NH Command injection | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2020-7961 Liferay Portal - Java Unmarshalling via JSONWS RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2022-1388 F5 BIG IP RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2021-36356, CVE-2021-35064 Kramer VIAware RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
We have also listed the current vulnerabilities EnemyBot uses... CVE-2018-16763 Fuel CMS 1.4.1 RCE | LevelBlue Labs™ has been tracking a new IoT botnet dubbed “EnemyBot”, which is believed to be distributed by threat actor Keksec.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Enemybot attributed itself to Keksec, a threat group specializing in crypto mining and DDoS attacks, and is built on Gafgyt’s source code and several modules from Mirai’s original source code.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
It uses a list of hardcoded username/password combinations to login into devices in the attempt to access systems using weak or default credentials.
The message was stored as cleartext in earlier samples, new samples were released with the message encoded with an XOR operation using a multiple-byte key.
Each line of the script attempts to download (again using various methods), set permissions to execute (777), execute from /tmp/ and then delete the original ELF binary.
It uses a list of hardcoded username/password combinations to login into devices in the attempt to access systems using weak or default credentials.
“Stateless” TCP SYN probes to pseudorandom IPs on Telnet ports 23 and 2323 Once targets were identified, Mirai attempted a brute-force attack...
Scrubbing the file in a decompile, it appears to feature a host of networking options such as port scanners, TCP/UDP flood options and general system enumeration.
Mapped to MITRE ATT&CK The findings of this report are mapped to the following MITRE ATT&CK Matrix techniques: TA0011: Command and Control T1132: Data Encoding T1001: Data Obfuscation
Once the bot has been installed on a device, it connects to its C2 server and waits for further commands
it connects to a command-and-control (C2) server that is hidden in the Tor network, making its takedown more complicated.
Then the script downloads the actual Enemybot binary which is compiled for the target device’s architecture.
Mirai managed to keep 200,000 – 300,000 enslaved devices and peaked at an unbelievable 600,000... FBI special agents compared Mirai’s 1+ Tbps (1,000 Gbps)... The first Mirai incident was reported after the 18th Sep 2016 attack against popular Minecraft servers hosted on French service OVH.
19 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
KekSec-developed botnet mentioned as background context.
Botnet built on Gafgyt and Mirai code, actively developed and using Mirai-derived scanner, killer, and weak-credential modules to compromise devices and remove competitors.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and participate in DDoS attacks.
Enemybot is a botnet malware that targets IoT devices and servers, leveraging known vulnerabilities to propagate and conduct DDoS attacks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.