FritzFrog is a Golang-based peer-to-peer botnet targeting Linux systems, particularly internet-exposed SSH servers. It emerged in 2020 and is notable for its decentralized command-and-control design, in which infected nodes exchange commands, targets, and victim metadata directly rather than relying on a central server. The malware is memory-resident in observed campaigns, improving stealth and resilience, and has been described as frequently updated.
FritzFrog propagates primarily through aggressive SSH credential brute-forcing, including attacks against standard and alternate SSH ports. After obtaining valid credentials, it establishes an SSH session on the victim host, transfers and executes its payload, and uses the newly compromised system to continue scanning and spreading. Its peer-to-peer architecture distributes targets among nodes and supports file transfer, script execution, binary execution, and sharing of compromised-host information across the botnet.
Observed operator objectives include cryptocurrency mining and the removal of competing miners from infected systems. Reported functionality also includes deployment of additional payloads and the ability to create a Tor proxy chain for resilience, although that feature was not observed in active use at the time it was reported. FritzFrog has also incorporated logic to avoid low-resource devices and suspected sinkholes.
Victims have included cloud instances, data center servers, routers, enterprise systems, and government servers worldwide, with reported targeting across sectors such as healthcare, higher education, and government. Available reporting has suggested a possible link to a China-based actor or an actor attempting to appear Chinese, but attribution remains unconfirmed.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Bot deployment : this is where the bot is deployed into a target system member of the network, for instance through an exploit, or by brute-forcing the credentials... DDG’s method of infection involves brute-forcing the root user password against SSH servers... FritzFrog... relies on SSH credential brute-forcing as its propagation mechanism... Mozi uses weak Telnet credential brute-forcing as a way to propagate.
FritzFrog is a peer-to-peer botnet, which means its command and control server is not limited to a single, centralized machine, but rather can be done from every machine in its distributed network.
According to Akamai, FritzFrog is often updated and there is some indication that its developers might be preparing to target WordPress servers. The company’s researchers also noticed that FritzFrog contains functionality for creating a Tor proxy chain that would help it become more resilient.
Threat actors use peer-to-peer (P2P) botnets like these to build a platform that can later be used to carry out malicious operations... The need for increased takedown resistance eventually drove botnet operators to adapt and explore peer-to-peer approaches.
The malware then waits for commands from its operators, including for transferring files, running scripts and binary payloads... Other changes observed by Akamai include the use of a public Secure Copy Protocol (SCP) library that the malware leverages to copy itself to a compromised server
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A decentralized peer-to-peer botnet malware that spreads via SSH-targeted compromises and has been reported attacking Linux servers to mine Monero.
A mining P2P botnet that relies on SSH services and weak credentials to establish and maintain its peer-to-peer network.
Golang-based, memory-resident P2P botnet targeting SSH servers via brute-force credential attacks. After gaining SSH access, it deploys itself, accepts commands to transfer files, run scripts and binaries, deploy cryptocurrency miners, remove competing miners, and scan/spread to additional hosts. It also includes Tor proxy chain functionality for resilience.
A peer-to-peer botnet that spreads via SSH brute force, compromises servers using stolen credentials, drops and executes a malware binary, listens for commands, exchanges targets and compromised-host data with peers, transfers files, and can run scripts and binary payloads.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.