Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareExploits 6 CVEs

Zerobot

Zerobot is a Mirai-based IoT botnet/malware family first documented in 2022 and described in the provided content as having resurfaced in a ninth known iteration, "zerobotv9," in 2026. Earlier reporting referenced Zerobot as Go-based and IoT-focused, while the zerobotv9 variant is described as smaller, not written in Go, UPX-packed, and using encrypted strings. The malware is associated with active exploitation of internet-exposed devices and platforms to propagate, including Hikvision devices via CVE-2021-36260, Tenda AC1206 routers via CVE-2025-7544, and the n8n workflow automation platform via CVE-2025-68613. The content also notes Zerobot has been mentioned alongside newer Mirai forks that added Windows infection capability, but specific Windows functionality for Zerobot itself is not established here.

In the 2026 activity, Akamai observed Zerobot exploiting CVE-2025-68613 and CVE-2025-7544, with activity first detected in January 2026 and dating back to at least early December 2025. After exploitation, victims are instructed to download and execute a shell script named tol.sh from 144.172.100.228. That script copies BusyBox to /tmp, sets execution permissions, and downloads and runs the main multi-architecture payload zerobotv9. The malware hard-codes the C2 domain 0bot.qzz[.]io and uses browser-like user-agent strings to blend malicious traffic with legitimate web activity. The content also states the botnet uses fallback connection techniques including netcat, socat, and Perl socket methods.

Capabilities directly described in the content include Mirai-style botnet behavior and multiple attack modules named TCPXmas, Mixamp, SSH, and Discord. Zerobot is characterized as a Mirai-based botnet campaign targeting exposed networks and connected devices, especially IoT infrastructure such as routers and cameras. The content further states it has also been observed targeting older vulnerabilities including CVE-2017-9841, CVE-2021-3129, and CVE-2022-22947 as additional propagation paths.

Associated infrastructure and indicators explicitly mentioned in the content include the C2 domain 0bot.qzz[.]io, the staging IP 144.172.100.228 hosting tol.sh, and additional malicious IPs recommended for blocking or monitoring: 103.59.160.237, 140.233.190.96, 172.86.123.179, and 216.126.227.101. Zerobot is also explicitly associated in the content with exploitation of CVE-2021-36260, and is mentioned alongside Moobot in that context. Akamai SIRT research is cited as the source for the 2026 Zerobot activity.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

6 CVES
CVE-2021-36260Unauthenticated Command Injection in Hikvision Web ServerExploited in the wild

The botnet is likely using CVE-2021-36260 to infect these targets... VulnCheck tracks 23 public exploits for this vulnerability, including a Metasploit module... included in CISA’s Known Exploited Vulnerabilities Catalog (KEV)... actively detected in the Shadow Server and GreyNoise honeypot networks.

via vulncheck blogvulncheck.com
CVE-2025-7544Stack-based buffer overflow in Tenda AC1206 /goform/setMacFilterCfg (formSetMacFilterCfg)Exploited in the wild

Zerobot Exploits Flaws in n8n and Tenda Routers — ... exploiting vulnerabilities in the n8n AI automation platform (CVE-2025-68613) and Tenda routers (CVE-2025-7544) to expand its reach.

via the hacker newsthehackernews.com
CVE-2025-68613Authenticated RCE in n8n Workflow Expression EvaluationExploited in the wild

Zerobot... observed exploiting vulnerabilities in the n8n AI automation platform (CVE-2025-68613) and Tenda routers (CVE-2025-7544) to expand its reach.

via the hacker newsthehackernews.com
CVE-2021-3129Ignition debug mode RCE in LaravelExploited in the wild

The botnet was further observed targeting CVE-2017-9841, CVE-2021-3129, and CVE-2022-22947, using fallback connection techniques including netcat, socat, and Perl socket methods.

via cyber security newscybersecuritynews.com
CVE-2022-22947Spring Cloud Gateway Actuator Code Injection RCEExploited in the wild

The botnet was further observed targeting CVE-2017-9841, CVE-2021-3129, and CVE-2022-22947, using fallback connection techniques including netcat, socat, and Perl socket methods.

via cyber security newscybersecuritynews.com
CVE-2017-9841PHPUnit eval-stdin.php Remote Code ExecutionExploited in the wild

The botnet was further observed targeting CVE-2017-9841, CVE-2021-3129, and CVE-2022-22947, using fallback connection techniques including netcat, socat, and Perl socket methods.

via cyber security newscybersecuritynews.com
MITRE ATT&CK

Techniques & procedures

3 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

“Zerobot … exploiting vulnerabilities in the n8n AI automation platform … and Tenda routers … to expand its reach.”

Execution

1 technique
T1203Exploitation for Client ExecutionEvidence1

"CVE-2025-7544... critical stack-based buffer overflow in the /goform/setMacFilterCfg endpoint of Tenda AC1206... enabling... remote code execution (RCE)."

Impact

1 technique
T1498Network Denial of ServiceEvidence1

“Russia's internet watchdog fell victim to a DDoS attack…”; “Kimwolf DDoS botnet…”

INDICATORS OF COMPROMISE

IOCs tracked for this family

1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Other
1 tracked

Other indicator types observed in public reporting.

TypeValueLatest sighting
uri●●●●●●●●●●●●View more in app7 years ago
ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching1

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities6

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping3

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.