Remaiten is a Linux malware family targeting embedded and IoT-class devices, particularly Linux-based routers and similar systems exposed with weak or default credentials. Identified in 2016, it is associated with botnet activity and is primarily used to compromise devices through brute-force authentication attempts against commonly used username and password combinations. Reporting has described it as affecting routers and potentially other Internet-connected embedded Linux devices.
Remaiten combines characteristics associated with the Tsunami and LizardStresser (Torlus) malware families. After gaining access, it attempts to determine the victim device architecture so it can retrieve a platform-appropriate payload, improving infection reliability across heterogeneous IoT hardware. Command-and-control communications use IRC, including actual IRC channels rather than merely an IRC-like protocol.
On compromised systems, Remaiten can participate in distributed denial-of-service operations, download additional malware, and scan memory or processes for competing bot malware. It has also been reported to remove rival bots from infected devices, indicating both botnet monetization and competitive control objectives. Its tradecraft and targeting place it among the notable Linux IoT bot malware families that proliferated through credential abuse rather than software exploitation alone.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
Remaiten is able to scan and remove competing bots on a system compromised by it.
The infected devices constantly scan the Web for other IoT things to compromise... CJ: I scanned the internet with a few sets of defualt logins for telnet
Continuously scans /proc/ for new processes... For each process: Checks if the binary's realpath contains .anime... Performs memory scanning of /proc/$pid/exe against signatures for known competing botnets...
issues kill(pid, 9)... unlink() the binary and kill -9 the process... This targets malware that deletes itself after execution...
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Remaiten is referenced as a competing Linux ELF botnet malware family that this Mirai variant attempts to detect and kill on infected devices.
Notable IoT malware BASHLITE BrickerBot Carna Hajime Linux.Darlloz Linux.Wifatch Mirai Remaiten
Linux malware targeting embedded systems and IoT devices, especially routers, by brute-forcing default credentials. It uses IRC-based command and control, can launch distributed denial-of-service attacks, download additional malware, determine device architecture to fetch appropriate components, and remove competing bots from infected systems.
Notable IoT malware BASHLITE BrickerBot Carna Hajime Linux.Darlloz Linux.Wifatch Mirai Remaiten
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.