Linux/Rakos is a Linux malware family written in Go that targets internet-exposed embedded devices and servers, primarily by brute-forcing SSH logins that use weak or default credentials. It is associated with botnet-style propagation: after compromising a host, it reports system and access information to command-and-control infrastructure, retrieves additional scan targets, and attempts to spread by uploading and executing itself on newly accessed systems. Rakos has been observed across multiple CPU architectures, including x86, x86-64, and MIPS, reflecting its focus on heterogeneous Linux devices and appliances.
The malware’s core behavior centers on large-scale SSH scanning and credential attacks. When authentication succeeds, it executes basic host-identification commands, determines whether file upload is possible, and deploys itself to the victim if feasible. It also exfiltrates host metadata and valid SSH credentials to its operators, creating follow-on access opportunities beyond the immediate infection. Earlier variants reportedly included SMTP scanning capability, although that functionality was disabled in later analyzed builds.
Rakos uses HTTP-based command-and-control communications, loads configuration data in YAML format from standard input, and supports remote configuration updates and self-upgrade. It also exposes local and network-accessible HTTP services and disguises its process under benign-looking names to reduce casual detection. The malware was not observed to maintain persistence across reboot in the analyzed versions, but systems remain highly susceptible to rapid reinfection if insecure credentials are unchanged, particularly after factory resets restore default passwords.
Rakos is best characterized as a Linux botnet malware family focused on opportunistic compromise of poorly secured devices and servers through SSH brute force and credential abuse. Even without confirmed destructive or monetization payloads in the analyzed versions, it poses significant risk through unauthorized access, credential theft, propagation, and continued attacker control over compromised infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
It is executed from a temporary directory and disguised as a part of the Java framework, namely “. javaxxx ”. Additional names like “. swap ” or “ kworker ” are also used.
The main feature of this bot is its scanning of the SSH service on various IP addresses... if one of the username:password pairs from the configuration file results in a successful login to one of the target devices
The main feature of this bot is its scanning of the SSH service on various IP addresses... if one of the username:password pairs from the configuration file results in a successful login to one of the target devices connection to target is successful, two commands are run on that newly-accessed victim.
46 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux malware family written in Go that brute-forces SSH credentials on embedded devices and servers, reports victim details to C2 infrastructure, installs itself on newly accessed hosts, and supports configuration updates and self-upgrade. It is used to build a botnet of compromised devices.
Linux malware written in Go that brute-forces SSH logins on embedded devices and servers using weak/default credentials, reports victim details to C2, uploads itself to newly accessed hosts, and supports configuration updates and self-upgrade to grow a botnet.
For a description of Linux/Rakos, please see the article about Linux/Rakos on WeLiveSecurity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.