Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The main function of the Linux.Ngioweb Bot sample is to implement Back-Connect Proxy on the victim's machine. The attacker builds multiple bots into a Proxies Pool and controls it through a double-layer C2 protocol, and then provides a Rotating Reverse Proxy Service.
The main function of the Linux.Ngioweb Bot sample is to implement Back-Connect Proxy on the victim's machine. The attacker builds multiple bots into a Proxies Pool and controls it through a double-layer C2 protocol, and then provides a Rotating Reverse Proxy Service.
The main function of the Linux.Ngioweb Bot sample is to implement Back-Connect Proxy on the victim's machine. The attacker builds multiple bots into a Proxies Pool and controls it through a double-layer C2 protocol, and then provides a Rotating Reverse Proxy Service.
The main function of the Linux.Ngioweb Bot sample is to implement Back-Connect Proxy on the victim's machine. The attacker builds multiple bots into a Proxies Pool and controls it through a double-layer C2 protocol, and then provides a Rotating Reverse Proxy Service.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Anti-reverse engineering technique Uses a niche library named musl libc Stores its functions in the function table in advance Uses Stack Strings Obfuscation Generates constant table used by CRC and AES
At this stage, the communication is combined by double-layer encryption. The inner layer is XOR and the outer layer is AES.
Communication Protocol This phase of communication is based on the HTTP protocol and the parameters are Base64 encoded. | At this stage, the main behavior of the sample is to establish communication with Stage-1 C2, and proceed to the next step according to the instructions returned by C2. Communication Protocol This phase of communication is based on the HTTP protocol and the parameters are Base64 encoded.
The main functionality of the Linux.Ngioweb Bot sample is to implement Back-Connect Proxy on the victim's machine. The attacker builds multiple Bots into a Proxies Pool and controls it through a two-tier C2 protocol, then provides a Rotating Proxy Service.
2,793 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux botnet malware family that turns infected systems, including IoT devices, into back-connect proxy nodes for a rotating reverse proxy service. V2 adds AES-encrypted configuration storage, configurable DGA seeds/domain counts, and configurable C2 reporting paths to improve concealment and resilience.
Linux proxy botnet that implants on compromised WordPress web servers and turns them into back-connect rotating proxy nodes. It uses DGA-generated domains, a two-tier C2 architecture, and encrypted Stage-2 communications to provide SOCKS5/rotating proxy services.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.