Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
One of the addresses disguised the Bot sample as a Google font library "roboto.ttc", so we named the Botnet Roboto. Roboto Botnet mainly supports 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs, DDoS attack, etc.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
Get process network information (traverse process list, get process, network and crontab file information) and upload it to the specified HTTP interface
Roboto Bot mainly supports 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs, DDoS attack, etc.
Create self-starting script based on the release version of the Linux system /etc/init.d/dns-clear or systemd-hwdb-upgrade.service
Create self-starting script based on the release version of the Linux system /etc/init.d/dns-clear or systemd-hwdb-upgrade.service
Get process network information (traverse process list, get process, network and crontab file information) and upload it to the specified HTTP interface
disguise its own files and processes name to gain persistence control. Fake Process names (sd-pam) /sbin/rpcbind /usr/bin/python upstart-socket-bridge /usr/sbin/irqbalance /lib/systemd/systemd-udevd /usr/libexec/postfix/master File name for masquerading libXxf86dag.so .node_repl_history.gz
Collect system, process, and network info from the infected server
Get the Bot information and upload it to the specified HTTP interface.
some are also selected to prop up the P2P network or work as scanners to search for other vulnerable Webmin systems, to expand the botnet further.
Get process network information (traverse process list, get process, network and crontab file information) and upload it to the specified HTTP interface /proc/net/tcp /proc/net/udp
Get process network information (traverse process list, get process, network and crontab file information) and upload it to the specified HTTP interface /proc/%s/exe /proc/%s/cmdline
The Downloader sample downloads the above Bot program from two hard-coded HTTP URLs.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux ELF P2P botnet with separate downloader and bot modules. It downloads encrypted payloads by CPU architecture, decrypts and executes them, establishes persistence via init/systemd scripts, masquerades as legitimate processes/files, communicates over a P2P network using Curve25519/TEA/HMAC-SHA256, supports reverse shell and command execution, collects host/process/network information, can run additional encrypted payloads from URLs, and includes ICMP/HTTP/TCP/UDP flood DDoS capabilities.
A Linux botnet that compromises vulnerable Webmin servers, primarily to expand its peer-to-peer botnet infrastructure. It includes DDoS capabilities, reverse shell access, system and network information collection, remote command execution, file download-and-execute functionality, and self-uninstall features.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.