Echobot is a Mirai-derived botnet malware family that targets Linux-based Internet-of-Things, embedded, and network-connected systems through large-scale exploit-driven propagation. First publicly documented in 2019, it evolved rapidly from variants carrying roughly 18 exploits to later builds incorporating more than 50 and then 71 exploits, reflecting an aggressive expansion of its attack surface. Its operators relied heavily on publicly available exploit code, combining legacy and newly disclosed vulnerabilities to compromise a broad mix of devices and services.
Echobot is associated with opportunistic mass exploitation rather than narrowly focused victim selection. Observed targets include routers, IP cameras, smart home controllers, NAS appliances, SD-WAN devices, VoIP systems, wireless presentation systems, set-top boxes, enterprise application platforms, web application firewalls, application delivery controllers, video conferencing systems, database and administration software, and other internet-exposed embedded or enterprise systems. Later variants also added exploitation of Mitsubishi Electric remote terminal units used in industrial environments, an unusual expansion for a Mirai-family botnet and evidence that Echobot operators were willing to incorporate industrial-control-related vulnerabilities when publicly available.
The malware’s propagation model centers on remote code execution and command-injection exploits, supplemented in earlier reporting by brute-force attempts using default or weak credentials. A bash-based dropper known as Richard was used to download, compile, and execute Echobot payloads across numerous processor architectures, enabling infections on heterogeneous embedded hardware. Compromised systems were then used to host and distribute additional payloads, supporting continued spread.
As a Mirai-family botnet, Echobot’s primary operational role is botnet building for distributed denial-of-service activity. Its development history illustrates the broader shift in Mirai-derived malware from simple credential abuse toward modular exploit arsenals designed to maximize infection volume across diverse Linux-based devices and exposed services. The family remains notable for the speed with which its operators integrated both old and newly published vulnerabilities into a scalable propagation framework.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Echobot added four exploits to its arsenal from 2019, while the latest one is from August 2019, targeting Webmin Linux/Unix administration panel (CVE-2019-15107). | F5 Networks researchers have detected a new variant of the "Echobot" malware, now consisting of 71 exploits.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
this version of Echobot adds an outstanding exploit for CVE-2019-14927, which targets Mitsubishi Electric‘s Remote Terminal Unit (RTU). | F5 Networks researchers have detected a new variant of the "Echobot" malware, now consisting of 71 exploits.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
The exploit payloads repeatedly download and execute ECHOBOT binaries and scripts such as ECHOBOT.sh, ECHOBOT.mips, and ECHOBOT.x from 31.13.195[.]251.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
The list of exploits used by this Echobot variant includes multiple 'Remote Command Execution' and 'Command Injection' vulnerabilities across targeted products.
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Mirai-family botnet malware variant that propagates via a large and growing exploit set, spreads through a bash dropper named "Richard," downloads and compiles itself for multiple processor architectures, compromises exposed devices and servers, and recruits them into a botnet.
An IoT botnet and Mirai spin-off that propagates by leveraging dozens of public remote code execution exploits across a wide range of devices and software. It is described as built for distributed denial-of-service attacks.
ECHOBOT appears to be the payload/binary naming used by this Mirai variant, delivered via multiple exploit chains to infect vulnerable IoT and embedded devices.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.