ESET reported that Linux/Rakos is compromising internet-exposed embedded devices and Linux servers by brute-forcing weak or default SSH credentials, then enrolling the systems into a botnet. The malware, written in Go and often packed with UPX, hides under names such as .javaxxx, .swap, and kworker, starts local and external HTTP services, sends host details and stolen credentials to command-and-control servers, retrieves target IP lists, and propagates by uploading itself to newly accessed hosts. Researchers said the operators can remotely update configuration files and upgrade the malware, while analyzed samples showed no built-in DDoS or spam module.
The activity mirrors earlier Linux botnet campaigns such as Linux/Moose, which also spread by abusing weak default credentials on embedded Linux devices rather than exploiting software flaws. Moose primarily brute-forced Telnet on consumer routers and other MIPS and ARM systems, then used infected devices as whitelisted SOCKS/HTTP proxies, sniffed unencrypted traffic for social-network cookies, and supported large-scale social-media fraud from residential IP space. Both malware families lack reliable persistence after reboot, but exposed devices can be quickly reinfected if default passwords remain unchanged, including after factory resets.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
ESET researchers Peter Kálnai and Michal Malik published analysis of Linux/Rakos, describing its SSH brute-force propagation, C2 communications, credential theft, and reinfection risk on rebooted or factory-reset devices. ESET also released indicators of compromise, malware hashes, C2 server addresses, and a Volatility plugin for detection and memory analysis.
ESET documented Linux/Rakos malware samples for multiple architectures, including x86_64, MIPS, and 386, with first-seen dates spanning August through December 2016. The samples showed a botnet-focused malware family spreading through brute-force SSH attacks on devices and servers with weak credentials.
ESET published analysis of Linux/Moose, a Linux worm targeting consumer routers and embedded devices via brute-forced Telnet credentials, and concluded its primary purpose was social-network fraud using infected devices as proxies. The report documented capabilities including NAT traversal, traffic sniffing for social-network cookies, DNS hijacking during infection, and lateral scanning.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 38 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
welivesecurity.com
Open sourcewelivesecurity.com
Open sourceweb-assets.esetstatic.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.