Researchers reported that a new InterPlanetary Storm malware variant broadened its reach from earlier Windows and Linux infections to Mac, Android, and a growing set of IoT devices, including Android-based TVs and Linux-based routers. Barracuda estimated the botnet had infected roughly 13,500 systems across 84 countries, with the highest concentration in Asia, while separate reporting highlighted the malware’s use of the InterPlanetary File System (IPFS) and a peer-to-peer architecture to operate in the wild.
The Go-based malware spreads through SSH dictionary attacks and exposed Android Debug Bridge (ADB) services, then establishes persistence, updates itself, detects honeypots, kills competing processes, and enables reverse shell access for operators. Researchers warned that the botnet’s backdoor access could be repurposed for DDoS, cryptomining, or other follow-on attacks, underscoring the risk of internet-exposed administrative services and poorly secured embedded devices.

Pull IOCs and campaign context straight into your stack.
4 events from the most recent confirmed update back to the earliest known activity.
A Linux-targeting InterPlanetary Storm variant was reported in June of the same year as the earlier Windows discovery. This showed the malware expanding beyond its initial Windows focus.
The first known InterPlanetary Storm malware variant targeting Windows was uncovered by Anomali. This marks the earliest explicitly dated discovery referenced in the source material.
Barracuda reported that the new variant spread through SSH dictionary attacks and exposed ADB services, used IPFS and libp2p for peer-to-peer communications, and provided backdoor access to infected devices. Researchers estimated the botnet had about 13,500 infected machines across 84 countries and published technical indicators including IPFS DHT keys, protocol IDs, and file hashes.
Barracuda researchers first detected a new InterPlanetary Storm variant in late August. The variant expanded targeting to Mac, Android, Windows, and Linux devices, with emphasis on IoT systems such as Android TVs and Linux routers.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.