Researchers reported that the Roboto botnet has been compromising internet-exposed Linux servers by exploiting the Webmin remote code execution flaw CVE-2019-15107, which allowed attackers to run code with root privileges on vulnerable older versions. Attacks began within days of the vulnerability’s disclosure, and investigators said the campaign initially focused on expanding the botnet rather than launching visible disruption, even though the malware includes distributed denial-of-service capabilities.
Analysis from 360 Netlab found Roboto uses a downloader-and-bot ELF pair, with the downloader fetching the payload while disguising it as Google font files such as roboto.ttc. The malware provides reverse shell access, command execution, host and network reconnaissance, file download and upload, encrypted payload execution, and self-uninstall features, while maintaining persistence through fake process names and Linux startup scripts. Researchers said Roboto’s peer-to-peer architecture and use of cryptographic protections including Curve25519, Ed25519, TEA, SHA256, and HMAC-SHA256 could complicate takedown efforts, and they identified hard-coded peer nodes in multiple countries along with a local control socket at /tmp/.cs.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
On October 11, 2019, 360Netlab's Anglerfish honeypot captured a second ELF sample that functioned as a downloader for the earlier Roboto bot. The downloader fetched the bot from hard-coded URLs, including one disguised as a Google font file named roboto.ttc.
On August 26, 2019, 360Netlab detected a suspicious ELF file later identified as a Roboto P2P bot program. This was one of the earliest observed samples tied to the botnet.
The Webmin team disclosed and patched a remote code execution vulnerability in August 2019. The flaw affected older Webmin versions and allowed attackers to execute code with root privileges.
Qihoo 360 Netlab published research identifying Roboto as a Linux P2P botnet exploiting vulnerable Webmin servers. The analysis described its botnet-expansion focus, peer-to-peer architecture, and built-in but not yet observed DDoS capabilities.
360Netlab observed host 51.38.200.230 spreading the Roboto downloader by exploiting Webmin RCE vulnerability CVE-2019-15107. The exploit downloaded a file from 190.114.240.194 to /tmp and executed it, and the spreading host itself appeared possibly compromised.
360Netlab said Roboto had continued targeting Webmin servers for the previous three months, primarily focusing on expanding the botnet. Researchers observed the malware growing in both size and code complexity over that period.
Within days of the Webmin vulnerability disclosure, attackers started targeting internet-exposed vulnerable Webmin installations. Roboto was identified as one of the early threats exploiting the flaw.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.