Researchers reported new destructive malware targeting embedded and IoT devices, including a newly identified Kaden botnet and a new LOLFME variant tied to the KekSec ecosystem, while AcidPour surfaced as a new embedded wiper variant of AcidRain in Ukraine. The findings point to continued evolution of Linux-based malware capable of disrupting routers, modems, and other edge devices that are often used in critical infrastructure environments.
Forescout said Kaden blends code from rebirth, Gafgyt, Mirai variants, and Silex, and contains a wiping function that is present but not yet connected to an active C2 command. The newer LOLFME sample appears more mature, with logic to wipe a device if it loses contact with its command server and a bricklol capability designed to destroy logs, storage, and networking before rebooting the host. Researchers used YARA hunting based on earlier IoT wipers including AcidRain, AcidPour, BrickerBot, HEH, VPNFilter, Silex, and HandyMannyPot, and said there is not yet confirmed evidence that the Kaden or LOLFME wipers have been deployed at scale in the wild.

See affected versions and whether adversaries are exploiting it.
11 events from the most recent confirmed update back to the earliest known activity.
A follow-up search and LiveHunt identified 22 total Kaden botnet samples through the end of June 2024, with only the last five containing the wiping function matched by the YARA rule.
Forescout says a LiveHunt from May through the end of June 2024 found four recent LOLFME-related samples that contacted 192.3.117[.]132.
Forescout reports that most Kaden samples were newly submitted between February and May 2024, which it assesses as evidence of ongoing botnet development.
The RetroHunt returned eight matches, including three samples resembling a KekSec LOLFME variant and five samples containing the string "KADENBOTNET."
Forescout researchers built a YARA rule from 25 known IoT wiper samples and deployed it in VirusTotal RetroHunt to search files submitted between February and May 2024 for wiping behavior.
Forescout says AcidPour, a newer variant of AcidRain, was used in attacks against Ukrainian telecommunication networks in 2024.
Forescout states that AcidRain was used by a Russian APT to brick satellite modems in Europe at the start of Russia's 2022 invasion of Ukraine.
Forescout reports that one Kaden C2 IP, 185.244.25[.]166, previously resolved in 2019 to alex-botnet[.]xyz and related subdomains, indicating earlier botnet infrastructure overlap.
The Forescout analysis states that BrickerBot has existed since at least 2017 and is described as the first known IoT wiper.
Forescout says the KekSec group was created in 2016 and later became known for botnet development including Mirai and Gafgyt variants as well as Necro, LOLFME, and EnemyBot.
Forescout links strings in Kaden samples to a YouTube profile, @Kaden1227, that uploaded botnet-related videos between 2018 and 2020 advertising compromised-device access and a DDoS stresser service.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 42 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.