Researchers tracked the Mirai-derived Echobot botnet as it rapidly expanded from 18 exploits to 59 and then 71 exploits, broadening propagation across routers, cameras, NAS devices, smart home hubs, servers, SD-WAN appliances, Oracle WebLogic, Barracuda Web Application Firewall, Citrix NetScaler, video conferencing systems, and administration tools. The malware relied heavily on publicly available remote code execution and command-execution exploits, including both legacy flaws dating back to 2003 and newer issues such as CVE-2019-15107 in Webmin, showing how quickly commodity botnet code can be upgraded into large-scale exploit-driven malware.
The most notable escalation was Echobot’s move into industrial environments through exploitation of CVE-2019-14927 affecting Mitsubishi Electric remote terminal units, an uncommon step for a Mirai-family botnet toward SCADA and critical infrastructure-related devices. Researchers said the malware spread through a bash dropper named Richard, which downloaded, compiled, and executed payloads for at least 13 processor architectures, while infrastructure linked to the campaign included open or compromised servers and changing command-and-control domains and ports. The activity underscored Mirai’s continued evolution away from simple default-credential abuse and toward aggressive exploit-based propagation to build larger botnets, likely for DDoS operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
F5 Networks researchers detected a new Echobot variant that expanded its exploit arsenal to 71 and added targets including Mitsubishi Electric RTUs, Barracuda WAF, Citrix NetScaler, video conferencing systems, and administration tools. The report highlighted the unusual inclusion of an industrial control system exploit, CVE-2019-14927, in a Mirai-family botnet.
The F5 report states that the U.S. Department of Homeland Security issued an alert in September 2019 covering CVE-2019-14927 in Mitsubishi Electric remote terminal units. The vulnerability later appeared in Echobot's exploit arsenal.
Carlos Brendel Alcañiz identified a new Echobot variant using 59 exploits to propagate across routers, cameras, NAS devices, servers, database software, and other network-connected products. The report said the operator relied on publicly available exploits and hosted the dropper in a file named Richard on an open server.
On June 7, 2019, Palo Alto Networks Unit 42 published analysis of a new Mirai variant containing 18 exploits, including eight not previously seen in Mirai campaigns. The malware targeted a broad range of embedded and IoT devices and reflected Mirai's shift toward exploit-driven propagation.
Palo Alto Networks observed malware samples for the Mirai variant later dubbed Echobot being hosted in an open directory and updated multiple times between May 19 and May 26, 2019. The final observed version was uploaded on May 26 and used updated command-and-control endpoints.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
f5.com
Open sourcebleepingcomputer.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.