Researchers documented a rapidly evolving Go-based botnet, reported as Zerobot and WSzero, that compromised vulnerable devices for distributed denial-of-service (DDoS) attacks. First observed on November 18, 2022, it progressed through four major versions by November 29, adding self-replication, string obfuscation, and propagation through 21 vulnerability or backdoor vectors plus SSH/Telnet weak-password attacks. A subsequent December variant expanded exploitation of cameras, network devices, and server applications. The malware supports Linux and Windows, although FortiGuard reported that it could not propagate to Windows machines.
The botnet supports HTTP_BYPASS, TCP, UDP, and ICMP attacks, arbitrary operating-system commands, scanning, and remote updates. Researchers observed JSON-based command-and-control traffic over TCP, WebSocket, and TLS-protected WebSocket, with some variants encoding server addresses using byte subtraction. Netlab first received a DDoS command on November 23; attack commands were relatively infrequent, but control infrastructure actively issued updates at the time. Defenders should prioritize patching exposed devices and applications, eliminating weak SSH/Telnet credentials, and monitoring for botnet traffic; FortiGuard reported antivirus, intrusion-prevention, and web-filtering coverage. These historical reports do not establish ongoing activity in 2026.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
Fortinet first publicly reported Zerobot in a technical blog detailing its propagation, WebSocket command-and-control, DDoS capabilities, and arbitrary operating-system command execution. The report supplied malware hashes and infrastructure indicators and recommended patching vulnerable systems.
BotMon researchers first captured Wszero v4, which retained 21 exploit vectors, SSH/Telnet password cracking, and Linux and Windows support. The variant used WebSocket command-and-control at 176.65.137.5:80.
Researchers first captured Wszero v3.x, adding 21 exploit vectors, SSH/Telnet password cracking, and support for both Linux and Windows. FortiGuard's analysis likewise documented an updated Zerobot with self-replication and expanded propagation capabilities.
Researchers first captured Wszero v3, which used zero.sudolite.ml for command-and-control over TLS-protected WebSocket. Its stored C2 information was decoded by subtracting one from each byte.
BotMon researchers received their first Wszero DDoS command. Their analysis documented an HTTP_BYPASS attack instruction and additional TCP, UDP, and ICMP attack capabilities.
BotMon researchers first captured Wszero v2, which used WebSocket communications with 176.65.137.5:80 instead of the initial version's TCP channel. The variant continued to target Linux.
FortiGuard Labs dated Zerobot's first appearance to November 18, when BotMon researchers also first captured the family they named Wszero. The initial Go-based DDoS botnet targeted Linux and communicated with 176.65.137.5:1401 over TCP.
FortiGuard Labs reported a new variant adding propagation exploits affecting Zivif cameras, Grandstream devices, Sophos SG UTM, Apache HTTP Server, Roxy-WI, Apache Spark, and MiniDVBLinux. The report stated that Zerobot could run on Linux and Windows but could not propagate to Windows machines.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 85 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourceblog.netlab.360.com
Open sourcefortinet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.