A recent analysis of files uploaded to a Cowrie honeypot identified active exploitation attempts targeting Raspberry Pi devices using default and uncommon credentials. The attacks involved the UNIX_PIMINE.A botnet worm, which propagates via SSH, installs persistence, removes competing malware, and connects to IRC-based C2 channels. The findings highlight the ongoing risk to IoT devices with unchanged default passwords and the value of automated event correlation in honeypot environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
OSINT Team Blog published an article titled "How to use FindAnyFil3 & why," indicating public release of guidance or commentary about the FindAnyFil3 tool and its use cases. No earlier event date is provided in the reference.
The SANS Internet Storm Center published a guest diary titled "Exploring Uploads in a Dshield Honeypot Environment," describing analysis of files uploaded in a DShield honeypot setting. The reference indicates public technical discussion of honeypot upload activity by this date.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.