Last seven days
- First activity
- Oct 2, 2026
- Last activity
- Oct 2, 2026
- Feed role
- Distribution
- Host form
- 1 IP / 0 hostnames
Echobot is a Mirai-derived botnet malware family that targets Linux-based Internet-of-Things, embedded, and network-connected systems through large-scale exploit-driven propagation.
Profile source: Mallory opens in a new tabECHOBOT
Echobot is a Mirai-derived botnet malware family that targets Linux-based Internet-of-Things, embedded, and network-connected systems through large-scale exploit-driven propagation. First publicly documented in 2019, it evolved rapidly from variants carrying roughly 18 exploits to later builds incorporating more than 50 and then 71 exploits, reflecting an aggressive expansion of its attack surface. Its operators relied heavily on publicly available exploit code, combining legacy and newly disclosed vulnerabilities to compromise a broad mix of devices and services.
Echobot is associated with opportunistic mass exploitation rather than narrowly focused victim selection. Observed targets include routers, IP cameras, smart home controllers, NAS appliances, SD-WAN devices, VoIP systems, wireless presentation systems, set-top boxes, enterprise application platforms, web application firewalls, application delivery controllers, video conferencing systems, database and administration software, and other internet-exposed embedded or enterprise systems. Later variants also added exploitation of Mitsubishi Electric remote terminal units used in industrial environments, an unusual expansion for a Mirai-family botnet and evidence that Echobot operators were willing to incorporate industrial-control-related vulnerabilities when publicly available.
The malware’s propagation model centers on remote code execution and command-injection exploits, supplemented in earlier reporting by brute-force attempts using default or weak credentials. A bash-based dropper known as Richard was used to download, compile, and execute Echobot payloads across numerous processor architectures, enabling infections on heterogeneous embedded hardware. Compromised systems were then used to host and distribute additional payloads, supporting continued spread.
As a Mirai-family botnet, Echobot’s primary operational role is botnet building for distributed denial-of-service activity. Its development history illustrates the broader shift in Mirai-derived malware from simple credential abuse toward modular exploit arsenals designed to maximize infection volume across diverse Linux-based devices and exposed services. The family remains notable for the speed with which its operators integrated both old and newly published vulnerabilities into a scalable propagation framework.
Samples
Exploited software
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.