Skip to content

ECHOBOT

Echobot is a Mirai-derived botnet malware family that targets Linux-based Internet-of-Things, embedded, and network-connected systems through large-scale exploit-driven propagation.

Profile source: Mallory opens in a new tab

ECHOBOT

Family profile

Echobot is a Mirai-derived botnet malware family that targets Linux-based Internet-of-Things, embedded, and network-connected systems through large-scale exploit-driven propagation. First publicly documented in 2019, it evolved rapidly from variants carrying roughly 18 exploits to later builds incorporating more than 50 and then 71 exploits, reflecting an aggressive expansion of its attack surface. Its operators relied heavily on publicly available exploit code, combining legacy and newly disclosed vulnerabilities to compromise a broad mix of devices and services.

Echobot is associated with opportunistic mass exploitation rather than narrowly focused victim selection. Observed targets include routers, IP cameras, smart home controllers, NAS appliances, SD-WAN devices, VoIP systems, wireless presentation systems, set-top boxes, enterprise application platforms, web application firewalls, application delivery controllers, video conferencing systems, database and administration software, and other internet-exposed embedded or enterprise systems. Later variants also added exploitation of Mitsubishi Electric remote terminal units used in industrial environments, an unusual expansion for a Mirai-family botnet and evidence that Echobot operators were willing to incorporate industrial-control-related vulnerabilities when publicly available.

The malware’s propagation model centers on remote code execution and command-injection exploits, supplemented in earlier reporting by brute-force attempts using default or weak credentials. A bash-based dropper known as Richard was used to download, compile, and execute Echobot payloads across numerous processor architectures, enabling infections on heterogeneous embedded hardware. Compromised systems were then used to host and distribute additional payloads, supporting continued spread.

As a Mirai-family botnet, Echobot’s primary operational role is botnet building for distributed denial-of-service activity. Its development history illustrates the broader shift in Mirai-derived malware from simple credential abuse toward modular exploit arsenals designed to maximize infection volume across diverse Linux-based devices and exposed services. The family remains notable for the speed with which its operators integrated both old and newly published vulnerabilities into a scalable propagation framework.

Capabilities

  • Brute Force
  • Ddos
  • Initial Access
  • Reconnaissance
  • Scanning

Observed infrastructure

Last seven days

First activity
Oct 2, 2026
Last activity
Oct 2, 2026
Feed role
Distribution
Host form
1 IP / 0 hostnames

Leading locations

  • BR1

Leading providers

  • FONSECA ALVES TECNOLOGIA LTDA1

Infrastructure traits

  • Hosting 1

Samples

Recent associated samples

Exploited software

Vulnerabilities linked to ECHOBOT

10 CVEs

MITRE ATT&CK

ECHOBOT in ATT&CK

9 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.