Skip to content

Enemybot

EnemyBot is a self-propagating, multi-architecture DDoS botnet identified in 2022 and attributed to the Keksec cybercrime group, also known as Kek Security.

Enemybot

Family profile

EnemyBot is a self-propagating, multi-architecture DDoS botnet identified in 2022 and attributed to the Keksec cybercrime group, also known as Kek Security. Its codebase incorporates substantial Gafgyt code alongside components from Mirai and other botnets. It primarily targets Linux servers, routers, and IoT devices, with additional support for Android infection and builds for Darwin/macOS. Its source code has been publicly released, enabling reuse by other operators.

EnemyBot scans pseudorandom IP ranges, attempts authentication using hardcoded weak or manufacturer-default credentials, and exploits vulnerabilities in internet-facing applications and network devices. Its exploit repertoire includes Log4Shell, Apache HTTP Server, Spring Cloud Gateway, VMware Workspace ONE, content management systems, and numerous router products. Samples embed CVE-2022-22954 exploitation logic for continued propagation. Android infection routines target exposed Android Debug Bridge services and connected devices. Successful compromises launch shell-based download chains that retrieve and execute architecture-specific payloads.

The bot supports multiple network- and application-layer DDoS methods, including TCP, UDP, HTTP, TLS, DNS, SSDP, and ICMP flooding. Operator commands also support shell execution, reverse shells, scanner and sniffer control, and additional payload downloads. Observed variants establish persistence through cron, randomize process names, obfuscate strings, and use Tor-hidden command-and-control infrastructure. Development during 2022 incorporated new exploits and incremental changes to scanning and obfuscation. Keksec's associated operations include DDoS attacks and DDoS-based extortion.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Initial Access
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Scanning

Samples

Recent samples

1 sandbox sample in the Derp library, newest 1 shown

Reported operators

Threat actors

1 named in public reporting
Keksec

EnemyBot is mainly built on Gafgyt’s source code, with several modules from the original Mirai source code, and other botnets.

Exploited software

Vulnerabilities linked to Enemybot

23 CVEs
CVE-2021-45046 JNDI lookup injection in Apache Log4j non-default logging configurations CVE-2018-10823 Authenticated Command Injection in D-Link DWR Routers CVE-2017-18368 Unauthenticated Command Injection in ZyXEL P660HN-T1A Remote System Log CVE-2022-25075 Command Injection in TOTOLink A3000RU Main Function CVE-2022-29013 Command Injection in Razer Sila Gaming Router v2.0.441_api-2.0.418 CVE-2022-22947 Spring Cloud Gateway Actuator SpEL Injection RCE CVE-2015-2051 D-Link DIR-645 HNAP SOAPAction Command Injection CVE-2020-17456 Remote Code Execution in SEOWON INTECH SLC-130 and SLR-120S system_log.cgi CVE-2021-4039 Command Injection in Zyxel NWA-1100-NH Web Interface CVE-2021-44228 Log4Shell CVE-2014-9118 Command Injection in Zhone zNID GPON 2426A Web Administrative Portal CVE-2016-6277 Remote Command Injection in NETGEAR Multiple Routers CVE-2022-27226 CSRF to RCE in iRZ Mobile Routers /api/crontab CVE-2021-42013 Path Traversal and RCE in Apache HTTP Server 2.4.49 and 2.4.50 CVE-2018-20062 Remote PHP Code Execution in NoneCms V1.3 ThinkPHP CVE-2021-41773 Path Traversal and Conditional RCE in Apache HTTP Server 2.4.49 CVE-2020-5902 TMUI Remote Code Execution in F5 BIG-IP CVE-2021-35064 Privilege Escalation in KramerAV VIAWare via sudo Misconfiguration CVE-2022-22954 Server-Side Template Injection RCE in VMware Workspace ONE Access and Identity Manager CVE-2020-7961 Java Deserialization RCE in Liferay Portal JSONWS CVE-2022-1388 F5 BIG-IP iControl REST Authentication Bypass RCE CVE-2021-36356 Arbitrary Code Execution in KRAMER VIAware via writeBrowseFilePathAjax.php CVE-2018-16763 Pre-Auth RCE in FUEL CMS 1.4.1

MITRE ATT&CK

Enemybot in ATT&CK

24 distinct techniques