EnemyBot is mainly built on Gafgyt’s source code, with several modules from the original Mirai source code, and other botnets.
Enemybot
EnemyBot is a self-propagating, multi-architecture DDoS botnet identified in 2022 and attributed to the Keksec cybercrime group, also known as Kek Security.
Enemybot
Family profile
EnemyBot is a self-propagating, multi-architecture DDoS botnet identified in 2022 and attributed to the Keksec cybercrime group, also known as Kek Security. Its codebase incorporates substantial Gafgyt code alongside components from Mirai and other botnets. It primarily targets Linux servers, routers, and IoT devices, with additional support for Android infection and builds for Darwin/macOS. Its source code has been publicly released, enabling reuse by other operators.
EnemyBot scans pseudorandom IP ranges, attempts authentication using hardcoded weak or manufacturer-default credentials, and exploits vulnerabilities in internet-facing applications and network devices. Its exploit repertoire includes Log4Shell, Apache HTTP Server, Spring Cloud Gateway, VMware Workspace ONE, content management systems, and numerous router products. Samples embed CVE-2022-22954 exploitation logic for continued propagation. Android infection routines target exposed Android Debug Bridge services and connected devices. Successful compromises launch shell-based download chains that retrieve and execute architecture-specific payloads.
The bot supports multiple network- and application-layer DDoS methods, including TCP, UDP, HTTP, TLS, DNS, SSDP, and ICMP flooding. Operator commands also support shell execution, reverse shells, scanner and sniffer control, and additional payload downloads. Observed variants establish persistence through cron, randomize process names, obfuscate strings, and use Tor-hidden command-and-control infrastructure. Development during 2022 incorporated new exploits and incremental changes to scanning and obfuscation. Keksec's associated operations include DDoS attacks and DDoS-based extortion.
Capabilities
- Brute Force
- Ddos
- Defense Evasion
- Initial Access
- Persistence
- Post Exploitation
- Reconnaissance
- Scanning
Samples
Recent samples
1 sandbox sample in the Derp library, newest 1 shown
Reported operators
Threat actors
1 named in public reportingExploited software
Vulnerabilities linked to Enemybot
23 CVEsMITRE ATT&CK