Skip to content
Data by Hatching Triage opens in a new tab IotLinuxNetwork DeviceWindows

Zerobot

Zerobot, also known as ZeroStresser, is a malware-as-a-service botnet initially documented in 2022 as a Go-based threat targeting internet-exposed IoT devices and web-facing systems.

Profile source: Mallory opens in a new tab

Zerobot

Family profile

Zerobot, also known as ZeroStresser, is a malware-as-a-service botnet initially documented in 2022 as a Go-based threat targeting internet-exposed IoT devices and web-facing systems. It compromises routers, firewalls, cameras, web servers, and related appliances through exploitation of known remote-code-execution, command-injection, authentication-bypass, and path-traversal vulnerabilities, and by brute-forcing weak or default SSH and Telnet credentials. Compromised systems are enrolled into a distributed denial-of-service botnet; observed versions support multiple flooding methods and scan for additional exposed victims. Zerobot uses architecture-specific payloads and has targeted a broad range of embedded-device CPU architectures. It has also been observed in Linux and Windows-capable forms, with platform-specific persistence mechanisms. Some variants terminate competing malware, clear shell-command history, and use packing, encrypted strings, or browser-like user agents to hinder analysis and detection. Microsoft tracks associated activity as Storm-1061. A later Mirai-based iteration, zerobotv9, was observed exploiting vulnerabilities affecting Tenda routers and the n8n automation platform, demonstrating continued use of newly disclosed vulnerabilities for botnet propagation.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Initial Access
  • Persistence
  • Scanning

Reported operators

Threat actors

2 named in public reporting
DEV-1061

Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.

Storm-1061

Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.

Exploited software

Vulnerabilities linked to Zerobot

34 CVEs
CVE-2025-68613 Authenticated Expression Injection RCE in n8n CVE-2017-17215 Command Injection RCE in Huawei HG532 DeviceUpgrade CVE-2022-22965 Spring4Shell CVE-2018-10561 Authentication Bypass in Dasan GPON Home Routers CVE-2020-25506 Command Injection RCE in D-Link DNS-320 system_mgr.cgi CVE-2016-20017 Unauthenticated Command Injection in D-Link DSL-2750B CVE-2018-10562 Command Injection in Dasan GPON Router Diagnostic Ping Handler CVE-2014-8361 Remote Code Execution in Realtek SDK miniigd SOAP Service CVE-2021-42013 Path Traversal and RCE in Apache HTTP Server 2.4.49 and 2.4.50 CVE-2020-10987 Tenda AC15 AC1900 USB-Unload OS Command Injection CVE-2022-1388 F5 BIG-IP iControl REST Authentication Bypass RCE CVE-2021-36260 Hikvision Web Server Unauthenticated Command Injection CVE-2022-34538 Command Injection in Digital Watchdog DW MEGApix IP Cameras CVE-2022-30525 Unauthenticated OS Command Injection in Zyxel ZLD Firewalls and VPN Devices CVE-2021-35395 Multiple Remote Code Execution Vulnerabilities in Realtek Jungle SDK Web Server CVE-2022-37061 Remote Command Injection in FLIR AX8 thermal sensor cameras CVE-2020-7209 Remote Code Execution in LinuxKI CVE-2022-26186 Command Injection in TOTOLINK N600R exportOvpn Interface CVE-2021-46422 Command Injection in Telesquare SDT-CW3B1 1.1.0 CVE-2022-26210 Command Injection in TOTOLINK setUpgradeFW CVE-2021-41773 Path Traversal and Conditional RCE in Apache HTTP Server 2.4.49 CVE-2022-25075 Command Injection in TOTOLink A3000RU Main Function CVE-2022-30023 Command Injection in Tenda ONT GPON AC1200 HG9 Ping Function CVE-2019-10655 Unauthenticated RCE in Grandstream Devices via Authentication Bypass and Command Injection CVE-2020-25223 Unauthenticated RCE in Sophos SG UTM WebAdmin CVE-2018-12613 LFI/RCE in phpMyAdmin 4.8.0/4.8.1 (CVE-2018-12613) CVE-2022-31137 Unauthenticated RCE in Roxy-WI CVE-2017-17105 Unauthenticated Remote Command Injection in Zivif PR115-204-P-RS Web Cameras CVE-2022-33891 Apache Spark UI Command Injection via ACL Impersonation CVE-2018-20057 Authenticated Command Injection in D-Link DIR-619L/605L goform/formSysCmd CVE-2025-7544 Stack-Based Buffer Overflow in Tenda AC1206 formSetMacFilterCfg CVE-2021-3129 Unauthenticated RCE in Laravel Facade Ignition Debug Mode CVE-2022-22947 Spring Cloud Gateway Actuator SpEL Injection RCE CVE-2017-9841 Unauthenticated PHP code execution in PHPUnit

MITRE ATT&CK

Zerobot in ATT&CK

22 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.