Zerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Zerobot
Zerobot, also known as ZeroStresser, is a malware-as-a-service botnet initially documented in 2022 as a Go-based threat targeting internet-exposed IoT devices and web-facing systems.
Profile source: Mallory opens in a new tabZerobot
Family profile
Zerobot, also known as ZeroStresser, is a malware-as-a-service botnet initially documented in 2022 as a Go-based threat targeting internet-exposed IoT devices and web-facing systems. It compromises routers, firewalls, cameras, web servers, and related appliances through exploitation of known remote-code-execution, command-injection, authentication-bypass, and path-traversal vulnerabilities, and by brute-forcing weak or default SSH and Telnet credentials. Compromised systems are enrolled into a distributed denial-of-service botnet; observed versions support multiple flooding methods and scan for additional exposed victims. Zerobot uses architecture-specific payloads and has targeted a broad range of embedded-device CPU architectures. It has also been observed in Linux and Windows-capable forms, with platform-specific persistence mechanisms. Some variants terminate competing malware, clear shell-command history, and use packing, encrypted strings, or browser-like user agents to hinder analysis and detection. Microsoft tracks associated activity as Storm-1061. A later Mirai-based iteration, zerobotv9, was observed exploiting vulnerabilities affecting Tenda routers and the n8n automation platform, demonstrating continued use of newly disclosed vulnerabilities for botnet propagation.
Capabilities
- Brute Force
- Ddos
- Defense Evasion
- Initial Access
- Persistence
- Scanning
Reported operators
Threat actors
2 named in public reportingZerobot, a Go-based botnet that spreads primarily through IoT and web application vulnerabilities, is an example of an evolving threat, with operators continuously adding new exploits and capabilities to the malware.
Exploited software
Vulnerabilities linked to Zerobot
34 CVEsMITRE ATT&CK