Echobot

First seen
2019-05-15 00:00:00
Malware type
botnet, worm
Family
Malware family
Last IoC activity
2026-07-08 02:28:48
Profile updated
2026-07-07 14:24:27

Targeted industries: technology-and-telecommunications energy-and-utilities

Context

The latest in this long line of Mirai scourges is a new variant named Echobot. Coming to life in mid-May, the malware was first described by Palo Alto Networks in a report published at the start of June, and then again in a report by security researchers from Akamai, in mid-June. When it was first spotted by Palo Alto Networks researchers in early June, Echobot was using exploits for 18 vulnerabilities. In the Akamai report, a week later, Echobot was at 26. https://www.zdnet.com/article/new-echobot-malware-is-a-smorgasbord-of-vulnerabilities

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Echobot (report)
  • Palo Alto Unit 42 — New Mirai Variant Adds 8 New Exploits Targets Additional Iot Devices (report)
  • blogs.akamai.com — Latest Echobot 26 Infection Vectors (report)
  • Palo Alto Unit 42 — Mirai Variant Echobot Resurfaces With 13 Previously Unexploited Vulnerabilities (report)
  • bleepingcomputer.com — New Echobot Botnet Variant Uses Over 50 Exploits To Propagate (report)
  • f5.com — Echobot Malware Now Up To 71 Exploits Targeting Scada (report)

External references