Echobot
- First seen
- 2019-05-15 00:00:00
- Malware type
- botnet, worm
- Family
- Malware family
- Last IoC activity
- 2026-07-08 02:28:48
- Profile updated
- 2026-07-07 14:24:27
Targeted industries: technology-and-telecommunications energy-and-utilities
Context
The latest in this long line of Mirai scourges is a new variant named Echobot. Coming to life in mid-May, the malware was first described by Palo Alto Networks in a report published at the start of June, and then again in a report by security researchers from Akamai, in mid-June. When it was first spotted by Palo Alto Networks researchers in early June, Echobot was using exploits for 18 vulnerabilities. In the Akamai report, a week later, Echobot was at 26. https://www.zdnet.com/article/new-echobot-malware-is-a-smorgasbord-of-vulnerabilities
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Echobot (report)
- Palo Alto Unit 42 — New Mirai Variant Adds 8 New Exploits Targets Additional Iot Devices (report)
- blogs.akamai.com — Latest Echobot 26 Infection Vectors (report)
- Palo Alto Unit 42 — Mirai Variant Echobot Resurfaces With 13 Previously Unexploited Vulnerabilities (report)
- bleepingcomputer.com — New Echobot Botnet Variant Uses Over 50 Exploits To Propagate (report)
- f5.com — Echobot Malware Now Up To 71 Exploits Targeting Scada (report)