EnemyBot

First seen
2022-04-01 00:00:00
Malware type
botnet, ddos
Family
Malware family
Profile updated
2026-07-07 13:05:44

Targeted industries: technology-and-telecommunications

Context

According to the Infosec Institute, EnemyBot is a dangerous IoT botnet that has made headlines in the last few weeks. This threat, which seems to be disseminated by the Keksec group, expanded its features by adding recent vulnerabilities discovered in 2022. It was designed to attack web servers, Android devices and content management systems (CMS) servers.

Detection coverage

  • 1 YARA rules

Detection rules

  • SEKOIA_Bot_Lin_Enemybot_April22 (yara-rule)

Related threat objects

  • EnemyBot (infrastructure)

Reports & references

  • fortinet.com — Enemybot A Look Into Keksecs Latest Ddos Botnet (report)
  • cybersecurity.att.com — Shikitega New Stealthy Malware Targeting Linux (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Enemybot (report)
  • securonix.com — Detecting The Enemybot Botnet Advisory (report)
  • cybersecurity.att.com — Rapidly Evolving Iot Malware Enemybot Now Targeting Content Management System Servers (report)

External references