FritzFrog
- First seen
- 2020-01-01 00:00:00
- Malware type
- botnet, worm
- Family
- Malware family
- Last IoC activity
- 2026-07-10 16:01:27
- Profile updated
- 2026-07-07 12:59:28
Context
Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. It is a worm which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk.
Detection coverage
- 1 YARA rules
Detection rules
- TRELLIX_ARC_MALW_Fritzfrog (yara-rule)
Reports & references
- intezer.com — Top Linux Cloud Threats Of 2020 (report)
- blackberry.com — Report Bb 2021 Threat Report (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Fritzfrog (report)
- guardicore.com — Fritzfrog P2P Botnet Infects Ssh Servers (report)
- securityweek.com — Sophisticated Fritzfrog P2P Botnet Returns After Long Break (report)
- akamai.com — Fritzfrog A New Generation Of Peer To Peer Botnets (report)
- blog.netlab.360.com — P2P Botnets Review Status Continuous Monitoring (report)
- akamai.com — Fritzfrog P2P (report)
- cyberkendra.com — Fritzfrog Botnet Expands Attack Arsenal (report)