FritzFrog

First seen
2020-01-01 00:00:00
Malware type
botnet, worm
Family
Malware family
Last IoC activity
2026-07-10 16:01:27
Profile updated
2026-07-07 12:59:28

Context

Guardicore has discovered FritzFrog, a sophisticated peer-to-peer (P2P) botnet which has been actively breaching SSH servers since January 2020. It is a worm which is written in Golang, and is modular, multi-threaded and fileless, leaving no trace on the infected machine’s disk.

Detection coverage

  • 1 YARA rules

Detection rules

  • TRELLIX_ARC_MALW_Fritzfrog (yara-rule)

Reports & references

  • intezer.com — Top Linux Cloud Threats Of 2020 (report)
  • blackberry.com — Report Bb 2021 Threat Report (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Fritzfrog (report)
  • guardicore.com — Fritzfrog P2P Botnet Infects Ssh Servers (report)
  • securityweek.com — Sophisticated Fritzfrog P2P Botnet Returns After Long Break (report)
  • akamai.com — Fritzfrog A New Generation Of Peer To Peer Botnets (report)
  • blog.netlab.360.com — P2P Botnets Review Status Continuous Monitoring (report)
  • akamai.com — Fritzfrog P2P (report)
  • cyberkendra.com — Fritzfrog Botnet Expands Attack Arsenal (report)

External references