LiquorBot
- Malware type
- botnet, cryptominer
- Family
- Malware family
- Profile updated
- 2026-07-07 14:27:05
Context
BitDefender tracked the development of a Mirai-inspired botnet, dubbed LiquorBot, which seems to be actively in development and has recently incorporated Monero cryptocurrency mining features. Interestingly, LiquorBot is written in Go (also known as Golang), which offers some programming advantages over traditional C-style code, such as memory safety, garbage collection, structural typing, and even CSP-style concurrency.
Detection coverage
- 1 YARA rules
Detection rules
- TRELLIX_ARC_MALW_Liquorbot (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Elf.Liquorbot (report)
- labs.bitdefender.com — Hold My Beer Mirai Spinoff Named Liquorbot Incorporates Cryptomining (report)
- zdnet.com — Naive Iot Botnet Wastes Its Time Mining Cryptocurrency (report)