PerlBot
Aliases: DDoS Perl IrcBot, ShellBot
- First seen
- 2007-01-01 00:00:00
- Malware type
- botnet, ddos, trojan
- Family
- Malware family
- Last IoC activity
- 2026-07-21 16:41:42
- Profile updated
- 2026-07-07 12:59:29
Targeted industries: technology-and-telecommunications government-and-public-sector
Context
PerlBot, also known as DDoS Perl IrcBot or ShellBot, is a malware family leveraging the Perl scripting language for distributed denial-of-service (DDoS) attacks. It often communicates via IRC channels and has capabilities typical of a botnet, providing control over infected machines for malicious activities.
Exploited vulnerabilities
- CVE-2020-17496 (vulnerability)
- CVE-2022-22954 (vulnerability)
Reports & references
- Trend Micro — Teamtnt Now Deploying Ddos Capable Irc Bot Tntbotinger (report)
- sysdig.com — Rubycarp Romanian Botnet Group (report)
- CISA — Aa20 345A (report)
- Palo Alto Unit 42 — Cve 2022 22954 Vmware Vulnerabilities (report)
- blog.netlab.360.com — Some Details Of The Ddos Attacks Targeting Ukraine And Russia In Recent Days (report)
- yoroi.company — Outlaw Is Back A New Crypto Botnet Targets European Organizations (report)
- Trend Micro — Perl Based Shellbot Looks To Target Organizations Via C&C Appendix (report)
- Palo Alto Unit 42 — Cve 2020 17496 (report)
- malpedia.caad.fkie.fraunhofer.de — Elf.Perlbot (report)
- therecord.media — Agents Raid Home Of Kansas Man Seeking Info On Botnet That Infected Dod Network (report)
- asec.ahnlab.com — 54647 (report)
- asec.ahnlab.com — 49769 (report)
- brianstadnicki.github.io — Malware Gitlab Perlbot (report)
- sysdig.com — Malware Analysis Shellbot Sysdig (report)
- twitter.com — 1308430959512092673 (report)
- jask.com — Shellbot Campaign V2 (report)
- Palo Alto Unit 42 — Los Zetas From Eleethub Botnet (report)