PerlBot

Aliases: DDoS Perl IrcBot, ShellBot

First seen
2007-01-01 00:00:00
Malware type
botnet, ddos, trojan
Family
Malware family
Last IoC activity
2026-07-21 16:41:42
Profile updated
2026-07-07 12:59:29

Targeted industries: technology-and-telecommunications government-and-public-sector

Context

PerlBot, also known as DDoS Perl IrcBot or ShellBot, is a malware family leveraging the Perl scripting language for distributed denial-of-service (DDoS) attacks. It often communicates via IRC channels and has capabilities typical of a botnet, providing control over infected machines for malicious activities.

Exploited vulnerabilities

  • CVE-2020-17496 (vulnerability)
  • CVE-2022-22954 (vulnerability)

Reports & references

  • Trend Micro — Teamtnt Now Deploying Ddos Capable Irc Bot Tntbotinger (report)
  • sysdig.com — Rubycarp Romanian Botnet Group (report)
  • CISA — Aa20 345A (report)
  • Palo Alto Unit 42 — Cve 2022 22954 Vmware Vulnerabilities (report)
  • blog.netlab.360.com — Some Details Of The Ddos Attacks Targeting Ukraine And Russia In Recent Days (report)
  • yoroi.company — Outlaw Is Back A New Crypto Botnet Targets European Organizations (report)
  • Trend Micro — Perl Based Shellbot Looks To Target Organizations Via C&C Appendix (report)
  • Palo Alto Unit 42 — Cve 2020 17496 (report)
  • malpedia.caad.fkie.fraunhofer.de — Elf.Perlbot (report)
  • therecord.media — Agents Raid Home Of Kansas Man Seeking Info On Botnet That Infected Dod Network (report)
  • asec.ahnlab.com — 54647 (report)
  • asec.ahnlab.com — 49769 (report)
  • brianstadnicki.github.io — Malware Gitlab Perlbot (report)
  • sysdig.com — Malware Analysis Shellbot Sysdig (report)
  • twitter.com — 1308430959512092673 (report)
  • jask.com — Shellbot Campaign V2 (report)
  • Palo Alto Unit 42 — Los Zetas From Eleethub Botnet (report)

External references