Roboto

Malware type
botnet, ddos
Family
Malware family
Profile updated
2026-07-07 14:29:27

Context

P2P Botnet discovered by Netlab360. The botnet infects linux servers via the Webmin RCE vulnerability (CVE-2019-15107) which allows attackers to run malicious code with root privileges and take over older Webmin versions. Based on the Netlabs360 analysis, the botnet serves mainly 7 functions: reverse shell, self-uninstall, gather process' network information, gather Bot information, execute system commands, run encrypted files specified in URLs and four DDoS attack methods: ICMP Flood, HTTP Flood, TCP Flood, and UDP Flood.

Exploited vulnerabilities

  • CVE-2019-15107 (vulnerability)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Elf.Roboto (report)
  • blog.netlab.360.com — The Awaiting Roboto Botnet En (report)
  • zdnet.com — New Roboto Botnet Emerges Targeting Linux Servers Running Webmin (report)

External references